Skip to content

At Commvault, we talk a lot about cyber resilience, the ability to recover from whatever challenges come your way. But for one engineer at Australian technology services provider Perfekt, it is his personal resilience that helps him succeed.

Viktor Trokhin left Ukraine when the war began, traveling through five countries before eventually reuniting with his family in Australia. He brought more than six years of ICT experience, deep technical expertise, and a determination to continue his career in tech.

Like many skilled professionals starting over in a new country, Viktor wasn’t just adapting to a new workplace. He was building expertise in new technologies, communicating in a second language, and finding his place in a different professional environment.

Marcus Rolim, Managed Services General Manager at Perfekt and Viktor’s manager, saw his potential immediately.

“Our engineering development program is built around people,” Marcus says. “We invest heavily in mentoring and creating opportunities for engineers from different backgrounds.”

Over the years, Perfekt has welcomed engineers from around 10 different countries. Rather than following a standard training path, the company focuses on each person’s strengths, providing mentoring, practical experience, and support where it’s needed most.

For Viktor, that meant building on his existing expertise while gaining experience with Commvault Cloud and cyber resilience.

As he worked with customers, Arlie – the AI assistant in Commvault Cloud – became a natural part of his daily workflow. Whether he was exploring product capabilities, troubleshooting an issue, or looking for guidance, Arlie helped him quickly find trusted information without interrupting his work.

Then came an unexpected benefit.

Because Arlie supports multiple languages, Viktor could work through complex concepts in his native language before switching to English when speaking with customers or colleagues. While this wasn’t the use case Perfekt originally envisioned, it quickly became a valuable learning advantage.

“When an engineer can explore a complex question in their own language, understand the reasoning behind the answer, and then communicate it clearly in English, it changes the learning experience,” Marcus says. “It allows their technical ability to come through without language becoming a barrier.”

Today, Viktor is an Infrastructure & Data Protection Engineer at Perfekt, supporting customers while continuing to deepen his expertise in cyber resilience.

When Viktor left Ukraine, he carried with him years of experience, deep technical expertise, and an unwavering determination to continue the career he had worked so hard to build. Today, he helps organizations strengthen their cyber resilience, drawing on the same resilience that helped him rebuild his own life.

Maybe that’s why this story resonates. Viktor’s resilience shaped his own future. Today, it helps him make a difference for others.

That’s what putting people first looks like: organizations like Perfekt investing in people, and technology like Commvault Cloud helping them thrive.

Chris DiRadoè responsabile dell’esperienza di prodotto presso Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In che modo i responsabili della sicurezza possono proteggere i propri dati più sensibili?

La sicurezza dei dati e dell’IA consente alle organizzazioni di individuare, classificare e gestire l’accesso ai dati sensibili tra utenti, sistemi e soluzioni di intelligenza artificiale.

Punti di forza

Data is the life force of modern businesses, helping guide key decisions and power AI initiatives. Given its value, knowing and protecting your data is essential.

  • 90% of organizations affrontiamoexposed sensitive cloud data that can be surfaced by AI. This makes visibility into data assets the first and most critical step in reducing enterprise risk. 
  • 40% of files uploadedinto shared with generative AI toolscontainsPersonal Identifying Information (PII) or Payment Card Industry (PCI) data. Such misuse of sensitive data causes significant risk for organizations when it comes to privacy and regulatory violations. 
  • Data discovery and classification form the foundation of effective security, helping enable organizations to identify sensitive data across structured, semi-structured, and unstructured environments.
  • Overpermissive access is one of the most persistent data risks for modern businesses. With users, applications, and service accounts often retaining unnecessary access to sensitive data, the “attack surface” is expanded.
  • Helping protect AI requires governing both training data and runtime interactions. Organizations need to verify that sensitive data is not exposed through inputs, outputs, or model behavior.
  • Regulatory compliance depends on strong data foundations. Strong classification and access governance enables organizations to enforce policies and demonstrate control.

Sensitive data now moves across clouds, applications, and AI workflows without clear visibility — creating exposure risks that traditional security controls cannot address alone. Commvault Data and AI Security helps organizations discover and classify sensitive data, govern access for both human and machine identities, and maintain compliance with GDPR, HIPAA, and PCI DSS across the full data lifecycle.


Why is sensitive data exposure the biggest security gap?

Data is the invaluable fuel that propels modern businesses. So, organizations have made it a priority to heavily invest in sophisticated security tools.

However, according to Varonis’ 2025 State of Data Security Report, 90% of organizations still have exposed sensitive cloud data. Similarly, 88% of organizations have stale but enabled ghost users.

Butthat’snot all.According to IBM’s Cost of a Data Breach Report 2025, 53% of breached organizations reported compromised customerPII. Thesestatistics paint a vivid image: though data is central to businesses, visibility and overall security remain critical issues. 

Data is no longer confined to structured databases. It exists across files, emails, cloud platforms, SaaS applications, and endpoints. Much of it is unstructured, duplicated, or unmanaged, making it difficult to track and protect.

AI is amplifying this problem. About40% of files uploaded to generative AI tools contains sensitive information, often without governance or oversight. As AI adoption grows, so does the number of systems and identities interacting with data.

Without visibility into what data exists and where it resides, organizations cannot effectively secure it. This lack of visibility is the root of the modern data security problem.


Quali sono i pilastri della sicurezza dei dati e dell’IA?

Per affrontare la sfida rappresentata dall’esposizione dei dati,le organizzazioni necessitano di un approccio strutturato che garantisca coerenza e controllo nella gestione dei dati. La sicurezza dei dati e dell’IA si fonda su tre pilastri fondamentali:individuazione dei dati,classificazione dei dati,and Data & AI Access Governance.

Ciascun pilastro colma una lacuna significativa:

  • Discovery provides visibility into where data resides across environments. This includes structured systems such as databases,as well as semi-structured and unstructured sources that are often overlooked.
  • Classification adds context by identifying the type and sensitivity of data. It enables organizations to distinguish between operational data,sensitive personal information,financial records,intellectual property,and other high-risk categories.
  • Access governance enables organizations to verify that data is used appropriately. It defines who or what can access data,under what conditions,and with what level of control.

These three pillars do not exist independently. They create a connected system that fully covers data and AI security. Discovery identifies the complete data landscape,classification defines the appropriate sensitivity,and access governance enforces control based on that context.

This model even extends beyond human users to include machine identities such as AI models. In modern environments,these non-human identities often represent a significant portion of data access activity. Bringing these pillars together can help organizations move from fragmented security controls to a unified,policy-driven approach.


In che modo le organizzazioni possono individuare e classificare i dati sensibili?

L’individuazione e la classificazione sono fondamentali per un modello di sicurezza dei dati efficace. Tuttavia, spesso sono le più difficili da implementare in modo efficace.

Ciò è dovuto al fatto che i moderni ambienti di dati sono altamente frammentati. Le informazioni sensibili sono distribuite su più piattaforme cloud, sistemi on-premise, applicazioni SaaS ed endpoint. Una parte significativa di questi dati è di natura non strutturata, il che ne complica l’identificazione e la categorizzazione.

Tra le sfide più rilevanti figurano:

  • Dati “ombra” che esistono all’insaputa degli amministratori, senza approvazione né controllo di sicurezza.
  • Formati non uniformi tra dati strutturati e non strutturati.
  • Rapida crescita dei dati dovuta all’adozione dell’intelligenza artificiale, che supera la capacità di classificazione manuale.

Per far fronte a questa situazione, le organizzazioni necessitano di capacità di individuazione scalabili e di framework di classificazione. Una corretta classificazione può attribuire un significato alle vaste quantità di dati esistenti. Ciò include in genere categorie quali le informazioni di identificazione personale (PII), le informazioni sanitarie protette (PHI), i dati PCI, la proprietà intellettuale, nonché chiavi e segreti.

Il valore della classificazione deriva dal modo in cui viene utilizzata. Una volta classificati i dati, le organizzazioni possono applicare efficacemente le politiche di conservazione e cancellazione, limitare o monitorare l’accesso e abilitare il mascheramento o la redazione dei campi sensibili.

Su larga scala, un approccio maturo all’individuazione e alla classificazione non si limita a garantire la copertura, ma contribuisce anche a produrre risultati significativi. Tra questi figurano una minore esposizione al rischio, una migliore applicazione delle politiche e una riduzione misurabile del rischio.


Quali sono i principali rischi legati a un accesso troppo permissivo?

Secondo una ricerca condotta daReliaQuest, il 99% delle identità cloud dispone di privilegi eccessivi. Analogamente, unostudio del 2025 del Ponemon Instituteevidenzia che il 61% delle aziende statunitensi ha subito violazioni dei dati da parte di personale interno negli ultimi due anni, con un costo medio di tali incidenti pari a ben 2,7 milioni di dollari.

Ciò dimostra che, anche quando le organizzazioni hanno una chiara comprensione dei propri dati, l’accesso rimane uno dei punti più deboli della sicurezza.

Si parla di accesso eccessivamente permissivo quando utenti, applicazioni o account di servizio dispongono di un accesso ai dati superiore a quello necessario. Si tratta di un problema molto diffuso, poiché i controlli di accesso vengono spesso concessi in modo generico per motivi di praticità e raramente rivisti.

L’impatto è significativo. Un accesso eccessivo aumenta la probabilità di esposizione accidentale, di rischi interni e di sfruttamento in caso di violazione.

Per affrontare questo problema, le organizzazioni devono innanzitutto esaminare attentamente i modelli di accesso. Ciò include individuare chi accede ai dati sensibili, quali sistemi o identità sono coinvolti e se tale accesso è in linea con le esigenze aziendali.

Particolare attenzione deve essere riservata agli account privilegiati e alle identità di servizio. Questi dispongono spesso di autorizzazioni estese e possono accedere a grandi volumi di dati sensibili su diversi sistemi.

In questo contesto, una governance efficace degli accessi è fondamentale. Ciò richiede:

  • Allineare le politiche di accesso alla classificazione dei dati.
  • Monitorare continuamente i modelli di utilizzo.
  • Identificare e correggere le deviazioni di accesso nel tempo.

Riducendo gli accessi non necessari, le organizzazioni contribuiscono a limitare la propria superficie di attacco e a migliorare la protezione complessiva dei dati.


In che modo le organizzazioni dovrebbero gestire i dati utilizzati dai sistemi di intelligenza artificiale?

L’adozione dell’IA si sta rapidamente diffondendo in ogni aspetto delle aziende moderne. Ciò introduce un nuovo livello di complessità nelle modalità di accesso, elaborazione e divulgazione dei dati.

I set di dati di addestramento spesso includono grandi volumi di dati provenienti da tutta l’organizzazione. Senza un’adeguata classificazione e governance, questi set di dati potrebbero contenere informazioni sensibili o soggette a normative.

Ciò comporta rischi in diverse fasi:

  • Durante la preparazione dei dati e l’addestramento.
  • Quando i modelli interagiscono con i dati in tempo reale.
  • Attraverso i risultati che potrebbero divulgare involontariamente informazioni sensibili.

Pertanto, la classificazione deve precedere l’addestramento del modello. Ciò significa convalidare e classificare tutti i dati utilizzati nei set di dati e rimuovere le informazioni sensibili quando necessario.

Allo stesso modo, dopo l’implementazione degli strumenti di IA, i team che si occupano dei dati devono valutare continuamente come i modelli utilizzano ed espongono i dati. Dovrebbero inoltre applicare meccanismi di controllo appropriati, come il mascheramento o la redazione, ove necessario.

I sistemi di IA non dovrebbero essere considerati separatamente dalla sicurezza dei dati. Essi rappresentano un’estensione delle modalità di utilizzo dei dati e devono essere gestiti di conseguenza. Integrando tali funzionalità di sicurezza dei dati e dell’IA nel più ampio ciclo di vita dello sviluppo dell’IA, le organizzazioni possono contribuire a ridurre i rischi pur continuando a favorire l’innovazione.


In che modo la classificazione dei dati favorisce la conformità normativa?

La conformità normativa dipende dalla capacità di identificare e controllare i dati sensibili. Normative quali il GDPR, l’HIPAA e il PCI DSS definiscono requisiti specifici su come i dati devono essere gestiti. Tuttavia, tali requisiti non possono essere applicati senza prima comprendere dove si trovano i dati soggetti a regolamentazione.

Ecco perché i programmi di conformità falliscono in assenza di una solida base di dati.

In questi casi, la classificazione dei dati funge da spina dorsale della conformità, mappando i dati alle categorie normative. Consente alle organizzazioni di applicare controlli mirati in base alla sensibilità dei dati e di far rispettare le politiche relative al ciclo di vita dei dati critici.

Ciò apre la strada a una miriade di funzionalità essenziali:

  • Applicazione delle politiche di conservazione e cancellazione
  • Limitazione dell’accesso ai dati soggetti a regolamentazione
  • Implementazione di controlli fondamentali sulla privacy

Inoltre, semplifica i processi di audit. Le organizzazioni possono dimostrare dove risiedono i dati sensibili, come sono protetti e chi vi ha accesso. La governance degli accessi rafforza ulteriormente la conformità garantendo che solo le identità autorizzate possano interagire con i dati regolamentati.

Insieme, la classificazione dei dati e i controlli di accesso ridefiniscono la conformità nell’era moderna, basata sull’intelligenza artificiale.


Conclusione: cosa richiede oggi una sicurezza efficace dei dati e dell’IA?

La sicurezza moderna dei dati e dell’IA non è più definita da difese perimetrali o controlli isolati. Richiede un approccio continuo e unificato che colleghi visibilità, classificazione e governance degli accessi lungo l’intero ciclo di vita dei dati.

Per dare vita a un approccio di questo tipo, le organizzazioni devono innanzitutto comprendere i propri dati, individuando con esattezza dove risiedono. Successivamente, devono controllare le modalità di accesso agli stessi. Infine, le organizzazioni devono assicurarsi che i sistemi di IA li utilizzino in modo responsabile. Queste funzionalità devono operare in sinergia, non in modo indipendente, per contribuire a ridurre l’esposizione e mantenere la fiducia.

Con l’aumento dei volumi di dati e l’accelerazione dell’adozione dell’IA, la sfida non consisterà più solo nel proteggere i dati, ma nel dimostrare dove si trovano i dati sensibili, chi può accedervi e come vengono protetti in tutti i sistemi. Chi adotterà un approccio strutturato e basato su politiche sarà in una posizione migliore per ridurre i rischi, soddisfare i requisiti normativi e promuovere l’innovazione con fiducia.

Domande frequenti

Che cos’è la sicurezza dei dati e dell’IA?

Data and AI security is the practice of discovering, classifying, and governing access to sensitive data across systems, users, and AI models. Commvault Data and AI Security delivers these capabilities across hybrid environments — enabling organizations to confirm that data remains visible, controlled, and protected throughout its lifecycle, including how it is used in AI training and outputs.

Perché l’esposizione dei dati sensibili rappresenta un rischio significativo?

L’esposizione dei dati sensibili rappresenta un rischio significativo perché spesso le organizzazioni non dispongono di visibilità su dove risiedono i dati e su chi può accedervi, aumentando così la probabilità di violazioni, uso improprio e infrazioni normative. Commvault contribuisce a mitigare questo rischio attraverso un approccio unificato che combina individuazione dei dati, classificazione e governance degli accessi in ambienti ibridi.

Quali sono i pilastri fondamentali della sicurezza dei dati?

The three core pillars of data security are discovery, classification, and access governance. Commvault delivers each — Data Discovery identifies where sensitive data exists across environments, Data Classification defines its sensitivity and type, and Data & AI Access Governance enforces access control aligned with business and regulatory policy.

Perché un accesso troppo permissivo è pericoloso?

Overpermissive access allows users, applications, and service accounts to access more data than necessary — increasing risk of accidental exposure, insider threats, and exploitation. Commvault Data & AI Access Governance addresses this by continuously monitoring access patterns, aligning permissions with data classification, and identifying and remediating access drift across hybrid environments.

In che modo le organizzazioni dovrebbero contribuire a proteggere i dati utilizzati dall’IA?

Organizations can protect AI data by classifying datasets before training and continuously monitoring how models access and expose data. Commvault Data and AI Security supports this through discovery, classification, and governance controls including masking, redaction, and access restrictions — helping ensure that sensitive data is not exposed through AI training, model behaviour, or outputs.

In che modo la classificazione dei dati contribuisce alla conformità?

Data classification supports compliance by identifying regulated data such as PII and mapping it to appropriate controls. Commvault Data Classification helps organisations enforce retention and deletion policies aligned with GDPR, HIPAA, and PCI DSS — and provides the audit-ready evidence needed to demonstrate how sensitive data is identified, protected, and governed.

Esplora le risorse correlate

Esplora

What are the Key Risks of Data & AI Security?

Explore how AI introduces new data vulnerabilities – from model training to exposure to runtime risks – and the layered practices organizations use to govern workloads responsibly.
Leggi l’articolo suabout What are the Key Risks of Data & AI Security?
Libro bianco

Analisi dei rischi di sicurezza legati all’IA

Un rapporto di valutazione della Readiness destinato al tuo CISO e al tuo CIO per comprendere cosa è cambiato con MCP 2.0 e cosa fare per preparare la tua organizzazione.
Leggi il white paperabout Analisi dei rischi di sicurezza legati all’IA


Punti di forza

  • Replace subjective claims about “ease of use” with a measurable data protection gearing ratio: protected capacity divided by the number of full-time administrators.
  • La misurazione della capacità protetta per FTE offre una visione più significativa dell’efficienza operativa rispetto alle metriche tradizionali, come i processi di backup per amministratore.
  • L’indice di protezione dei dati dovrebbe essere utilizzato come valore di riferimento prima della migrazione della piattaforma e misurato nuovamente in seguito per verificare i miglioramenti operativi.
  • Fattori quali gli ambienti multi-cloud, i requisiti di cyber-Recovery e gli obblighi di conformità possono influenzare il rapporto, pertanto esso dovrebbe essere valutato nel contesto di ciascun ambiente.
  • Le organizzazioni dovrebbero chiedere ai fornitori di impegnarsi a garantire risultati operativi misurabili, anziché affidarsi a affermazioni qualitative sulla semplicità.

Every vendor evaluation I have sat in eventually reaches the same dead end. One side says the platform is simple to run. The other side says their platform is simpler.

Nobody can prove either claim, so the conversation drifts to the demo, the reference call, the gut feeling in the room. That is not how you should be making a decision that determines how your team will spend the next five years.

I have run production data protection environments. I have watched teams get buried under fragmented tooling that promised automation and delivered tickets instead.

“Reduced complexity” is not a feeling you should have to take on faith. It is something you should be able to calculate.

La metrica che mancava al settore

We have started using a simple ratio internally and with customers: total protected capacity divided by the number of full-time staff required to run it. We call it the data protection gearing ratio.

Protected Capacity (PB) / FTEs = Data Protection Gearing Ratio

That’s it. No survey questions about satisfaction. No adjectives. A number, calculated from data you already have.

Here is why it matters more than the metrics it replaces. Calculating the number of backup jobs per person made sense a decade ago, when a job represented a discrete unit of manual effort. It does not reflect how modern platforms operate today, where automation absorbs the routine work and a single administrator can be accountable for petabytes, not job counts.

Measuring jobs per person in an automated environment tells you nothing about whether the automation is actually working.

Come funziona nella pratica

One clarification before the number, because it trips people up. Protected capacity means the full, uncompressed, undeduplicated size of the applications being protected, not the physical disk behind them.

That distinction matters because it is the whole point. Commvault’s own production environment protects 42,39 PB of application data on 9,26 PB of physical disk, an 81,91% space savings from deduplication and compression.

The ratio is not just a measure of how many petabytes a person can watch over. It is a measure of how much architecture is doing the work before headcount ever enters the picture.

With that in mind: Commvault runs its own production backup environment on 42,39 PB of protected capacity with two FTEs. That is a gearing ratio of 21.20 PB per FTE. Industry benchmarks for modern platforms typically land between 5 and 25 PB per FTE, depending on environment complexity, so that number sits at the high end of what is achievable today.

Metrico  Valore  Definizione 
Capacità protetta (front-end)  42,39 PB  Full, uncompressed, undeduplicated application size protected in our environment 
Capacità totale del disco  9,26 PB  Archiviazione fisica di destinazione 
Spazio totale utilizzato  7,89 PB  Current utilization 
Dati totali scritti  7,67 PB  Dati logici scritti su disco 
Risparmio di spazio  81,91%  Efficienza di deduplicazione e compressione 
FTE dedicati alla protezione dei dati  2  Number of full-time admins managing Commvault’s own production backup estate 

Data Protection Gearing Ratio = 42,39 PB / 2 FTEs = 21.20 PB per FTE

I want to be direct about what this number does not do. It does not account for a multi-cloud footprint, cyber recovery requirements, or a compliance-heavy application mix, all of which will pull the ratio down for reasons that have nothing to do with how good the platform is.

A ratio in isolation is not a verdict. A ratio measured before and after a migration is.

That is the actual use case. Baseline your current environment on your current tools. Set a target ratio based on your growth projections and your team’s capacity. Then hold your vendor to it after the implementation is done, not just during the sales cycle.

Le implicazioni a livello di consiglio di amministrazione

Se siete voi a dare l’approvazione per la migrazione a una nuova piattaforma, non vi viene semplicemente chiesto di fidarvi che la nuova piattaforma sia più facile da gestire. Vi viene chiesto di finanziare un risultato operativo specifico. Un obiettivo relativo al rapporto di protezione dei dati vi offre un modo per inserire tale risultato nel business case e verificarlo 12 mesi dopo.

Si tratta della stessa disciplina che applichiamo al tempo medio di recupero pulito (MTCR). La capacità di recupero non è qualcosa che si dichiara, ma qualcosa che si misura e si rimisura finché il dato non riflette la realtà. L’efficienza operativa merita lo stesso standard.

La sfida

Ask your current vendor for the gearing ratio of your own environment today. If they cannot produce it, that tells you something about how well they understand what “simple to manage” means for your team.

And if you are evaluating a new platform, do not accept “easier to use” as an answer. Ask what ratio they will commit to, and ask again after year one.

Domande frequenti

Q: What is the data protection gearing ratio?

A: The data protection gearing ratio measures the amount of protected data capacity managed by each full-time administrator. It provides an objective way to evaluate operational efficiency rather than relying on subjective impressions of platform usability.

Q: Why is this metric more useful than backup jobs per administrator?

A: Modern data protection platforms automate much of the routine work that previously required manual effort. As a result, counting backup jobs no longer reflects the true workload or efficiency of an operations team.

Q: What does “protected capacity” mean in this calculation?

A: Protected capacity refers to the full, uncompressed, and undeduplicated size of the application data being protected. This measurement reflects the actual workload managed by the platform rather than the physical storage consumed after optimization.

Q: Does a higher gearing ratio always indicate a better platform?

A: Not necessarily. Environmental complexity, including multi-cloud deployments, cyber resilience requirements, and regulatory obligations, can reduce the ratio even when the platform performs well. The metric is most valuable when comparing the same environment before and after a migration.

Q: How should organizations use the data protection gearing ratio during vendor evaluations?

A: Organizations should establish a baseline using their current environment, define a target ratio aligned with future growth, and ask vendors to commit to achieving measurable improvements after implementation. This approach shifts the conversation from marketing claims to verifiable business outcomes.

Q: What is the broader business value of this metric?

A: The data protection gearing ratio enables executives to quantify expected operational efficiency gains and include them in the business case for a platform investment. It also provides a benchmark that can be reviewed after deployment to confirm the promised results were achieved.

Rajiv Kottomtharayilè Chief Products Officer presso Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In thefirst episode of our STRIVE series on digital sovereignty, Commvault’s Alex Zinin and Osmium Data Group’s Max Mortillaro challenged one of the biggest misconceptions in the industry: Digital sovereignty isn’t a feature you buy – it’s a business problem you have to understand before you can solve.

This conversation picks up where that one left off. This time, I sat down with Thomas Maurer, EMEA Global Black Belt for Sovereign Cloud at Microsoft, to explore what happens after an organization decides sovereignty matters. How do executive teams move from broad concerns about regulation, jurisdiction, or geopolitical uncertainty into practical architectural decisions?

The answer, it turns out, is rarely as straightforward as choosing a cloud provider or selecting the right deployment model. It’s about asking better questions before making technical decisions.

Watch the full episode.

Punti di forza

  • Every organization defines digital sovereignty differently – and that’s exactly where the conversation should begin.
  • Sovereignty isn’t solved by technology alone. Legal, operational, architectural, and business considerations all shape the outcome.
  • Cloud and on-premises aren’t competing strategies. For many organizations, the future is a carefully designed combination of both.
  • Risk management – not fear – should drive sovereignty decisions.
  • Good architecture starts with understanding business requirements, not choosing infrastructure.

Sovereignty Means Different Things to Different Organizations

One of the first observations Thomas made was also one of the most important.

There is no universal definition for digital sovereignty. For one organization, it may simply mean meeting regulatory requirements or keeping data within a specific geography. For another, it may involve operational independence, business continuity, or preparing for geopolitical disruption. That difference matters because it changes the conversation entirely.

Too often, organizations assume there’s a standard sovereignty blueprint waiting to be implemented. In reality, the first challenge isn’t selecting technology – it’s understanding what problem the organization is actually trying to solve.

Only then does architecture begin to make sense.

Technology Should Follow Strategy

One theme that kept surfacing throughout our discussion was the temptation to jump straight into technical design.

It’s understandable. Architects naturally think about infrastructure, workloads, connectivity, and deployment models. But Thomas emphasized that the most successful projects begin somewhere else.

They begin by listening.

What concerns are driving the initiative? Is the objective regulatory compliance? Business continuity? Data residency? Operational control? Protection against geopolitical disruption?

Different answers lead to different architectures.

That may sound obvious, but it’s surprising how often organizations begin evaluating solutions before they’ve aligned on the business outcome they’re trying to achieve.

Sneak Peek: Start With Risk, Not Assumptions

One of the most practical moments in our conversation comes when Thomas and I discuss why sovereignty initiatives should begin with a risk assessment – not an architectural diagram.

Every organization has a different risk appetite. A Formula 1 team, a government agency, and a global manufacturer won’t make the same decisions, nor should they. The key is understanding which risks matter most to your business, what trade-offs you’re willing to make, and then designing an architecture that supports those decisions.

As Thomas points out, there is no perfect solution – only informed trade-offs. The earlier organizations adopt that mindset, the stronger their sovereignty strategy will be.

‘Cloud or On-Premises?’ Is the Wrong Question to Ask

One of the more interesting parts of the conversation challenged another common assumption – that organizations must choose between public cloud and private infrastructure.

Thomas described a very different reality.

Many organizations aren’t replacing one with the other. They’re designing environments where workloads can move between them based on business need, regulatory requirements, or resilience considerations.

That flexibility changes how we should think about architecture. Instead of asking whether cloud or on-premises is better, the more useful question becomes:

“Where does this workload belong today – and could that answer change tomorrow?”

When sovereignty becomes part of the design process, workload mobility becomes just as important as workload placement.

Architecture Is Only Part of the Equation

Another takeaway I appreciate is Thomas’s reminder that architecture alone doesn’t solve sovereignty.

  • Contracts matter.
  • Legal frameworks matter.
  • Operational processes matter.
  • The people responsible for running the environment matter.

None of those disciplines can operate in isolation. Sovereignty requires legal, security, compliance, and infrastructure teams to work together from the beginning – not hand projects off to one another after decisions have already been made.

That’s a familiar pattern for anyone working in cyber resilience. The strongest outcomes rarely come from individual teams. They come from coordinated ones.

Risk Should Drive Every Decision

Toward the end of our discussion, the conversation naturally shifted toward risk. For me, this is where sovereignty starts to feel much more familiar. Every resilience project begins by asking what the organization is trying to protect, what threats matter most, and how much risk it’s willing to accept.

Digital sovereignty is no different.

Rather than searching for a perfect solution, organizations need to identify the specific sovereignty scenarios they’re concerned about and then determine which architectural, operational, or contractual controls best address those risks.

That shift – from feature comparison to risk management – is what ultimately leads to better decisions.

Why This Conversation Matters

Digital sovereignty continues to evolve rapidly. New regulations will emerge. Technology will change. Geopolitical realities will continue to shift.

That means sovereignty isn’t something organizations solve once. It’s something they regularly evaluate as business priorities and external risks evolve.

The organizations that succeed won’t necessarily have the most restrictive architectures. They’ll have the clearest understanding of their business objectives, the discipline to assess risk thoughtfully, and the flexibility to adapt as those risks change.

Ultimately, digital sovereignty isn’t something organizations can buy off a shelf. It’s an exercise in understanding risk, managing dependencies, and making informed trade-offs long before those decisions are tested.

Guarda l’episodio completo

In this STRIVE episode, Thomas and I discuss:

  • Why sovereignty means different things to different organizations.
  • How executives should approach sovereignty strategy.
  • Public cloud versus private cloud – and why it’s often not an either/or decision.
  • Why risk management should guide architectural choices.
  • The role of resilience in modern sovereignty planning.

Guardalo subito.

Domande frequenti

Q: Does digital sovereignty mean keeping everything on-premises?

A: No. Many organizations adopt hybrid approaches that balance cloud capabilities with specific sovereignty requirements.

Q: Where should sovereignty projects begin?

A: Start by defining the business problem and understanding the risks you’re trying to mitigate before evaluating technology.

Q: Is sovereignty purely a technical issue?

A: No. It requires collaboration between legal, compliance, security, operations, and architecture teams.

Q: How does sovereignty relate to resilience?

A: Both disciplines focus on maintaining operational continuity by reducing exposure to risks that could disrupt the business.

Q: What’s one big mistake organizations make in regard to digital sovereignty?

A: Jumping into architectural decisions before agreeing on what sovereignty means for their organization.

Q: What should executives ask first in terms of planning for digital sovereignty?

A: “What problem are we trying to solve?” Everything else follows from that answer.

Darren Thomsonis Vice President and Chief Technology Officer, EMEA, at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Punti di forza

  • Terraform manages desired state – it provisions and configures infrastructure from code.
  • Cloud Rewind captures actual deployed state – it helps restore environments to a known-good point in time.
  • I file di stato di Terraform e la cronologia di Git non sono strumenti di ripristino; non registrano ciò che era effettivamente in esecuzione.
  • Cloud Rewind consente di ripristinare l’infrastruttura indipendentemente dal fatto che le modifiche siano state apportate tramite IaC, dalla console o tramite intervento manuale.
  • Insieme, Terraform e Cloud Rewind contribuiscono a fornire ai team una strategia completa per le operazioni di tipo “ cloud ”: sviluppare velocemente, ripristinare ancora più velocemente.

If your team runs Terraform, you already know how powerful IaC can be. You define what you want, apply it, and your cloud environment materializes. Change management becomes repeatable. Provisioning becomes predictable.

But there is a gap between provisioning infrastructure and recovering it – and it matters most when something goes wrong at 2 a.m.

Terraform and Cloud Rewind address different parts of the cloud lifecycle. Understanding the difference helps you avoid a dangerous assumption: that your IaC tooling doubles as a recovery plan.

In che modo Terraform e Cloud Rewind si differenziano

Terraform is a provisioning tool. It defines and manages desired state. When you revert a Terraform change, you are re-applying a previous desired configuration – not restoring the actual deployed environment that was running before the incident.

That distinction matters. Terraform state is not a historical recovery snapshot.

Cloud Rewind captures actual cloud configuration state and stores point-in-time snapshots. When something breaks, you do not rebuild from code and hope the environment comes back intact. You restore a known-good environment – the one that was actually running – regardless of how the change that caused the problem was introduced.

Terraform Design  Cloud Rewind Design 
Gestione dello stato desiderato  Ripristino dello stato effettivo 
Provisioning dell’infrastruttura  Ripristino dell’infrastruttura 
Applica le modifiche  Annulla le modifiche 
Fonte di verità = codice  Fonte di verità = ambiente distribuito 
Orientato al futuro  Retrospettivo 
Creazione e aggiornamento  Recuperare e ricostruire 
Aiuta a ripristinare la configurazione desiderata  Aiuta a ripristinare lo stato di distribuzione a partire da un momento specifico 

Quando Terraform raggiunge i propri limiti

Anche negli ambienti IaC più consolidati si verificano situazioni di ripristino in cui la ricostruzione a partire dal codice non è sufficiente. Si consideri quanto segue:

  • Una modifica all’infrastruttura non riuscita, già implementata in produzione.
  • Cancellazione accidentale delle risorse di cloud .
  • Deriva dell’infrastruttura causata da modifiche manuali o fuori banda.
  • Modifiche apportate al di fuori di Terraform che non si riflettono nel codice o nello stato.
  • La necessità di ripristinare le infrastrutture esattamente nello stato in cui si trovavano in un determinato momento.
Terraform does not maintain historical cloud state. It re-applies a desired configuration – it does not restore what was actually deployed and running. “Rewind to 2:15 PM yesterday” is not a Terraform feature. It is a Cloud Rewind feature.

Un ripristino che dipende dalla disponibilità, dall’accuratezza e dalla completezza del codice Terraform, dei file di stato e della cronologia delle versioni comporta un rischio concreto. In caso di incidente reale, tali condizioni non sono garantite.

Due strumenti, un’unica strategia completa

Terraform helps you automate infrastructure creation and change management. Cloud Rewind helps you recover infrastructure quickly and consistently when deployments fail, resources are deleted, infrastructure drifts, or your team needs to restore a known-good environment.

They complement each other. Terraform is designed to make your cloud environment repeatable. Cloud Rewind is designed to make it recoverable.

Build with Terraform.Ripristina con Cloud Rewind.

Domande frequenti

Q: Does Terraform provide point-in-time recovery?

A: No. Terraform re-applies a desired configuration from code. It does not maintain historical snapshots of your deployed cloud environment. If the change that caused an incident is not captured in your Terraform state or Git history – for example, a console change or infrastructure drift – Terraform cannot help you restore it.

Q: What happens when changes are made outside Terraform?

A: Console changes, manual interventions, and out-of-band configurations are common in real environments. Terraform does not track them. Cloud Rewind captures actual deployed state – regardless of how a change was introduced – so you can restore a known-good environment even when your IaC does not reflect what was running.

Q: Is Cloud Rewind a replacement for Terraform?

A: No. They solve different problems. Terraform is your provisioning and change management tool. Cloud Rewind is your recovery tool. Most teams that use one can benefit from both – they cover different parts of the cloud operations lifecycle.

Q: What kinds of incidents does Cloud Rewind address?

A: Cloud Rewind is designed for scenarios where rebuilding from code is not enough: failed deployments already in production, accidental resource deletion, infrastructure drift, and cases where teams need to restore an environment to a specific historical point in time.

Q: Does Cloud Rewind require teams to stop using Terraform?

A: No. Cloud Rewind works alongside your existing IaC workflows. Teams continue to use Terraform for provisioning and change management and use Cloud Rewind when they need to recover from a real incident.

Cailin Pitcherè Senior Portfolio Marketing Manager presso Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Punti di forza 
  • Commvault integrates frontier AI vulnerability discovery into its risk-based security program rather than relying on AI as a standalone solution.
  • Every AI-generated finding is reviewed and validated by humans before remediation decisions are made.
  • Frontier AI complements established security practices such as static analysis, dynamic analysis, and penetration testing by expanding code coverage and identifying more complex exploit scenarios.
  • Commvault maintains strict governance over source code, vendor access, and vulnerability handling.
  • Commvault is investing in scalable vulnerability management processes in order to respond efficiently as AI increases the volume of potential security findings.

Across the security industry, AI and large language models are being applied to vulnerability discovery – helping teams evaluate more code, explore more attack paths, and identify exploitable conditions faster than manual review alone.  

This is not a niche experiment. It is a shift in how thorough a security evaluation can be, and it is changing what customers reasonably expect from their software vendors. 

Customers are regularly asking their software vendors: Do you test your own products against the same methods a threat actor might use? Are the processes behind that testing rigorous enough to keep pace? These are the right questions to ask. 

Our Approach: Strong Processes, no Single Tool

Commvault’s security posture is built on strong, repeatable processes rather than dependence on any single tool, model, or vendor.  

Vulnerability management follows an established, risk-based framework: Findings are assessed for practical exploitability, prioritized by severity and exposure, and remediated through our standard development lifecycle. That framework applies the same way regardless of whether a finding comes from a penetration test, an external researcher, or AI. 

AI vulnerability discovery is integrated into this framework as an additional capability, not a separate program running on its own rules. Candidate findings generated through AI methods are treated as inputs that require human confirmation of exploitability before any remediation action is taken. That step helps prevent two failure modes at once: under-prioritizing genuine risk and burning cycles on false positives. 

AI Alongside Established Security Practices

AI methods do not replace the disciplines that have always defined responsible vulnerability management. Static analysis, dynamic analysis, penetration testing, and established scanning tools remain essential parts of our program.  

What AI adds is coverage depth: the ability to evaluate a broader set of code paths, model more complex exploit conditions, and surface findings that require contextual understanding rather than simple pattern matching. 

Our vulnerability program is tool-agnostic and model-agnostic by design. We are not dependent on any single vendor or model, and new approaches can be added as they prove out, without re-architecting how findings are governed or remediated. The advantage isn’t which model we use but whether the process behind it is disciplined enough to act on what that model finds. 

Governance and Controls

Every AI scan we run operates under the same governance principles: 

  • AI models are vetted before used. Any vendor and tooling access is governed by formal NDA and engagement terms.
  • Findings are processed through the same security engineering review pipeline used for every other vulnerability source.
  • No AI-generated finding is acted upon without human triage and exploitability confirmation.
From Candidate Finding to Confirmed Fix

Findings generated through AI are treated as candidates, not confirmed vulnerabilities. Each one is assessed by engineers and product security experts for practical exploitability in realistic customer environments.  

Severity ratings are assigned based on exposure, exploitability, and impact – not on how the finding was discovered. Confirmed vulnerabilities move through the same remediation timelines and escalation paths as any other source, with priority set by severity and exposure. 

First Patch Tuesday Disclosures – August 2026

Our inaugural Patch Tuesday, published August 11, 2026, includes the following disclosures: 

CVE ID  Severity  Sintesi 
CVE-2026-13737  Critico  CommServe contained an allowlist bypass affecting command execution authorization.  
CVE-2026-13738  Critico  CommServe contained an authorization bypass affecting a limited set of command execution operations.  
CVE-2026-13739  Elevata  A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) related to the handling of arbitrary target URLs. 

 

Full technical advisories, including affected versions and remediation guidance, are available on our Dove trovare risorse aggiornate. Read more about the move to a monthly cadence in Bringing  Trust to CVE Disclosures 

Why Operational Readiness Matters More Than Any Single Tool

As AI vulnerability discovery becomes standard practice across the industry, the volume of potential findings that security teams need to evaluate will keep rising. The question that matters for any enterprise software vendor isn’t which AI model they use. It’s whether their vulnerability management process is mature enough, and scalable enough, to handle that throughput without creating a backlog that increases customer exposure. 

We pair our investment in AI with an equal investment in the process infrastructure needed to act on what it finds: triage capacity, severity prioritization, remediation tracking, and coordinated disclosure practices. Our investment is only as valuable as the response capability behind it. 

Domande frequenti

Q: What is Commvault doing with frontier AI security testing? 
A: We actively evaluate our products using AI methods as part of our structured security engineering program. We are being thoughtful about testing different models and harnesses so that we find any potential vulnerabilities previously undiscovered by humans and or existing testing. That work follows the same vulnerability management process as every other form of testing. This is underway today – it isn’t a roadmap item. 
Q: How is Commvault preparing for AI vulnerability discovery? 
A: We built a program that is model-agnostic and tool-agnostic by design. Our goal is to make sure our security engineering practice can incorporate the best available methods across a range of AI tooling, inside one consistent governance and risk management framework. 
Q: Is Commvault using these models safely? 
A: Yes. All AI scans are thoroughly vetted. Any vendor and tool access is governed by formal NDA and engagement terms, and every AI-generated finding requires human confirmation of exploitability before any remediation action is taken. 
Q: How is Commvault scaling vulnerability management for the AI era? 
A: Our focus is on making sure the response process scales with discovery volume and discovery pace. As AI increases the number of potential findings our teams need to review, we’re investing in risk-based triage, consistent remediation service level agreements, and the operational infrastructure needed to act on higher discovery throughput within accelerated timeframes to decrease exposure for customers. 

Bill O’Connell is Chief Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

When frontier AI models started making headlines, most of the discussion centered on one question: What happens when attackers gain access to them? 

It’s a fair question.  

Models capable of discovering vulnerabilities faster, chaining exploits together, and operating at unprecedented speed naturally raise concerns for every CISO.  

But after spending time talking with customers over the past several months – and in my conversation with Tim Zonca, Commvault’s VP of Portfolio Marketing, in this episode of STRIVE – I think there’s an even more important question emerging. 

What happens to resilience itself? 

Because while frontier AI will undoubtedly accelerate cyber threats, it’s also accelerating something else: Enterprise complexity. 

Watch the episodio. 

 Punti di forza 

  • Frontier AI isn’t just accelerating cyberattacks – it’s accelerating enterprise complexity.  
  • Vulnerability management isn’t disappearing, but the speed and scale of discovery are changing dramatically.  
  • AI systems introduce entirely new recovery dependencies, including agents, vector databases, embeddings, and distributed state.  
  • Organizations need a coherent understanding of their environments before they can recover them.  
  • The next generation of resilience will depend on trusted systems of record that explain what happened, why it happened, and how to recover confidently.  
The Conversation Has Changed 

One thing Tim and I discuss early in the episode is how differently organizations are reacting to frontier AI. 

  • Some see an entirely new class of cybersecurity challenge. 
  • Others view it as simply the next evolution of vulnerability management. 

What’s interesting is that neither perspective is necessarily wrong. 

The processes organizations use to identify, prioritize, and remediate vulnerabilities remain familiar. But the pace at which AI can discover those vulnerabilities – and uncover entirely new chains of attack – is unlike anything we’ve seen before.  

That’s the shift. 

The work isn’t fundamentally different. The speed is. 

When AI Changes the Shape of Recovery 

Most conversations about AI focus on security and prevention: 

  • How do we secure models? 
  • How do we protect prompts? 
  • How do we defend against AI-assisted attacks? 

Those are important questions. But resilience introduces a different one: What exactly are we recovering? 

Traditional enterprise applications already involve complicated relationships between infrastructure, applications, and data. AI expands that picture considerably. Now there are agents operating across multiple systems. Vector databases. Embeddings. Models interacting with different data sources simultaneously. It’s become far more than a traditional application stack.  

Recovery is no longer about restoring an application. It’s about restoring an ecosystem. 

Sneak Peek: Check This Out 

In this moment from our STRIVE discussion, Tim and I discuss the growing complexity of AI stacks, what coherent recovery is (and why it matters), and how Commvault is helping our customers with full AI-stack recovery. 

Why Coherency Matters 

One idea that keeps surfacing throughout our conversation is coherence. 

For years, organizations have worked to map application dependencies, understand infrastructure relationships, and identify critical services. AI makes that challenge significantly more difficult. 

Applications no longer interact with a single database or service. They may depend on multiple models, agents, data stores, and orchestration layers – all changing dynamically. 

Understanding those relationships isn’t just an architectural exercise anymore. 

It’s a recovery requirement. 

Because if you don’t understand what makes up the system, it’s difficult to know whether you’ve actually recovered it. 

A New System of Record 

Another concept from Tim that I found compelling is the idea of a system of record for the AI era. Historically, systems of record gave organizations confidence in business data. Customer records lived in CRM platforms. Financial records lived in ERP systems. 

AI changes that expectation. 

Organizations increasingly need trusted visibility into how data is used, what agents interact with it, why decisions are made, and whether restored environments represent a known-good state.  

That doesn’t replace resilience. It strengthens it. Because confidence in recovery depends on confidence in what you’re recovering. 

AI Can Also Help Solve the Problem 

As organizations struggle to understand increasingly distributed environments, AI becomes a powerful tool for discovery, classification, and policy recommendation.  

Rather than manually identifying relationships across sprawling environments, organizations can use AI to help identify dependencies, recommend protection policies, and continuously update those relationships as environments evolve. 

That’s an important shift. 

The same technology that’s adding to organizational complexity may also become one of the best tools for managing it. 

Why This Conversation Matters 

Frontier AI isn’t simply introducing another cybersecurity challenge. It’s forcing organizations to rethink resilience itself. 

Recovery is becoming less about individual systems and more about restoring trusted business operations across increasingly intelligent environments. That means resilience strategies must evolve alongside the technologies they’re protecting. 

Organizations that prepare for that shift won’t just recover faster. They’ll recover with greater confidence. 

Guarda l’episodio completo 

In this conversation, Tim and I explore: 

  • How frontier AI is changing enterprise risk.  
  • Why vulnerability management is entering a new phase.  
  • What AI means for modern recovery architectures.  
  • The role of coherent recovery across AI-enabled environments.  
  • Why trusted systems of record will become increasingly important.  

Guardalo subito. 


Domande frequenti 

Q: What are frontier AI models? 
A: Frontier AI models are the latest generation of highly capable AI systems designed to solve increasingly complex reasoning and cybersecurity tasks. 
Q: Why are organizations concerned about them? 
A: They dramatically accelerate vulnerability discovery, exploit chaining, and security research, increasing both defensive and offensive capabilities. 
Q: How does AI change cyber resilience? 
A: AI introduces new dependencies – including agents, models, vector databases, and distributed states – that make recovery more complex. 
Q: What is a coherent recovery strategy? 
A: It’s an approach that restores not only data, but also the applications, infrastructure, dependencies, and AI components required for trusted business operations. 
Q: What is a system of record in the AI era? 
A: It’s a trusted source that helps organizations understand what happened, why it happened, and whether recovered systems represent a known-good state. 
Q: What should organizations do now? 
A: Begin mapping AI dependencies, understand how AI changes recovery requirements, and develop resilience strategies that account for increasingly intelligent application environments. 

Chris Mierzwa is Senior Director of Portfolio Marketing at Commvault. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Protezione unificata dei dati | Recovery dopo un attacco ransomware | Cleanroom Recovery | Carichi di lavoro ibridi

Come unificare la protezione dei dati su ogni carico di lavoro ibrido

Commvault® Cloud helps organizations discover, govern, and unify workload protection, allowing teams to rebuild critical services quickly after a cyber incident.


You’re the VP of IT Operations. It’s 2:00 a.m. on a Saturday. Your SecOps team just confirmed ransomware has encrypted files across three regions. Your last backup job completed successfully – but when your team attempts to restore the ERP system, the application fails to start.

The backup was marked successful. The data was present. But the dependencies, transaction logs, and service relationships were never captured in a consistent, recoverable state. Recovery isn’t just about data – it’s about rebuilding services.

This scenario plays out across hybrid environments every day. Modern enterprises run on interconnected cloud-native services, Kubernetes clusters, hybrid databases, and SaaS platforms – none of which recover cleanly from a simple file restore. Fragmented protection strategies designed for a simpler era leave organizations exposed at exactly the moment resilience matters most.

Commvault Cloud is an AI-enabled platform designed to help organizations discover, govern, and unify data protection across cloud-native, hybrid, and on-premises workloads – from a single control plane. Capabilities such as AI-enabled workload discovery, Cleanroom Recovery, Cleanpoint Identification, Threat Scan, and Command Center orchestration help teams validate recovery readiness and rebuild critical services in a controlled sequence after a cyber incident. 

Il 45%

of organizations are repeat ransomware victims – meaning fast recovery without clean validation reinfects as often as it restores. 
ESG Research — Zero Trust and Ransomware Protection Report 

What Is Unified Data Protection – and Why Does It Matter? 

Unified data protection is a backup and recovery approach that helps organizations govern the broadest range of workloads – including cloud databases, Kubernetes, SaaS, hypervisors, and on-premises systems – from a single control plane, rather than managing separate tools and policies for each environment.Commvault Cloud Unityè progettato per supportare questo approccio, aiutando i team a ridurre la complessità operativa e a mantenere una protezione coerente negli ambienti ibridi e multi-cloud.

Fragmented data protection strategies can create invisible gaps: inconsistent policies across environments, coverage blind spots that surface only during recovery, and manual overhead that scales poorly as workloads diversify. When ransomware strikes or an outage occurs, teams may discover too late that critical workloads were not protected consistently. A unified approach is designed to help address this by bringing all workloads under a centralized policy engine – so protection status, retention schedules, and recovery workflows are governed from one place.

  • Commvault Cloud workload coverage: Unified protection across cloud databases (AWS RDS, Azure SQL, SAP HANA, Oracle), hypervisors (VMware, Hyper-V), Kubernetes (AKS, EKS, GKE), SaaS (Microsoft 365, Salesforce, Google Workspace), and on-premises infrastructure.
  • Unified control plane: All workloads managed from a single AI-enabled Command Center –helping reduce fragmented policy sets and manual operational overhead.
  • AI-enabled discovery and tagging: Automated workload inventory and classification can help teams identify coverage gaps and bring unprotected resources under policy.
  • TCO analysis: Real-time visibility into protected status and cost drivers can support budget governance across cloud, hybrid, and on-premises environments.

In che modo Commvault Cloud ti aiuta a individuare e gestire la protezione dei carichi di lavoro?

Effective data protection depends on knowing what you have before an incident occurs – not discovering gaps during recovery. Commvault Cloud is designed to help organizations continuously discover, classify, and apply backup policies across hybrid and multi-cloud assets, so coverage stays current as environments change.

Commvault Cloud begins with AI-enabled discovery –automatically inventorying cloud-native and hybrid assets, identifying resources without policy coverage, and bringing workloads under centralized governance in Command Center. Policies can be applied consistently across accounts, regions, and clouds, with real-time visibility into protected status and cost. Because environments change continuously – new workloads deployed, configurations updated, cloud resources spun up – discovery is designed to run as an ongoing process rather than a one-time assessment, helping teams maintain accurate coverage without manual audits.

  • AI-enabled discovery: Continuously inventories cloud-native and hybrid assets, identifies coverage gaps, and brings new workloads under centralized policies.
  • Centralized policy engine: Command Center applies consistent retention schedules, backup frequency, and copy policies across multi-cloud, hybrid, and on-premises workloads from a single interface.
  • Commvault Threat Scan: Continuously monitors backup data for anomalies, encryption activity, and malware indicators so security teams can act before recovery begins.
  • Cross-region and cross-cloud copies: Backup copies can be created across regions and cloud providers to support compliance, data residency requirements, and resilience posture.

Perché gli strumenti frammentati falliscono in fase di Recovery?

L’89% delle organizzazioni operate in environments environments with more than one cloud, including hybrid cloud and multi-cloud set ups, yet most recovery failures don’t stem from a lack of backup jobs – they stem from protection that wasn’t built for the environment being recovered. Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.

Recovery failures surface the gap between a backup that ran and a service that actually restarts. Crash-consistent snapshots may restore raw data while leaving transaction logs, service dependencies, and cluster configurations in an inconsistent state – meaning the application cannot start even when the data is present. Unified data protection can help address this by ensuring workloads are protected in a way that reflects how they operate, and by validating recovery readiness before an incident forces the question.

Commvault Cloud supporta i responsabili della sicurezza che richiedono una recuperabilità pronta per gli audit, i team IT che gestiscono ambienti ibridi e multi-cloud, nonché i soggetti interessati al cloud e alla conformità responsabili della protezione e della convalida dei carichi di lavoro critici. Commvault è stata riconosciuta nell’IDC MarketScape: Worldwide Cyber-Recovery 2025 Vendor Assessment per i suoi punti di forza nell’architettura di cyber-recupero, nell’integrazione dell’ecosistema di sicurezza e nell’ampiezza dei carichi di lavoro.

  • Continuous backup monitoring: Threat Scan monitors backup data for malware indicators, encryption activity, and anomalous behavior –with alerts integrated into SIEM and SOC tools for coordinated incident response.
  • Commvault Cleanroom Recovery: Designed to stage restoration in an isolated environment so teams can validate data integrity and confirm systems are threat-free before returning to production – reducing reinfection risk.
  • Cleanpoint Identification: Designed to help pinpoint when data may have become compromised, providing more precise selection of a verified recovery point and supporting minimization of data loss.
  • Orchestrated service recovery: Command Center workflows can restore dependent services in sequence – helping reduce the manual coordination burden during high-pressure recovery events.
  • Scalable on-premises protection: HyperScale supports on-premises protection for hybrid environments, with streamlined onboarding and management through Command Center.

Microsoft Azure (Cloud)

Individuazione, classificazione e backup basato sulle applicazioni per Azure SQL, macchine virtuali Azure, Azure Blob e carichi di lavoro ospitati su Azure.

Microsoft Entra ID (Identità)

Identity-based access governance integration – connects classification-based controls to Entra ID-managed users and AI service principals for policy enforcement.

AWS (Cloud)

Application-aware protection across AWS-hosted workloads including RDS, EC2, and EKS – via native API integrations.

Okta (Identità)

Identity-based access policy integration –connects Commvault access governance to Okta-managed identities for role-based enforcement.

Cloud Google (Cloud)

Individuazione e backup specifico per le applicazioni su Google Cloud Storage, GKE (Google Kubernetes Engine) e carichi di lavoro collegati.

ServiceNow (ITSM)

Integration for incident and audit workflows – connects Commvault threat scan events and recovery actions to ServiceNow ticketing for compliance reporting.

Come funziona


Discover and protect

AI-enabled discovery inventories cloud-native, hybrid, and on-premises assets to identify unprotected workloads. Command Center applies centralized policies – including backup frequency and retention – across environments, with cross-region and cross-cloud copies to support resilience and compliance. 


Monitor and detect

Threat Scan monitors backup data for anomalies, encryption activity, and malware indicators. Alerts integrate with SIEM and SOC tools, helping teams isolate affected data and plan a response before recovery begins. 


Validate and recover

Cleanpoint Identification helps pinpoint when data may have been compromised and surfaces viable recovery points. Cleanroom Recovery stages restoration in an isolated environment for validation before production restore, while Command Center orchestrates service recovery in the correct sequence to support controlled, reinfection-resistant recovery.


Before unified data protection, the most dangerous moment in incident response was often the restore itself – when teams discovered coverage gaps they didn’t know existed. With Commvault Cloud, teams can move from reactive gap discovery to proactive governance: understanding which workloads are protected, at what policy level, and whether recovery points have been validated. That shift – from hoping a backup worked to demonstrating that it can – can make the difference between a measured recovery and an extended outage.

Sei pronto a unificare la protezione su tutti i carichi di lavoro ibridi?

Scopri come Commvault Cloud può aiutare il tuo team a individuare, gestire e ripristinare ogni carico di lavoro in modo efficiente.

Domande frequenti

Che cos’è la protezione unificata dei dati?

Unified data protection is an approach to managing backup and recovery across cloud-native, multi-cloud, and on-premises workloads from a single control plane. Commvault Cloud supports this by applying consistent policies and coverage across environments – helping teams reduce operational complexity and maintain visibility into protection status.

Perché le strategie di backup frammentate falliscono in fase di Recovery?

Le strategie di backup frammentate possono creare criteri incoerenti, lacune nascoste nella copertura e un sovraccarico di lavoro manuale che si adatta male agli ambienti ibridi.

Commvault® Cloud addresses this with a unified control plane, centralized policies, and AI-enabled discovery – helping organizations identify and close gaps before they impact recovery.

In che modo Commvault Cloud supporta la protezione dei dati per i carichi di lavoro ibridi?

Commvault Cloud delivers unified data protection across cloud, SaaS, Kubernetes, and on-premises environments through a single AI-enabled platform. The Command Center, AI-enabled discovery, and Cleanroom Recovery work together to centralize policies, identify coverage gaps, and help validate data before production restoration –supporting a more controlled recovery process.

Che cos’è Cleanroom Recovery e come funziona?

Cleanroom Recovery offre un ambiente isolato per ripristinare e convalidare i dati in modo sicuro prima dell’utilizzo in produzione. Combinando la Threat Scan con la convalida a livello di applicazione, aiuta il vostro team a ridurre il rischio di reinfezione e a eseguire il ripristino con maggiore controllo dopo un incidente informatico.

In che modo la protezione unificata dei dati supporta i requisiti RTO e RPO?

Commvault Cloud aiuta ad allineare la protezione dei dati alle priorità aziendali e supporta gli obiettivi di RTO e RPO. I flussi di lavoro di ripristino orchestrati in Command Center e Cleanpoint Identification, combinati con un piano di controllo unificato, aiutano a ridurre i tempi di inattività, a migliorare la coerenza e consentono ai team di monitorare lo stato della protezione e di affrontare le lacune in modo proattivo.

Quali integrazioni supporta Commvault Cloud per la risposta alle minacce?

Commvault Cloud si integra nativamente con Microsoft Azure, Entra ID, AWS, Google Cloud, Okta e ServiceNow. I segnali di Threat Scan vengono instradati verso gli strumenti SIEM e SOC, mentre le azioni di ripristino si collegano a piattaforme ITSM come ServiceNow per il tracciamento degli incidenti e la generazione di report di audit.

Risorse correlate

Solution Brief

Protezione dei dati sicura e resiliente

Scopri come la protezione dei dati moderna combini backup immutabili, resilienza al ransomware e Recovery rapido per le operazioni aziendali.
Leggi la scheda informativaabout Protezione dei dati sicura e resiliente
eBook

5 Questions Most Data Protection Providers Won’t Answer

Scopri le domande fondamentali da porre durante la valutazione dei fornitori per individuare i costi nascosti e verificare le reali capacità di Recovery.
Scarica l’eBookabout 5 Questions Most Data Protection Providers Won’t Answer

For years, cyber resilience has been defined by technology – security controls, sophisticated detection capabilities, and increasingly robust backup strategies designed to prevent attacks or recover more quickly. Those investments remain essential, but they are no longer enough. 

AI has fundamentally changed the nature of cyberattacks, which now move at a speed that challenges even mature organizations. As the window between compromise and business disruption continues to shrink, resilience is becoming less about preventing every attack and more about keeping the enterprise running when prevention inevitably falls short. 

That shift is at the heart of IDC’s new report, Resilience Operations: The Discipline that Makes Readiness Provable. Based on a survey of more than 500 North American organizations, the report argues that resilience is evolving into a cross-functional operating discipline that connects business priorities with cybersecurity, ITOps, and disaster recovery. More importantly, it reveals several gaps that suggest many organizations are still preparing for a threat landscape that no longer exists. 

Here are the insights that stood out. 

Recovery should begin with business outcomes – not technical ones.

Historically, recovery planning has focused on restoring infrastructure as quickly as possible, with success judged by recovery time objectives, backup completion rates, and application availability. While those measures remain valuable, they don’t necessarily answer the question executives care about most: When can we get the business back online? 

IDC argues that resilience should be anchored to business outcomes rather than technical milestones – restoring the capabilities that allow the organization to serve customers, generate revenue, and meet its obligations. That may sound like semantics, but it changes how recovery priorities are established. Technology becomes the means to an end rather than the end itself. 

Most organizations still haven’t defined what matters most.

Nearly 6 in 10 organizations have not fully defined their minimum viable business (MVB) – the smallest set of functions, systems, processes, and data required to continue operating after a disruption. 

Without a shared understanding of what the business truly depends on, every movement during recovery becomes reactive. By defining your MVB before a crisis, you’ll enable faster decisions, better coordination during recovery, and ultimately a more resilient organization. 

Automation is becoming the dividing line between resilience and recovery debt.

While attackers increasingly automate reconnaissance, exploitation, and lateral movement, many organizations still rely on manual recovery processes. 

That imbalance is becoming increasingly difficult to ignore. AI is compressing attack timelines, but recovery timelines have not kept pace. Organizations that fail to automate these recovery tasks may find themselves spending days assembling and executing plans while the damage has already been done. 

Automated recovery orchestration, clean recovery point identification, and coordinated validation are becoming foundational capabilities for recovering at the speed modern attacks demand. 

Technology isn’t the biggest resilience challenge – organizational alignment is.

Security teams focus on containment, infrastructure teams focus on restoration, business leaders focus on customer impact, and compliance teams focus on regulatory obligations. None of these priorities are inherently wrong, but when they evolve independently, organizations enter a crisis without a shared operating model. 

Enter ResOps. Rather than positioning resilience as an IT responsibility, the report frames it as a discipline that deliberately brings together business, security, infrastructure, and recovery planning. The message is clear: Resilience depends less on individual tools than on creating shared priorities before an incident forces you to make difficult decisions. 

Testing remains one of the strongest indicators of resilience.

IDC found that relatively few organizations conduct frequent tabletop exercises or cyber-range simulations, despite decades of evidence showing that rehearsal consistently improves performance during real incidents. 

Exercises reveal hidden dependencies, expose communication gaps, and allow teams to make decisions without the real consequences. Organizations that repeatedly validate their recovery processes develop a level of confidence beyond planning alone. 

Tomorrow’s resilience challenges are already taking shape.

Ransomware still dominates headlines, but the next resilience challenges have already emerged – from agentic AI and machine identities to post-quantum cryptography. 

These threats remind us that resilience planning can’t focus exclusively on today’s infrastructure. Recovery increasingly involves cloud services, SaaS applications, AI models, machine identities, third-party providers, and distributed digital ecosystems that didn’t exist a decade ago. 

Resilience is becoming measurable.

IDC’s ResOps Maturity Model is invaluable for assessing your organization’s current posture. Rather than treating resilience as something organizations either possess or lack, the framework describes a progression from reactive, siloed operations to mature, adaptive resilience built on governance, automation, and continuous improvement. 

To me, that progression acknowledges an important reality: Resilience is never finished. It’s not about purchasing a platform or completing a project. Organizations become resilient by continually improving how technology, people, and business processes work together under pressure. 

Viewed through that lens, resilience becomes less like insurance and more like operational excellence – a capability that can be assessed, strengthened, and demonstrated over time. 

We’re undergoing a broader shift in how organizations think about resilience.

Resilience conversations are evolving from protecting infrastructure to protecting the business itself. That means recovery planning starts with customers instead of servers, governance becomes as important as technology, and confidence comes from proving capabilities rather than documenting intentions. 

ResOps isn’t really a new framework; rather, it’s a broader recognition that cyber resilience has become an operational discipline. As attacks become faster and more complex, resilience will be measured not by the absence of incidents, but by an organization’s ability to continue serving customers, supporting employees, and maintaining trust despite disruption. 

That’s ultimately what ResOps is designed to prove. 

Rajiv Kottomtharayilè Chief Products Officer presso Commvault. 

More related posts


Cyber Resilience

Read more about Cyber Resilience

Punti di forza

  • Trust in the age of AI isn’t disappearing – it’s evolving.
  • Le organizzazioni devono verificare costantemente l’intelligenza artificiale, anziché fidarsi di essa di default.
  • L’adozione dell’IA dovrebbe dare più autonomia ai dipendenti, non spingerli verso l’IA “ombra”.
  • Zero trust isn’t about distrusting people. It’s about continuously validating identities, devices, and actions.
  • L’adozione responsabile dell’IA richiede la collaborazione tra tecnologia, governance e persone.

When we launched Ready. Or Not., we wanted to create a series that made some of today’s biggest AI conversations easier to understand. By pairing comedian Nathan Macintosh with industry experts, we’re exploring everything from agentic AI and cyber resilience to data management – and adding a little humor along the way.

If you caught our first episode on the opportunità e i rischi dell’IA agente, I think you’ll enjoy this one as well. This time, we’re tackling a topic that’s at the center of every AI conversation: trust.

Nathan sits down with Diana Kelley, Chief Information Security Officer at Protect AI, for a conversation about what it means to trust technology when AI can generate convincing fake content, make decisions, and even imitate people. From deepfakes and hallucinations to zero trust and shadow AI, they explore how organizations can embrace AI without losing confidence in their people and systems.

Guarda l’episodio completo su Readiverse.Dopo aver visto questa puntata, mi sono sentito più ottimista di quanto mi aspettassi. Non perché l’IA sia improvvisamente diventata più affidabile, ma perché Diana ci dimostra che la fiducia cresce quando le organizzazioni mettono in atto le giuste politiche, le misure di sicurezza e la tecnologia adeguata. Ecco alcuni spunti emersi dalla conversazione che offrono una nuova prospettiva sull’IA.

Fiducia e tecnologia possono coesistere

Diana believes trust is possible in the AI era, but it’s going to look different. We’ve always built trust through relationships with people. Now, we’re learning how to extend that trust to systems.

That doesn’t mean trusting technology blindly. It means understanding how AI works, recognizing its limitations, and putting the right safeguards in place so people and technology can work together with confidence.

“Trust has to evolve for the new world.”

– Diana Kelley

What resonated with me was the idea that trust and technology don’t have to be at odds with one another. With the right approach, they can strengthen each other.

We’re Getting Smarter About AI

Deepfakes have become one of the most talked about AI risks, and it’s easy to understand why. AI can now generate convincing voices, images, and videos that make us question what’s real. But Diana pointed out that while AI is getting more sophisticated, people are getting smarter. We’re more likely to question an unexpected phone call, take a closer look at a social media post, or pause at something that doesn’t feel quite right.

Organizations are becoming savvier, too. As AI gets better at impersonation, businesses are investing in new ways to continuously verify identities and validate information. My takeaway is this: Technology will continue to improve, but so will our ability to recognize it and respond responsibly.

“Is today a good day to start a deepfake?”

– Nathan Macintosh

Un’IA responsabile fa bene agli affari

Diana shared an example that will probably sound familiar to many organizations. An employee she calls “Karen in Finance” starts using AI because it helps her complete a task in minutes instead of hours. Karen isn’t trying to work around company policy – she’s trying to be more productive.

Employees use AI because they see real value in it, and that’s an opportunity for organizations. When employees have access to approved AI tools, supported by clear policies and practical guidance, they can work more efficiently while helping protect company data and systems.

Anteprima: un’adozione più intelligente dell’IA

The goal isn’t to stop employees from using AI. It’s to make sure they’re using it the right way. Diana explains how organizations can encourage AI adoption without creating unnecessary risk.

Il modello Zero Trust è più importante che mai

“When you understand how things work, then you can start to understand how to manage them.”

– Diana Kelley

Zero trust is one of those concepts that’s much easier to understand with an analogy. Diana has a great one. She describes it as moving through a building. Just because you’ve been allowed through the front door doesn’t mean every other door automatically opens for you. Each time you access a new room, there’s another quick check to confirm you’re supposed to be there.

That’s essentially how zero trust works. Instead of assuming a person or device is trustworthy after a single login, organizations continuously verify identities, devices, and actions as technology becomes more connected. Most of those checks happen quietly behind the scenes.

One of the things I appreciated about Diana’s explanation is that zero trust doesn’t feel like another security buzzword. It feels like a practical way to think about trust in a world where AI and digital identities are becoming part of everyday business.

La fiducia riguarda le persone

At the end of the day, technology doesn’t create trust – people do. People define the policies, processes, and ethical boundaries that guide how AI is used, while technology helps verify that those guardrails are working as intended. It’s that partnership between people and technology that makes responsible AI possible.

Trust extends beyond our own organizations. Businesses need confidence in the partners they work with, the systems they connect to, and the technologies they adopt. That’s why transparency, shared standards, and continuous verification are becoming just as important as innovation itself. The more AI becomes part of everyday business, the more trust becomes everyone’s responsibility.

Guardare avanti

AI will continue to evolve, and so will the way we interact with it. The organizations that succeed won’t be the ones that trust AI blindly or avoid it altogether. They’ll be the ones that build strong policies, adopt the right technologies, and continuously verify the systems they rely on.

Trust isn’t something we lose as technology advances. It’s something we intentionally build and evolve. That’s exactly the kind of conversation we hope to continue with every episode of Ready. Or Not.

Guarda l’episodio completo su Readiverse.

Domande frequenti

Q: What is digital trust?

A: Digital trust is the confidence that people, systems, and organizations are who they claim to be and are acting in expected, secure ways. It combines technology, governance, and verification to help organizations interact safely.

Q: What are deepfakes?

A: Deepfakes are AI-generated images, videos, or audio recordings designed to closely imitate real people. While they have legitimate uses, they can also be used to impersonate individuals or commit fraud.

Q: What is zero trust?

A: Zero trust is a security model based on continuous verification rather than automatic trust. Instead of assuming a user or device is trustworthy after one login, organizations continuously validate identities and actions.

Q: What is shadow AI?

A: Shadow AI refers to employees using AI tools that haven’t been approved or governed by their organization. While often well-intentioned, it can introduce security, privacy, and compliance risks.

Q: Why shouldn’t organizations simply block AI tools?

A: Employees typically adopt AI because it helps them work more efficiently. Rather than banning AI outright, organizations should provide approved tools, establish clear policies, and educate employees on responsible use.

Q: What’s the biggest takeaway from this episode?

A: Trust isn’t disappearing because of AI – it’s evolving. Organizations that combine people, policies, and technology with continuous verification will be better positioned to adopt AI confidently and responsibly.

Katherine Demacopoulosè direttrice senior della strategia e dei programmi globali relativi ai contenuti presso Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Our Chief Products Officer, Rajiv Kottomtharayil, recently wrote about a big shift that is taking place across industries. Frontier AI models are compressing the time between vulnerability discovery and exploitation.  

This shift is prompting organizations everywhere to re-examine their vulnerability management processes. We’re doing the same at Commvault. That’s why, starting August 11, we’re changing the rhythm of how we disclose vulnerabilities.  What’s ChangingWe are raising the bar for security, transparency, and customer trust. On August 11, and on the second Tuesday of each month after that, we’re introducing Patch Tuesdays: a scheduled monthly release where we share security advisories and vulnerability patches.  

Patch Tuesdays are a hallmark of leading technology companies, because they provide customers with a predictable security rhythm.  This matters even more as the pace of vulnerability discovery accelerates. Of course, if there is an urgent vulnerability that must be reported off cycle, we will not hesitate to follow our well-established processes.  

Where You Can Find Up-to-Date Resources  

On the second Tuesday of each month, you’ll find new information pertaining to CVEs on our Dove trovare risorse aggiornate. You also can find the official publications at MITRE’s pagina degli avvisi di sicurezza. 

On the Commvault Security Center, you’ll find our vulnerability management program and other security-by-design thought leadership.   

For compliance certifications, audit reports, and documentation on how Commvault protects customer data, visit the Centro fiduciario Commvault. You can subscribe to updates from the Trust Center at the link in the upper righthand corner of the page. 

Bill O’Connell is Chief  Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

For decades, technology leaders have been trying to eliminate silos. Entire modernization programs have been built around connecting applications, consolidating platforms, and giving organizations a more complete view of their data.

Those efforts have delivered enormous value, but they also have shaped the way we think about resilience. When something goes wrong, we instinctively look for technical fragmentation. However, we’ve found the greater challenge lies elsewhere.

The most significant silos affecting cyber resilience today aren’t found in databases or applications but in organizational structures. They exist between security and infrastructure teams, between IT and the business, and between the people responsible for responding to an attack and those responsible for keeping the organization operating.

IDC’s latest research on ResOps, Resilience Operations: The Discipline that Makes Readiness Provable, suggests these organizational boundaries have become one of the defining obstacles to effective recovery. That’s a timely observation because cyberattacks have evolved in ways that can make those boundaries increasingly difficult to maintain.

Modern Attacks Don’t Follow Your Org Chart

A modern cyberattack rarely affects a single technology domain. A ransomware incident might begin with compromised identities, spread through cloud infrastructure, encrypt critical workloads, disrupt customer-facing applications, impact third-party services, and trigger regulatory Rapportoing requirements – all within a matter of hours. Every stage involves different teams, different tools, and different priorities.

Yet many organizations still prepare for recovery as though these responsibilities can be managed independently.

Security teams naturally focus on containing threats and preserving evidence. Infrastructure teams prioritize restoring systems and minimizing downtime. Business leaders concentrate on customers, revenue, and operational continuity. Communications teams think about reputation, while legal and compliance teams focus on regulatory obligations.

Each perspective is entirely reasonable. The problem arises when those priorities have never been reconciled before an incident occurs.

In the middle of a crisis, recovery requires decision-making under pressure. Which applications should return first? Which data can safely be restored? How much risk is acceptable before customer services resume? Who has the authority to make those decisions?

Without alignment, organizations often discover that the greatest delays aren’t caused by technology but by uncertainty – the kind that could be mitigated by better preparation.

Resilience Begins with a Shared Definition of What Matters

The Rapporto places emphasis on establishing your minimum viable business (MVB). At first glance, it appears to be another recovery planning exercise, but its real value lies in the conversations it forces organizations to have.

Defining an MVB requires business leaders, security teams, infrastructure specialists, and application owners to agree on a deceptively simple question: What absolutely must continue operating if everything else stops?

That discussion changes the nature of resilience planning. Recovery priorities are no longer determined by whichever application owner argues most convincingly during an incident. Instead, they are established in advance, grounded in business outcomes, and supported by technical dependencies that everyone understands.

Perhaps more importantly, MVB creates a common language. Business leaders begin talking about critical capabilities rather than individual systems. Technology teams begin mapping infrastructure to customer outcomes rather than technical architectures. Security teams gain greater clarity about which assets deserve the highest levels of protection during recovery.

That shared understanding is precisely what many organizations have been missing.

Technology Can Automate Recovery – But it Can’t Create Alignment

The Rapporto doesn’t argue that organizations need yet another platform. It argues they need a way of working that aligns people, processes, and technology around a single operational objective. This is where ResOps – a cross-functional discipline – proves its mettle.

Technology can help automate recovery, but it cannot resolve disagreements about business priorities. It cannot decide which customer services matter most. And it cannot replace the governance needed to coordinate multiple teams during a high-pressure event.

Those are leadership challenges, and they are best addressed by investing time in answering the difficult questions together, long before an attack forces your hand.

The Strongest Organizations Don’t Eliminate Silos – They Connect Them

Cyberattacks will continue evolving. AI will continue compressing attack timelines. New technologies will introduce new dependencies, and new threats will emerge alongside them. None of that changes the fundamental requirement for resilience.

Organizations don’t recover because individual teams perform brilliantly in isolation, but because those teams already know how to work together.

That may ultimately be the most important insight from IDC’s research. Resilience isn’t simply the product of better technology or more sophisticated security controls. It is the result of shared priorities, clear governance, and a tested operating model that brings the right people together before an incident occurs.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Learn about our advances through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

By Sustainability Team

As AI adoption accelerates, cyber threats are becoming more sophisticated, and data regulations are expanding. Resilience is no longer simply a defensive posture – it is a business imperative and competitive advantage.

That belief is at the center of Commvault’s FY26 Sustainability Report, which is now available. This year’s report reflects the progress we’ve made across the areas that matter most to our business, our customers, our people, and the communities where we live and work.

Anchored by our updated materiality assessment, the report highlights how we are advancing sustainability through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

Cyber resilience remains foundational to our work. As organizations rethink what it means to be ready for disruption, Commvault continues to unify data security, identity resilience, and cyber recovery to help customers detect threats faster, operate more efficiently, and recover with greater confidence. We also are integrating AI and automation designed to support smarter, more secure, and more resilient operations.

That same focus on resilience extends to our environmental commitments. Our solutions help customers optimize data storage and movement, which can help reduce energy expenditure in data centers. For Commvault, responsible innovation means building solutions that support both operational strength and more efficient use of resources.

The report also reflects the people and principles behind our progress. Strong governance, a modern Code of Ethics, and continued investment in our talent help create the foundation for trusted partnerships and long-term value. These commitments are deeply connected: Strong governance enables responsible innovation, responsible innovation helps strengthen the security and efficiency our customers depend on, and that trust is sustained by the people who bring our mission to life every day.

We invite you to read Commvault’s FY26 Sustainability Report as both a record of our progress and a look forward to the priorities that will shape our next chapter.

 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

A few years ago, digital sovereignty was largely viewed as a compliance conversation. If you stored data in the right geography, met the right regulatory requirements, and satisfied a handful of audit questions, you could generally move on.

That’s no longer the case.

Today, sovereignty has become a board-level discussion. Governments are rewriting policies. Regulators are increasing scrutiny. And business leaders are starting to recognize that sovereignty isn’t just about where data resides – it’s about how organizations continue operating when geopolitical, legal, or operational assumptions suddenly change.

In the first episode of our STRIVE series on digital sovereignty, I sat down with Max Mortillaro, co-founder and Chief Research Officer at Osmium Data Group. Together, we unpack what sovereignty actually means, why the conversation has accelerated so quickly, and where organizations are most likely to get it wrong.

Watch the full episode.

Punti di forza

  • Digital sovereignty is no longer just a compliance issue – it has become a resilience and business continuity concern.
  • Data location is only one piece of the puzzle. Jurisdiction, operations, technology dependencies, and governance all matter.
  • Many organizations focus on technical controls before understanding the business problem they’re trying to solve.
  • Geopolitical uncertainty is accelerating sovereignty initiatives, particularly across Europe.
  • There is no such thing as a perfectly sovereign environment. Every organization must make informed trade-offs between risk, cost, and operational requirements.

Why Data Location Isn’t the Whole Story

One of the most common misconceptions around digital sovereignty is that it begins and ends with geography. If data is stored in a local data center, the thinking goes, the sovereignty problem has been solved.

It’s an understandable assumption. After all, many of the early conversations around sovereignty focused heavily on data residency requirements and where information could legally be stored.

But as Max points out during our discussion, that’s only one dimension of a much larger challenge. Sovereignty isn’t simply about where a data center sits. It’s also about who operates it, which laws apply to it, who has access to it, and what dependencies exist behind the scenes.

A cloud service may be physically located within a specific country, but that doesn’t necessarily mean it’s insulated from legal, operational, or technological influence originating elsewhere.

That’s where the conversation becomes significantly more complex.

The Hidden Dependencies Most Organizations Overlook

When organizations first begin exploring sovereignty, they often approach it as a technology project. They evaluate hosting locations. They assess replication strategies. They examine where workloads should run.

Those conversations are important, but they can also create a false sense of confidence.

As Max explains, modern technology environments are built on layers of dependencies that aren’t always visible. A service may appear local on the surface but it may be relying on infrastructure, management systems, telemetry services, or operational controls that exist elsewhere.

That’s why sovereignty isn’t simply a question of location. It’s a question of influence.

Who ultimately controls the service? Which legal jurisdiction applies when disputes arise? What happens if geopolitical tensions introduce new restrictions, regulations, or limitations on access?

These aren’t hypothetical questions anymore. They’re becoming part of real-world risk assessments.

Sneak Peek: Sovereignty Is More Than a Technical Problem

In this segment from the conversation, Max explains why organizations often start sovereignty discussions in the wrong place – and why understanding the legal, operational, and business objectives must come before any technology decisions.

Why Europe Is Driving the Conversation

One of the most interesting parts of our discussion focuses on why sovereignty has become such a dominant topic across Europe.

The answer isn’t just regulation; it’s dependency.

European organizations have become increasingly aware that many of the technologies they rely on every day are owned, operated, or governed outside of their direct control. For years, that reality was largely accepted as part of the global technology ecosystem.

Today, that assumption is being reevaluated.

Geopolitical tensions, evolving regulations, and increasing concern around strategic autonomy have pushed sovereignty higher on the priority list for governments and enterprises alike. What was once considered an edge case has become a mainstream business concern.

The result is a growing recognition that resilience isn’t only about recovering from technical failures. It’s also about understanding and managing external dependencies before they become business disruptions.

Sovereignty and Resilience Are the Same Conversation

One of the themes that you’ll see repeatedly surfacing throughout the discussion is how closely sovereignty and resilience are connected.

At first glance, they may seem like separate disciplines. One focuses on governance, regulation, and control. The other focuses on recovery, continuity, and operational readiness.

In practice, they’re deeply intertwined.

If a business cannot access critical systems because of a geopolitical event, regulatory restriction, or third-party dependency, the outcome isn’t very different from other disruptions organizations spend years preparing for.

The business still needs to operate. Customers still need to be served. Recovery still needs to happen.

That’s why I increasingly view sovereignty through the same lens as cyber resilience. Both are fundamentally about reducing exposure to events that could disrupt operations and preparing the organization to continue functioning when those events occur.

Start With the Business Problem

Perhaps the most practical advice Max shares is also the simplest.

Before evaluating sovereign cloud offerings, before engaging vendors, and before debating technical architectures, organizations should first understand what problem they’re trying to solve.

That means understanding:

  • Which business processes are most critical.
  • Which data assets matter most.
  • Which regulatory requirements apply.
  • Which risks are truly being mitigated.

Only after those questions are answered does it make sense to evaluate technology options.

Too often, organizations start with solutions and work backward toward the problem. Sovereignty requires the opposite approach. The strategy should come first.

The architecture follows.

Why There Is No Perfect Answer

One of the realities leaders need to accept is that there is no such thing as a perfectly sovereign environment.

Every organization operates within a network of dependencies. Every technology choice introduces trade-offs. Every risk decision involves balancing operational requirements, compliance obligations, cost considerations, and business outcomes.

The goal isn’t perfection. The goal is understanding those trade-offs well enough to make informed decisions.

Organizations that approach sovereignty as a binary yes-or-no question often find themselves frustrated. Organizations that approach it as a risk-management exercise tend to make better progress.

Why This Conversation Matters

Digital sovereignty is moving quickly from a niche compliance topic to a strategic business issue.

Boards are asking questions. Regulators are increasing scrutiny. Customers are becoming more aware of where their data lives and who controls it.

At the same time, geopolitical uncertainty continues to reshape how organizations think about risk.

That doesn’t mean every company needs a radical sovereignty transformation tomorrow.

But it does mean that the organizations that start building a clear strategy today will be in a much stronger position than those who wait until the conversation becomes unavoidable.

Sovereignty isn’t a technology decision masquerading as a business problem. It’s a business problem that requires legal, operational, and technical decisions working together.

Guarda l’episodio completo

In this installment, Max and I explore:

  • What digital sovereignty actually means.
  • Why data location alone isn’t enough.
  • The legal and operational dimensions organizations often overlook.
  • How geopolitical developments are influencing sovereignty strategies.
  • Why sovereignty and resilience are becoming inseparable.

Guardalo subito.

Domande frequenti

Q: What is digital sovereignty? 

A: Digital sovereignty refers to an organization’s ability to maintain control over its data, technology, operations, and governance within specific legal and jurisdictional boundaries.

Q: Is digital sovereignty the same as data residency? 

A: No. Data residency is one component of sovereignty, but sovereignty also includes legal jurisdiction, operational control, technology dependencies, and governance.

Q: Why has digital sovereignty become more important recently? 

A: Growing geopolitical uncertainty, evolving regulations, and increasing concern about technology dependencies have accelerated interest in sovereignty initiatives.

Q: What is the biggest mistake organizations make? 

A: Treating sovereignty as a purely technical challenge instead of a broader business risk and resilience issue.

Q: How does sovereignty relate to cyber resilience? 

A: Both disciplines focus on maintaining operational continuity in the face of disruptions, whether those disruptions are technical, legal, geopolitical, or regulatory.

Q: Where should organizations begin? 

A: Start by understanding the business outcomes you’re trying to protect, the risks you’re trying to mitigate, and the data and processes that are most critical to your operations.

Alex Zinin is VP/GM of Managed Service Providers at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Punti di forza

  • The role of the backup administrator is evolving from managing infrastructure to delivering business resilience and recovery confidence.
  • Modern ResOps (resilience operations) focus on recovery readiness, continuous validation, governance, and business outcomes – not just successful backup jobs.
  • Autonomous Resilience is Commvault’s vision for the next evolution of ResOps, wqui AI helps resilience teams reduce operational overhead through intent-driven, governed workflows while maintaining human oversight, approvals, and auditability.
  • By helping reduce repetitive operational work, AI enables resilience teams to spend more time improving cyber recovery, governance, and recovery readiness.
  • The future of resilience will be measured by confidence in recovery – not simply the successful completion of protection activities.

The Operational Shift at 8 a.m.

For an enterprise backup administrator, the morning routine has long followed a predictable, high-stress pattern. You log in at 8 a.m. to face a wall of dashboards. Tqui are thousands of completed protection activities, but your eyes naturally scan for the exceptions – a handful of failed workloads, replication delays, and capacity alerts warning that critical storage resources are nearing their thresholds.As you begin sorting through the day’s priorities, the reality of modern infrastructure closes in. A virtualization administrator submits a request: Dozens of new workloads were provisioned overnight, and leadership needs to know whether they are automatically covered by existing protection policies.Moments later, the compliance team requests a detailed history of protection success and retention validation to prepare for an upcoming audit. Then, the security operations center (SOC) calls. An anomaly has been detected on a critical system, and they need confirmation that recovery copies remain isolated, immutable, and uncompromised.Before you can finish your first cup of coffee, leadership asks a simple but devastating question: “If we were hit by ransomware right now, how consistently and confidently could we recover?”

Ten years ago, a successful backup administrator was an infrastructure gatekeeper. Success was binary and infrastructure-centric: Did the jobs finish within the required time window? Was the data successfully protected? If the dashboard was green, the job was done.Today, that paradigm is entirely broken. The modern enterprise does not care whether data protection jobs completed successfully. It cares whether the business can survive a catastrophic disruption.Success is no longer measured by the completion of a background data protection process. It is measured by an organization’s ability to withstand ransomware, infrastructure failures, cloud outages, insider threats, and compliance events without losing data or operational momentum.The role has fundamentally evolved from infrastructure management to enterprise resilience. Yet many organizations still force administrators to spend their days managing operational tasks instead of architecting recovery confidence.Commvault is working to redesign the administrator experience to help break this cycle, enabling a shift from reactive backup management toward comprehensive ResOps.

The Drag of the Modern Administrator’s Daily Reality

To understand why this shift is necessary, one must first recognize the enormous operational burden carried by administrators every day. Consider the volume of tactical work required to maintain a modern enterprise protection environment:

  • Job and infrastructure monitoring: Reviewing overnight activities, distinguishing transient issues from legitimate failures, and validating infrastructure health across a rapidly changing hybrid environment.
  • Troubleshooting and issue resolution: Spending hours reviewing diagnostic information and operational telemetry to determine why processes stalled, services became unavailable, or critical workloads failed unexpectedly.
  • Resource optimization and performance management: Continuously identifying storage constraints, network bottlenecks, or infrastructure limitations that impact protection and recovery objectives, then manually expanding capacity as requirements grow.
  • Workload discovery and lifecycle management: Automatically discovering, classifying, and assigning appropriate protection policies to newly deployed applications, cloud services, databases, and infrastructure resources.
  • Capacity and storage management: Monitoring consumption trends, forecasting growth, and responding to unexpected increases before they threaten recovery objectives.
  • Audit and compliance support: Collecting reports, validation records, and historical evidence across multiple systems to demonstrate compliance with retention and governance requirements.

Every hour spent troubleshooting an operational issue or assembling compliance evidence is an hour taken away from strategic resilience planning. This is wqui resilience teams lose time. The challenge is the operational overhead required to keep protection systems synchronized with a constantly evolving hybrid cloud environment.

The Structural Shift: From Backup Operations to ResOps

As organizational risk profiles increasingly center around cyber resilience and business continuity, the very mindset of data protection must evolve.

Old Mindset: Backup Operations

“I need my protection jobs to finish successfully.” 

New Mindset: ResOps

“I need confidence that we can recover immediately.” 

This evolution fundamentally changes the questions administrators must answer.

Backup Operations  ResOps
Did the workload complete protection last night? Are our critical applications verified as recoverable?
How much storage capacity remains? What is our verified recovery readiness posture?
Are recovery copies synchronized? Are our recovery environments protected and isolated?
Can we restore a single file? Can we recover an entire business service during a cyber event?

In this new model, recovery – not backup – becomes the primary operational metric. 

An organization can achieve near-perfect protection success rates while remaining dangerously unprepared for a ransomware attack due to compromised credentials, hidden dependencies, configuration drift, or unverified recovery processes.ResOps assumes disruption is inevitable. The focus shifts toward continuous validation, proactive risk identification, threat awareness, and deterministic recovery orchestration.At Commvault, we see this evolution leading toward Autonomous Resilience, wqui AI helps resilience teams move from manual operations toward intent-driven, governed outcomes.

How Commvault is Redesigning the Experience Around Outcomes

Commvault is addressing these realities by working to redesign the administrator experience. Rather than requiring users to organize their work around infrastructure configurations, protection policies, storage resources, and system assignments, Commvault is shifting the experience toward outcomes that matter to the business.

  • Unified management and risk-driven visibility: Rather than navigating multiple interfaces to manage different environments, administrators gain visibility into their entire estate through a unified resilience experience.The focus extends beyond operational status. The platform highlights risk exposure, protection gaps, emerging threats, unprotected workloads, and configuration drift that could impact recovery readiness.
  • Policy simplification and intelligent automation: Traditional environments often require administrators to manage hundreds of static schedules and policies. Commvault is designed to replace this complexity with intent-based protection plans.

    Administrators define business outcomes, while the platform can automatically orchestrate the infrastructure, optimize workflows, and manage protection activities behind the scenes.

  • Continuous validation and clean recovery environments: True resilience requires confidence not only in protected data but also in the ability to restore it safely.

    Commvault can integrate automated recovery validation directly into operations. This includes the ability to orchestrate isolated recovery environments wqui systems can be restored, validated, and inspected before production restoration occurs.

  • Threat-aware operations and intelligent detection: Modern resilience requires more than monitoring activity counts. By applying advanced analytics and machine learning to operational telemetry, the platform establishes historical baselines and detects abnormal behavior.

    When suspicious activity occurs, administrators receive contextual explanations, probable causes, impact assessments, and recommended actions – not just generic alerts.

A Day in the Life: The Outcome-Driven Workflow

To understand the potential impact of this transformation, consider an illustrative day for an administrator within an outcome-focused resilience platform. The scenario below shows how these capabilities are intended to work together.

8 a.m. – Establishing Recovery Readiness

Instead of searching through thousands of activities and alerts, you open a resilience dashboard displaying a comprehensive Recovery Readiness Score across the environment. The platform highlights a scaling concern. Recently deployed workloads have increased demand beyond recommended operational limits.Rather than manually expanding infrastructure and coordinating resources, the platform automatically recommends a corrective action: “Additional infrastructure capacity is recommended to maintain recovery objectives. Approve?” 

A single approval initiates the adjustment.

11:30 a.m. – Automated Audit Resolution

The compliance team requests evidence of protection activity and policy compliance for a previous reporting period. Rather than manually compiling reports and spreadsheets, the administrator generates a compliance package containing validation records, policy compliance evidence, and supporting documentation within minutes.Time is spent improving resilience – not producing paperwork.

2 p.m. – Threat Detection and Autonomous Response

A critical anomaly is detected. A workload exhibits behavior that significantly deviates from normal historical patterns.Instead of issuing a generic warning, the platform automatically correlates the event with known behaviors, evaluates potential causes, assesses business impact, and identifies clean recovery points.If a cyberattack is suspected, the platform highlights affected recovery data, isolates impacted assets, validates clean recovery options, and prepares recommended recovery actions.The administrator is no longer investigating what happened. The platform is helping determine what to do next.

The Power of Intent: Why Embedded Intelligence Changes Everything

The engine powering this transformation is the move from manual task execution to autonomous, intent-driven operations.Commvault’s conversational and AI-driven capabilities are designed to support the operational model that this transformation requires:

  1. An administrator expresses intent.
  2. The platform gathers context.
  3. Recommendations are generated.
  4. Actions are executed with appropriate oversight.
  5. Outcomes are validated.
  6. Activities are documented automatically for governance and audit purposes.

This fundamentally changes the relationship between administrators and the underlying technology. The goal is no longer to manage systems. The goal is to direct outcomes.

From Diagnostics to Actionable Root Cause

When infrastructure issues occur, administrators traditionally have spent hours reviewing diagnostic information, searching for symptoms, and piecing together dependencies. Embedded intelligence continuously monitors infrastructure health, operational telemetry, and service activity patterns. When an issue arises, diagnostic information can be analyzed automatically, probable causes identified, and remediation recommendations generated without requiring manual investigation.

Multi-Workload Dependency Correlation

Modern environments are interconnected ecosystems. A single infrastructure issue can generate hundreds of downstream failures. Rather than forcing administrators to investigate each event individually, the platform automatically correlates failures and identifies shared infrastructure dependencies, common services, or connectivity issues contributing to broader disruption.

Proactive Resource Forecasting

Instead of waiting for operational failures, the platform continuously analyzes historical workload patterns, growth trends, and infrastructure utilization. Expected changes are separated from abnormal behavior, allowing resilience teams to proactively address capacity and performance concerns before they impact recovery readiness.

The Rise of the Resilience Engineer

The data protection industry is undergoing a profound transformation. The title of backup administrator is rapidly becoming an artifact of a previous era – one in which data protection was viewed primarily as an operational task supported by infrastructure checklists.Tomorrow’s successful professional is a resilience engineer. They collaborate with security teams to design cyber recovery strategies. They work alongside compliance leaders to automate governance requirements. They provide executives with measurable confidence in the organization’s ability to recover from disruption. Their value is no longer defined by how effectively they manage operational complexity, but by how effectively they reduce business risk and accelerate recovery.Commvault is not simply enhancing an existing backup platform. It is helping build the operational framework for the next generation of resilience leadership. By helping reduce administrative overhead, simplify operations, and align the experience around recovery readiness and continuous validation, Commvault is enabling administrators to focus on what matters most: helping the business remain resilient. 

The future of enterprise availability is no longer about managing backups. It is about delivering autonomous resilience. 

Continue the Conversation

The conversation around Autonomous Resilience is just beginning. At SHIFT 2026 in Nashville this November, we’ll explore how AI is reshaping ResOps and what it means for the next generation of resilience engineers. Register qui.

Domande frequenti

Q: Why is the role of the backup administrator changing?

A: Enterprise resilience is no longer measured by successful backup jobs alone. Organizations increasingly judge resilience by their ability to recover confidently from ransomware, cloud outages, infrastructure failures, and other disruptions. As a result, backup administrators are taking on a broader role that spans cyber resilience, governance, recovery readiness, and business continuity.

Q: What is ResOps (resilience operations)?

A: ResOps reflects the shift from managing backup infrastructure to managing recovery readiness. It brings together data protection, cyber recovery, governance, continuous validation, and operational visibility into a single discipline focused on helping organizations recover with confidence.

Q: What is Autonomous Resilience?

A: Autonomous Resilience is Commvault’s vision for the next evolution of ResOps. It applies AI to help resilience teams reduce operational overhead through intent-driven, governed workflows that gather context, recommend actions, execute approved tasks, validate outcomes, and maintain auditability throughout the recovery process.

Q: How will AI change the day-to-day work of resilience teams?

A: AI can help reduce repetitive operational work such as reviewing backup activity, investigating failed workloads, collecting compliance evidence, assessing recovery readiness, identifying clean recovery points, and recommending recovery actions – all while operating within established governance controls. This allows administrators to spend more time improving resilience strategy and less time performing routine operational tasks.

Q: Does Autonomous Resilience replace backup administrators?

A: No. Autonomous Resilience is designed to augment resilience professionals, not replace them. Administrators remain responsible for oversight, approvals, governance, and decision-making while AI helps reduce operational overhead and supports day-to-day resilience operations.

Q: Why is this important now?

A: Hybrid infrastructure, cyber threats, AI adoption, and increasing operational complexity are changing what organizations expect from backup and recovery teams. The role is evolving from managing infrastructure to delivering resilience, making recovery readiness, governance, and operational confidence more important than ever.

Rajiv Kottomtharayilè Chief Products Officer presso Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Punti di forza

  • Un CVE è un identificatore univoco a livello globale che contraddistingue una vulnerabilità software resa pubblica, consentendo a fornitori, ricercatori e responsabili della sicurezza di fare riferimento ad essa in modo coerente.
  • An organization’s approach to vulnerability disclosure – including coordinated fixes, researcher engagement, and accurate software inventory – is a strong indicator of overall security maturity.
  • Commvault tutela i propri clienti grazie a un programma CVE improntato alla trasparenza, alla regolarità e alla chiarezza. La divulgazione delle vulnerabilità CVE la dice lunga sulla maturità di un programma di sicurezza e di ingegneria.

Perché è importante

Many breaches that reach the boardroom trace back to vulnerability in software. The mechanism the entire industry uses to name and describe those vulnerabilities is the CVE, Common Vulnerabilities and Exposures.

How a vendor, or your own organization, handles CVEs is one of the clearest signals of security maturity.

A company that discloses and credits researchers fairly is usually a company that takes underlying engineering seriously. This blog explains how a CVE is built, who runs the system, and what separates an exemplary disclosure from a poor one.

Oltre il CVE: perché la filosofia della divulgazione è importante

La pubblicazione di un CVE è un requisito minimo. Gli elementi che fanno la differenza sono: la trasparenza riguardo alla vulnerabilità e alla patch, l’esecuzione regolare di scansioni e l’applicazione delle patch, nonché una comunicazione chiara. Commvault considera la divulgazione delle vulnerabilità una disciplina ingegneristica e di sicurezza, piuttosto che un semplice requisito di conformità da spuntare: stabiliamo una cadenza regolare per la revisione del codice e la correzione delle vulnerabilità, comunichiamo le soluzioni adottate in un linguaggio semplice e proteggiamo i nostri clienti. È proprio questa coerenza, più di qualsiasi singolo punteggio, a dimostrare la maturità in materia di sicurezza attraverso la divulgazione dei CVE.

Che cos’è in realtà un CVE

A CVE is not a patch, a score, or a piece of malware. It is a dictionary entry that gives one specific, publicly known vulnerability a permanent, unique name so that everyone can refer to it.

The identifier itself follows a simple, durable format: the letters CVE, the year the ID was assigned, and a sequence number, for example, CVE-2021-44228.

The scale of the program is enormous, and still growing:nel 2025 sono stati pubblicati 48.000 CVE, ovvero circa 132 al giorno, con un aumento di oltre il 260% rispetto al 2020.

L’anatomia di un singolo disco

Le pubblicazioni CVE richiedono una serie coerente di elementi. Leggerne una è semplice una volta compreso lo scopo di ciascuna parte:

  • Identifier, the unique CVE-YYYY-NNNNN
  • Description, a concise explanation of the vulnerability: what it is and how a threat actor could exploit it.
  • Affected products and versions, which software, hardware, or firmware (and which versions) are impacted, and which versions contain the fix.
  • Criticality, the underlying category of criticality.
  • References, links to the vendor advisory, the patch, and technical write-ups.

I protagonisti secondari: CVSS, CWE, EPSS e KEV

Quattro sistemi complementari trasformano un CVE in un elemento a cui un’azienda può dare priorità. È facile confonderli, quindi vale la pena tenere bene a mente la distinzione:

  • CVSS (Common Vulnerability Scoring System) answers “How severe is it?” CVSS is the severity rating (1–10, 10 being the most severe) of the flaw, not a measurement of your specific exposure.
  • EPSS (Exploit Prediction Scoring System) answers “How likely is this to be exploited soon?” EPSS produces a probability score, from zero to 100 percent, estimating the likelihood that a vulnerability will be exploited in the next 30 days.
  • CWE (Common Weakness Enumeration) answers “What kind of mistake caused it?” The CWE classifies the underlying coding weakness.
  • KEV (Known Exploited Vulnerabilities) answers “Is it being used against people right now?” The KEV catalog is a curated list of CVEs with confirmed real-world exploitation.

Un punteggio CVSS elevato indica la gravità potenziale di una vulnerabilità, un punteggio EPSS elevato indica la probabilità che venga sfruttata in tempi brevi, mentre la presenza nel catalogo KEV conferma che lo sfruttamento è già in atto. I migliori programmi di gestione delle vulnerabilità tengono conto di tutti e tre questi fattori.

Domande frequenti

Q: What is a CVE, and why is it important?
A: A Common Vulnerability and Exposure (CVE) is a standardized identifier assigned to a publicly disclosed software vulnerability. It enables everyone – from vendors and researchers to regulators and customers – to refer to the same vulnerability without ambiguity.

Q: What information should a well-formed CVE record contain?
A: A complete CVE record requires a unique identifier, a description of the vulnerability, affected products and versions, the criticality type, and references to vendor advisories or patches. These elements enable organizations to understand their exposure and respond efficiently.

Q: How do CVSS, CWE, EPSS, and KEV differ from a CVE?
A: A CVE identifies a specific vulnerability, while CVSS measures its severity, EPSS estimates the likelihood of near-term exploitation, CWE classifies the underlying coding weakness, and KEV identifies vulnerabilities that are actively exploited in the real world. Together, these frameworks help provide the context needed to prioritize remediation.

Q: What does Commvault look for in its own disclosure practices?
A: Commvault holds its own disclosures to the same standard it expects of others: transparency, cadence and clarity. That is how Commvault protects its customers.

Q: What should business leaders evaluate when assessing vendors’ vulnerability management practices?
A: Leaders should look for coordinated disclosure timelines, comprehensive and accurate CVE records, clear remediation guidance, robust reporting programs, and the ability to quickly determine whether products are affected by newly disclosed vulnerabilities. These characteristics reflect a strong security culture and improve organizational resilience.

Werner Nel is Principal Product Experience Manager at Commvault.

More related posts


Cyber Resilience

Read more about Cyber Resilience

Punti di forza

  • JadePuffer is the name security researchers at Sysdig gave to what they assessed as the first documented ransomware operation driven end-to-end by an autonomous AI agent, not a human working through a toolkit.
  • The individual techniques weren’t new. What changed was orchestration speed: The agent chained reconnaissance, credential theft, lateral movement, and destructive encryption, correcting a failed login attempt in 31 seconds.
  • The agent generated its own encryption key, then never stored or transmitted it. Paying the ransom would not have restored the data.
  • The real damage targeted configuration state and control-plane systems, not just files, which is exactly the layer most recovery plans don’t cover.
  • Recovering from an attack like this means proving the business can safely resume operations, not just restoring a backup.

Cosa è successo

In mid-2026, security researchers at Sysdig documented an extortion campaign they believe is the first of its kind: a ransomware operation carried out end-to-end by a large language model agent, with minimal human hands-on-keyboard involvement. They named it JadePuffer.

The entry point was familiar. The attacker exploited CVE-2025-3248, an unauthenticated remote code execution flaw in Langflow, an open source framework for building AI agent workflows, running a version older than 1.3.0. From there, the agent enumerated the host, searched for credentials across cloud providers, AI model vendors, and databases, and quietly dumped the platform’s own backing database.

What happened next is the part worth paying attention to. The agent scanned the internal network, found an exposed object store, and pulled Terraform state and configuration files. It set up a scheduled task to call home every 30 minutes. Then it pivoted to a separate production system running MySQL and Alibaba Nacos, a configuration and service-discovery platform common in microservice architectures.

Once inside, the agent tried to create an administrator account in Nacos. It failed. Thirty-one seconds later, it had diagnosed the failure and succeeded with a different approach. It then used MySQL’s file-handling functions to probe whether it could escalate further, before encrypting more than 1,300 configuration records, dropping the original tables, and leaving a ransom note behind.

The encryption key was generated on the fly, displayed once, and never stored anywhere the attacker could retrieve it again. Whether or not that was intentional, the outcome for the victim is the same: There was no path back through the attacker or a decryption key, ransom paid or not. Recovery would depend on clean backups, rebuild, or validated recovery points.

Why Researchers Are Calling This “Agentic”

None of the individual techniques here are new. Exploiting an unpatched CVE, harvesting credentials, scanning for lateral movement, encrypting data for extortion: Security teams have seen every one of these before. What made Sysdig classify the operator as agentic rather than a conventional attacker is how the steps fit together.

The agent didn’t run a fixed script. It observed results and adjusted. When it expected a JSON response and got XML back, it changed its approach and kept going. When its first attempt to create an admin account failed, it diagnosed the specific failure and tried something different, in under a minute.

Researchers also found comments embedded in the payloads, explaining targets and next steps in simple language, a pattern more consistent with an LLM reasoning through a task than a human copying and pasting a known exploit kit.

Public reporting hasn’t confirmed which model or platform powered the attack. What’s confirmed is the behavior: Something reasoned, acted, hit a wall, and corrected course faster than most human-paced incident response can move.

The Recovery Problem Too Many Frameworks Still Miss

Most ransomware playbooks are built around a specific assumption: something encrypted your files, and the question is whether you can restore a clean backup or need to negotiate a decryption key.

JadePuffer breaks that assumption in two ways. First, there was no decryption key to negotiate for. Second, the damage wasn’t only in the data. It was in the configuration and control-plane layer underneath the data: the service-discovery platform, the secrets it held, the Terraform state describing how the infrastructure fit together, and the credentials scattered across every system the agent touched on the way there.

That’s a harder recovery problem than “restore the database.” A clean file restore into an environment with rotated-but-not-verified credentials, unreviewed configuration drift, and an identity layer nobody has re-audited isn’t really a clean recovery. It’s a fresh copy of the data sitting inside a system that still can’t be trusted.

What This Means for Your Resilience Strategy

JadePuffer is a preview of the question every recovery plan will eventually have to answer: Can you resume operations when an attacker has touched not just your data, but the identity, configuration, and control-plane systems that data depends on?

A few places to start:

Treat configuration and control-plane systems as recovery-critical, not just applications. Service discovery platforms, secrets stores, and infrastructure-as-code state are as business-critical as the databases they configure. If they aren’t in your recovery plan today, that’s the first gap to close.

Build credential hygiene into recovery, not after it. Restoring a workload that reintroduces compromised secrets doesn’t end the incident; it resets the clock on it. This is the same discipline Commvault applies to identity infrastructure today: vulnerability assessment to see exposure before an attacker does, real-time auditing to catch changes as they happen, and rollback to undo unauthorized changes without rebuilding from scratch.

Validate before you restore, not after. A restore point is only useful if you know it’s clean. That’s the logic behind Commvault® Cleanroom™: testing and validating data in an isolated environment before it ever touches production again, rather than finding out after reinfection.

Plan for a control-plane compromise, not just a file-encryption event. A recovery journey map built only for “encrypted files, restore from backup” won’t hold up against an incident like this. The more useful question, and the one at the center of ResOps (resilience operations) as an operating discipline, is what it takes to reach minimum viable operations when the systems underneath your applications are the ones that got hit.

None of this requires treating agentic AI as an unprecedented threat that demands starting from zero. It requires extending the same resilience discipline that already applies to identity and data, down into the configuration and control-plane layer that agentic attacks are now targeting directly.

Learn more about how Commvault approaches identity resilience and clean recovery validation.

Domande frequenti

Q: What is JadePuffer?

A: JadePuffer is the name Sysdig gave to what it assessed as the first documented ransomware campaign driven end-to-end by an autonomous AI agent, rather than a human attacker manually operating a toolkit.

Q: Did the attackers use a specific AI model, like ChatGPT or Claude?

A: Public reporting hasn’t confirmed which model or platform was used. The agent searched for API keys from multiple AI providers, which shows interest in that kind of access, but doesn’t identify what powered the attack itself.

Q: How did the attack start?

A: Through CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow, an open-source AI agent framework, affecting versions before 1.3.0.

Q: Could the victim have paid the ransom to recover their data?

A: No. The encryption key was generated on the fly and never stored or transmitted, so there was no key available to recover, regardless of payment.

Q: What makes this different from typical ransomware?

A: The individual techniques weren’t new. What stood out was the speed and adaptability: the agent diagnosed a failed login attempt and corrected it in 31 seconds, a pace closer to machine speed than typical human-paced attacker behavior.

Q: What should security and recovery teams take away from this?

A: That recovery planning needs to extend beyond application data to configuration stores, service-discovery platforms, secrets, and identity systems, the layer JadePuffer actually targeted for maximum damage.

Chris Bevil is Principal Portfolio Marketing Manager at Commvault.

More related posts


Cyber Resilience

Read more about Cyber Resilience

Punti di forza

  • Modelli avanzati di intelligenza artificiale sono riusciti a sfuggire a un ambiente di valutazione controllato sfruttando vulnerabilità finora sconosciute.
  • OpenAI afferma che i modelli stavano perseguendo un obiettivo assegnato, senza agire con intento doloso, ma hanno comunque causato un vero e proprio incidente di sicurezza.
  • I controlli tradizionali, come il sandboxing e la segmentazione, risultano insufficienti se l’intelligenza artificiale è in grado di individuare percorsi inattesi per aggirarli.
  • La resilienza informatica sta diventando importante quanto la prevenzione.

Tutto è iniziato come una valutazione interna delle capacità informatiche avanzate basate sull’intelligenza artificiale. Nel tentativo di risolvere un benchmark ben definito, i modelli di OpenAI hanno individuato una vulnerabilità zero-day, hanno aggirato le restrizioni previste dall’ambiente di test, hanno ottenuto privilegi di livello superiore, hanno raggiunto Internet e hanno compromesso l’infrastruttura di Hugging Face. Consideravano i limiti tecnici che li circondavano come problemi da risolvere.

Non si è trattato di un attacco informatico tradizionale

Hugging Face ha riportato per prima la notizia secondo cui un framework di agenti IA autonomi aveva compromesso parte della propria infrastruttura di produzione. Un set di dati dannoso ha sfruttato due percorsi di esecuzione del codice nella pipeline di elaborazione dei dati, ha ottenuto privilegi di accesso a livello di nodo, ha raccolto credenziali e si è spostato lateralmente all’interno dei cluster interni.

I modelli coinvolti, tra cui GPT-5.6 Sol e un modello in anteprima dalle prestazioni superiori, operavano con un numero ridotto di rifiuti informatici e senza i normali classificatori di produzione. Sono andati ben oltre il compito assegnato, sfruttando una vulnerabilità proxy per accedere a Internet, per poi utilizzare credenziali rubate e vulnerabilità zero-day per individuare un percorso di esecuzione di codice remoto sui server di Hugging Face.

Non era necessario che vi fosse un intento doloso

Non vi è alcuna indicazione pubblica che i modelli abbiano sviluppato intenzioni criminali o abbiano scelto di danneggiare Hugging Face. Non ne avevano bisogno. Date a un sistema capace un obiettivo, strumenti, tempo e feedback, e esso aggirerà gli ostacoli. La discussione è ormai andata oltre i semplici prompt e le risposte errate. Si tratta di sistemi in grado di indagare, verificare ipotesi, scoprire vulnerabilità finora sconosciute, utilizzare credenziali rubate, elevare i privilegi e continuare a operare anche quando il primo approccio fallisce.

Una sandbox non è un campo di forza

Definiamo gli ambienti “isolati”, “segmentati” e “in sandbox” come se l’etichetta stessa garantisse la sicurezza. Ma non è così. In questo caso, il percorso ovvio verso Internet era bloccato, ma un proxy raggiungibile di un pacchetto software non lo era, e i modelli hanno sfruttato la sua vulnerabilità per sfuggire. Le politiche e il comportamento previsto non sono sufficienti. È l’ambiente tecnico stesso che deve far rispettare i confini.

Perché questa è una storia di resilienza

The activity moved from an evaluation environment, through OpenAI’s research infrastructure, onto the internet, and into Hugging Face’s production environment. That is a rapidly expanding blast radius. When AI can explore and act at machine speed, the time between initial access and broader compromise may continue to shrink.

Hugging Face did not simply block the original access path and declare the incident over. It closed the vulnerable code-execution paths, rebuilt compromised nodes, rotated credentials and tokens, and tightened cluster controls. The objective is not merely to restore a system. It is to restore confidence.

The question is no longer only: Are our AI systems secure? It is: When a powerful AI system finds a path we did not know existed, can we contain the blast radius, continue critical operations, rebuild what we no longer trust, and prove it is safe to move forward?

Chris Bevil is Principal Portfolio Marketing Manager at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements