Skip to content

Punti di forza

  • La sovranità minima necessaria (MVS) si concentra sull’applicazione del giusto livello di controllo ai carichi di lavoro appropriati.
  • Trattare tutti i carichi di lavoro allo stesso modo può comportare complessità e costi superflui o una protezione insufficiente.
  • Le organizzazioni rientrano in genere in tre profili di sovranità: sovranità totale, impresa regolamentata e multi-cloud ibrido.
  • Una governance coerente in ambienti misti rappresenta una delle maggiori sfide operative.

There is a version of the digital sovereignty conversation that leads organizations somewhere expensive, operationally burdensome, and – if they’re being honest – further than their actual obligations require. Maximum sovereignty sounds responsible. In practice, it’s often a miscalibration.

There is an equally common version that leads somewhere dangerously thin – controls that satisfy a checklist but wouldn’t survive an audit, an incident, or a regulator who has stopped accepting documented intent as proof of demonstrated control.

The organizations that get sovereignty right tend to do something more rigorous and more practical than either extreme: They ask what they actually owe, to whom, and for what. Then they build to that standard – no more, no less.

This is the discipline of MVS, introduced in the Rapporto sulla Readiness per la sovranità digitale  and developed in full here.

MVS isn’t a shortcut. It’s a recognition that the goal is the right level of control, applied consistently, across every workload that requires it.

Non tutti i carichi di lavoro sono uguali

The starting point for an MVS approach is workload classification – and most organizations skip it entirely.

A trading system processing regulated financial data carries fundamentally different sovereignty obligations than an internal HR collaboration tool. A database holding personal data of EU citizens is subject to a different legal and regulatory regime than a development environment running anonymized test data.

Treating all of these identically – either by applying maximum sovereign controls across the board or by assuming a single deployment model covers everything – is how organizations end up either over-engineered or under-protected.

The right question before any deployment decision: What does this workload require across each of the four sovereignty pillars? The Readiness Report includes a self-assessment structured around exactly that question.

The Three Profiles – and What They Actually Need

Le imprese soggette a regolamentazione rientrano in tre profili ben definiti, ciascuno con motivazioni principali e priorità di investimento diverse.

  • The True Sovereign. Government agencies, defense contractors, and critical national infrastructure operators. For these organizations, sovereignty is not a compliance requirement – it is an operational mandate. Maximum control over every dimension of the technology stack is often legally required, and the cost tradeoffs are accepted because the alternative is not.
  • The Regulated Organization. Financial services firms, healthcare organizations, energy companies. These organizations face binding requirements from DORA, NIS2, GDPR, and sector-specific frameworks. Compliance obligations may also map to EU certification schemes – including EUCS, EUCC, BSI C5, and SecNumCloud – depending on sector and deployment context.

on-negotiable in certain areas – particularly around data residency, operational access controls, and recovery within jurisdictional boundaries. But not every workload carries the same obligation.

  • The Hybrid Multi-Cloud Organization. Organizations with existing hyperscaler investments facing increasing sovereignty pressure from customers, regulators, or procurement requirements. Their challenge is not wholesale migration – it’s layering sovereign controls onto a mixed estate and maintaining consistent governance across it.

Il costo di una calibrazione errata

Over-engineering sovereignty creates its own operational risks. Organizations that apply maximum sovereign controls to workloads that don’t require them absorb cost and complexity that serves no regulatory or business purpose.

Under-engineering is the more common failure mode, and the more dangerous one. It typically doesn’t show up until the audit arrives – or, more seriously, until an incident occurs and recovery becomes a legally constrained problem. (That failure mode is the subject of the quarto articolo di questa serie.)

Un punto di partenza pratico

Un approccio MVS prevede tre passaggi:

  1. Classify workloads by their actual sovereignty requirements across each pillar – don’t start with deployment models.
  2. Mappare ciascuna classe di carico di lavoro al livello di implementazione che soddisfa tali requisiti, nell’intero spettro che va dalle regioni degli hyperscaler pubblici al cloud pubblico sovrano fino agli ambienti gestiti on-premise.
  3. Govern the resulting mixed estate consistently – controls, audit evidence, and recovery capabilities must be demonstrable across the full environment, not just the most-sovereign tier.

The third step is where most programs struggle. Maintaining consistent sovereignty controls across a mixed estate is an operational governance challenge – and specifically the domain of Operational Sovereignty – argomento del terzo articolo di questa serie, il pilastro che la maggior parte delle strategie considera come un aspetto secondario.

Utilizzate l’autovalutazione contenuta nelRapporto sulla Readiness per la sovranità digitaleper individuare la vostra posizione attuale rispetto a tutti e quattro i pilastri.

Domande frequenti

D: Che cos’è la “sovranità minima funzionante” (MVS)?

A: L’MVS consiste nell’applicare controlli di sovranità in base alle effettive esigenze aziendali e normative. Ha lo scopo di evitare sia un eccesso di complessità che una protezione insufficiente.

D: Perché è importante la classificazione del carico di lavoro?

A: Carichi di lavoro diversi comportano obblighi normativi e operativi diversi. La classificazione dei carichi di lavoro aiuta le organizzazioni ad applicare il livello appropriato di controlli di sovranità.

D: Quali sono i tre profili di sovranità più comuni?

A: I tre profili sono: organizzazioni sovrane vere e proprie, organizzazioni regolamentate e organizzazioni ibride multi-cloud. Ciascuna di esse presenta requisiti operativi e di conformità distinti.

D: Quali rischi comporta un approccio eccessivamente ingegneristico alla sovranità?

A: Controlli eccessivi possono aumentare la complessità operativa e i costi senza garantire una conformità significativa né apportare valore aggiunto all’azienda.

D: Perché gli ambienti misti comportano sfide in termini di governance?

A: Le organizzazioni operano spesso su più modelli di cloud e infrastrutture. È difficile garantire la coerenza dei controlli, delle prove di audit e degli standard di Recovery in tutti gli ambienti.

Ruben Renders è direttore delle soluzioni MSP presso Commvault.

More related posts


Thumbnail-Digital-Sovereignty-4

Sovereign Data You Can’t Recover Isn’t Actually Sovereign

Read more about Sovereign Data You Can’t Recover Isn’t Actually Sovereign
Thumbnail-Digital-Sovereignty-3

The Pillar Most Sovereignty Strategies Forget

Read more about The Pillar Most Sovereignty Strategies Forget
Thumbnail-Digital-Sovereignty-1

You Don’t Have a Sovereignty Strategy. You Have a Residency Policy.

Read more about You Don’t Have a Sovereignty Strategy. You Have a Residency Policy.

Punti di forza

  • La residenza dei dati indica il luogo in cui questi sono archiviati, ma la sovranità digitale richiede anche il controllo sull’accesso, sulle operazioni e una corretta comprensione delle implicazioni giurisdizionali.
  • La sovranità operativa è spesso l’aspetto più debole e meno sottoposto a verifica della maggior parte dei programmi di sovranità.
  • Una posizione di sovranità completa si basa su quattro pilastri: la località dei dati, la sovranità tecnologica, la sovranità operativa e la sovranità giurisdizionale.
  • La sovranità non è una questione binaria; le organizzazioni devono definire una strategia in linea con i propri obblighi normativi e operativi.

Here is a question worth sitting with: When your organization made its sovereignty decision, what exactly did it decide?

For most, the answer is some version of the same thing. Pick a region. Move the workloads. Choose a cloud provider with data centers in-country. Check the box. The question of where data lives was answered, and the sovereignty conversation was considered closed.

But it wasn’t closed. It had barely started.

Data residency answers one question: Where? Digital sovereignty asks three more – who, how, and under what conditions?

The conflation of residency with sovereignty is understandable. Hyperscalers have made region selection feel like a sovereignty decision. Compliance checklists ask where data is stored. Regulatory guidance, at least in its earlier iterations, focused heavily on geography.

Choosing a sovereign cloud region is a real thing – it matters, it has operational implications, and it’s a necessary first step. But it is only a first step. And most organizations stopped there.

What Residency Doesn’t Answer

Think of it this way: Choosing a sovereign cloud region is like buying a safe. It tells you where your valuables are stored. It says nothing about who has a copy of the combination, who manufactured the safe, which country’s laws govern the manufacturer, or whether you can open it if compelled to.

Region selection answers one question. Three more remain entirely open – and these are the questions regulators, procurement committees, and auditors are now asking with increasing precision:

  • Who can operate your environment, and from where? Whether your cloud provider’s support personnel are subject to foreign jurisdiction is a sovereignty question that data residency cannot resolve. A routine maintenance window performed by a support engineer in a different legal jurisdiction is an access pathway your residency policy doesn’t cover. This is the domain of Operational Sovereignty – the hardest pillar to audit and the most commonly overlooked.
  • Under what legal regime can your data be accessed? A foreign technology provider operating infrastructure in-country does not automatically remove the reach of their home jurisdiction’s law. The extraterritorial reach of foreign legal regimes is a risk that geography alone cannot eliminate.
  • Can you recover your data if something goes wrong? Most sovereignty programs are built around access control. Very few address recovery – whether your data can be restored cleanly, within defined tolerances, by personnel who operate within your sovereignty boundary. That gap is where sovereignty postures most commonly fail under real conditions.

Il quadro di riferimento che colma il divario

A complete sovereignty posture spans four interdependent pillars. The Rapporto sulla Readiness per la sovranità digitale – available at readiverse.com – walks through each in full. In brief:

  • Data locality addresses where data and metadata actually travel.
  • Technological sovereignty covers control over encryption, key custody, and architecture portability.
  • Operational sovereignty covers who runs the environment and from where.
  • Jurisdictional sovereignty establishes the legal framework governing and affecting all of the above.

No single pillar is sufficient. A strong data locality posture with weak operational controls is not sovereignty – it is residency with unexamined risk.

What makes the framework useful is not its complexity. It’s the questions it generates. When an organization maps its current posture against all four pillars for the first time, it almost always finds gaps it didn’t know were there – not because the controls are absent, but because the questions were never asked.

La sovranità è una scala mobile

One more thing worth naming: Sovereignty is not a binary state. There is no certification that grants it and no single deployment model that guarantees it. It is a posture – a set of deliberate, auditable decisions. And the right level of that posture varies by organization, by workload, and by what you actually owe regulators and customers.

That calibration is what minimum viable sovereignty is about – the subject of the secondo articolo di questa serie.

Regulatory confidence is built long before the audit itself – through clearly defined requirements, not assumptions tied to geography.

Download the Rapporto sulla Readiness per la sovranità digitale for the four-pillar framework and a practical self-assessment tool.

Domande frequenti

Q: What is the difference between data residency and digital sovereignty?

A: Data residency focuses on where data is physically stored. Digital sovereignty goes further by addressing who can access the data, how systems are operated, and exposure to which jurisdictions may create legal risk.

Q: Why is region selection not enough for sovereignty?

A: Choosing a cloud region only addresses geography. It does not resolve issues related to operational access, legal risks exposure, or recovery capabilities.

Q: What are the four pillars of digital sovereignty?

A: The four pillars are data locality, technological sovereignty, operational sovereignty, and jurisdictional sovereignty. Together, they create, what we believe, is a more complete framework for assessing sovereign readiness.

Q: Why is operational sovereignty difficult to manage?

A: Operational sovereignty involves monitoring who can access systems, where they operate from, and under which legal regime. These controls are harder to audit than simple data location requirements.

Q: Is digital sovereignty a fixed certification?

A: No. Sovereignty is an ongoing posture based on deliberate, auditable decisions that vary by organization, workload, and regulatory environment.

Ruben Renders is Solutions Director, MSP, at Commvault.

More related posts


Thumbnail-Digital-Sovereignty-3

The Pillar Most Sovereignty Strategies Forget

Read more about The Pillar Most Sovereignty Strategies Forget
Thumbnail-Digital-Sovereignty-4

Sovereign Data You Can’t Recover Isn’t Actually Sovereign

Read more about Sovereign Data You Can’t Recover Isn’t Actually Sovereign
Thumbnail-Digital-Sovereignty-2

Minimum Viable Sovereignty: Why the Right Posture Isn’t the Same for Every Organization

Read more about Minimum Viable Sovereignty: Why the Right Posture Isn’t the Same for Every Organization

Punti di forza

  • Gli attacchi di vishing hanno registrato un’impennata, con gruppi organizzati che hanno trasformato l’ingegneria sociale in una pratica sistematica per ottenere l’accesso iniziale tramite i servizi di assistenza.
  • Gli aggressori passano rapidamente dagli account utente compromessi a identità machine persistenti, come i token OAuth e gli account di servizio.
  • La maggior parte delle organizzazioni non dispone di meccanismi di governance e visibilità sulle identità non umane (NHI), creando così un grave punto cieco in termini di sicurezza.
  • Un’efficace Readiness dipende dalla correlazione dei segnali di identità e dal considerare le identità delle macchine come risorse ad alto rischio.
  • Una vera resilienza richiede la capacità di individuare e annullare le modifiche non autorizzate ai privilegi prima che gli aggressori riescano a stabilire una presenza persistente.

Your help desk staff just got a phone call. The caller knew the employee’s name, their manager, and the last four digits of their badge number. They asked for a password reset. Standard procedure. The IT rep complied.

That call was a fraud. And the attacker is now inside.

Voice phishing – vishing – jumped del 449% nel 2025. I gruppi di hacker hanno trasformato l’ingegneria sociale in un’operazione scalabile: reclutano operatori telefonici, redigono copioni eda 500 a 1.000 dollari per successful help desk impersonation. They’re not looking for your data. They’re looking for a foothold.

Once inside, attackers don’t linger on the human account. They move laterally – stealing OAuth tokens, creating new administrative service accounts, embedding access in machine-layer credentials that nobody watches. Unlike human passwords, those credentials are rarely rotated. They don’t trigger login alerts. They can survive a full remediation of the original compromised user.

By the time your security team closes the ticket on the help desk incident, the attacker may have been quietly persistent in your environment for weeks. The governance gap makes it worse.

Meno del 25% of organizations have formal policies for creating or decommissioning NHIs – the service accounts, API keys, and OAuth tokens that now outnumber human users by 144 a 1. Nearly all of them carry permissions far beyond what their function requires.

Most organizations have almost no confidence in their ability to detect an attack targeting this layer. That’s not a prevention failure. It’s a recovery planning failure.

Come si presenta la Readiness

Prevention at the help desk matters – training, callback verification, out-of-band confirmation. But it isn’t enough on its own. Attackers are industrializing faster than awareness programs can keep pace.

Readiness means correlating the signals: A help desk interaction followed immediately by a multi-factor authentication (MFA) reset or a new token creation is a high-probability indicator of compromise.

It means treating machine identities as Tier 0 assets – governing their creation, scoping their permissions, and monitoring for unauthorized escalation. And it means having the ability to detect and roll back malicious privilege changes quickly, before they become the new normal.

Explore how Resilienza delle identità di Commvaultconsente il rilevamento rapido, il rollback e il Recovery del vostro ambiente di gestione delle identità.

Domande frequenti

D: Che cos’è un attacco di vishing nel contesto della sicurezza aziendale?

A: Vishing (voice phishing) uses phone calls to impersonate employees and manipulate IT help desks into granting access – typically through password or MFA resets. It’s increasingly industrialized, with organized groups recruiting callers and using pre-written scripts to maximize success rates.

D: Perché gli autori degli attacchi passano alle identità delle macchine dopo essersi introdotti tramite vishing?

A: Human accounts get remediated. NHIs – OAuth tokens, service accounts, API keys – are more persistent and rarely rotated, often invisible to traditional monitoring. Migrating access to the machine layer allows attackers to maintain that persistence long after the original human credential breach is detected and closed.

Q: What does “identity resilience” mean in practice?

A: It means your organization can help detect unauthorized privilege changes in near real time and help restore the identity environment to a trusted state quickly. Detection alone isn’t sufficient – the ability to roll back malicious activity and verify that machine identities haven’t been tampered with (or if tampered with, to be rolled back to a prior good point in time) is what separates readiness from exposure.

Vidya Shankaran è il Field CTO di Commvault.

More related posts


Thumbnail_Blog-Identity-Resilience-MachineID-2026-Linkedin

The Machine Identity Blind Spot Is Now a Primary Attack Surface

Read more about The Machine Identity Blind Spot Is Now a Primary Attack Surface
Thumbnail_Blog-Help-Desk-2026-Linkedin

When the Help Desk Becomes the Front Door to Your Entire Network

Read more about When the Help Desk Becomes the Front Door to Your Entire Network
Thumbnail_Blog-SHIFT-Identity-Resilience-2026-Linkedin

Your Identity Infrastructure Is a Target. Here’s What Commvault Is Doing About It.

Read more about Your Identity Infrastructure Is a Target. Here’s What Commvault Is Doing About It.
Thumbnail_Blog-Rise-of-AI-Agents-in-Resops-2026

Commvault and Microsoft: The Rise of AI Agents in ResOps

Read more about Commvault and Microsoft: The Rise of AI Agents in ResOps
Thumbnail_Blog_Resilient-Against-the-AI-Machine

Resilient Against the AI Machine

Read more about Resilient Against the AI Machine

Punti di forza

  • L’ingegneria sociale nei servizi di assistenza è ormai diventata uno dei principali punti di accesso, con gli attacchi di vishing (phishing vocale) in rapido aumento che portano alla compromissione delle credenziali.
  • Le identità non umane, come gli account di servizio e i token, rappresentano un grave punto cieco in termini di sicurezza: spesso non vengono gestite e sono oggetto di gravi abusi finalizzati al movimento laterale.
  • Active Directory (AD) rappresenta un obiettivo di grande valore a causa del suo controllo centralizzato e delle potenziali configurazioni errate.
  • La prevenzione da sola non basta; le organizzazioni hanno bisogno di solide capacità di rilevamento e di ripristino rapido per limitare i danni.
  • Immediate operational actions – like auditing accounts and correlating help desk activity with identity changes – can significantly reduce risk.

AD rimane uno degli obiettivi principali degli hacker poiché è il fulcro della gestione delle identità aziendali.Ricerche recenti dimostrano cheil 67% degli incidenti comporta ormai una compromissione legata alle identità, with attackers going after critical systems like AD within hours of initial access.Once compromised, recovery can take days or weeks – causing significant business disruption.
The question worth asking isn’t whether AD is a target.It’s how attackers get tqui – and why the path is so much shorter than security teams might expect.

3 passi verso un compromesso completo

Gruppi di malintenzionati come ShinyHunters e Scattered Spider hanno trasformato l’ingegneria sociale in un’operazione su larga scala.Voice phishing – vishing – jumped 449% in 2025.I chiamanti vengono reclutati, istruiti su copioni prestabiliti epagati fino a 1.000 dollari depending on success and hit rate.
That means, it’s possible to start an attack with one step: Get a password reset or multi-factor authentication (MFA) change.That’s it.
From that single credential, the attacker moves laterally into cloud and virtualized environments.They harvest OAuth tokens, create new administrative service accounts, and embed access in machine-layer credentials.These non-human identities – service accounts, API keys, tokens – now outnumber human users 144 to 1.La proliferazione e i costi operativi rendono difficili la rotazione e l’audit. Quel movimento laterale ha una destinazione: Active Directory.

La pubblicità è l’obiettivo

AD is the central nervous system of enterprise identity.Control it and you control everything – user accounts, group policies, and access to every domain-joined system in the network.The reason it’s so attractive to attackers – and so difficult to defend – is structural.Any authenticated user can read the entire directory.Every domain-joined system inherits trust from it.
Group Policy Objects linked at the domain head can be weaponized to disable security controls outright.Legacy protocols left enabled for application compatibility provide straightforward access.Microsoft’s own documentation says that “most identity attacks utilize common misconfigurations in Active Directory.”

When an attacker reaches the AD, they don’t need to force entry.The door is usually open.

La prevenzione è necessaria ma non sufficiente

The standard security stack – MFA, endpoint detection, email filtering – is built around human behavior.It wasn’t designed to govern the machine identity layer or to detect the kind of slow, legitimate-looking privilege escalation that characterizes modern AD attacks.An attacker that moves from a compromised human account to a service account to a domain administrator over 72 hours may never trigger a single alert.
This is why the conversation must shift from prevention-first to recovery-first.
Prevention still matters.Least-privilege access, auditing AD changes, hardening default configurations, disabling inactive accounts – these can help reduce the attack surface.But given that half of organizations have already experienced an AD attack, designing only for prevention means designing to fail.
True identity resilience requires the ability to detect unauthorized privilege escalations in near real time, roll back malicious changes before they propagate, and restore the identity environment to a known-trusted state quickly – not in days or weeks, but fast enough to contain the blast radius.That means treating AD and the non-human identity layer as Tier 0 assets, with the same governance and recovery investment you’d apply to any other mission-critical system.

Cosa fare subito per rafforzare la resilienza dell’identità

The gap between wqui most organizations are and wqui they need to be on identity resilience is real.But it’s closeable.The immediate priorities are unglamorous and operational:

  1. Audit what’s in your AD.
  2. Find the accounts that shouldn’t still exist.
  3. Rotate the credentials that haven’t been touched in years.
  4. Correlare l’attività dell’help desk con gli eventi relativi alla creazione di token e account.

A help desk interaction followed by an MFA reset followed by a new service account is a high-confidence attack signal – and it’s detectable if you’re looking for it.
The longer-term work is architectural: Build recovery capability into your identity program so that when an attack succeeds – and it’s usually when, not if – you can contain it, reverse it, and try to restore trust faster than the attacker can consolidate their position.
Attackers are counting on your AD being ungoverned, your machine identities being invisible, and your recovery plan being theoretical.Close one of those gaps this quarter.Close all three and you’ve fundamentally changed the math. 

: dalla valutazione delle vulnerabilità al rollback con un solo clic, fino al ripristino completo della foresta.
Recentemente ho partecipato al podcast STRIVE insieme a Vidya Shankaran per parlare del divario di governance relativo alle identità non umane. Ascolta la nostra puntata
– from vulnerability assessment to one-click rollback and full forest recovery.
I recently joined Vidya Shankaran on the STRIVE podcast to talk about the governance gap for non-human identities.Check out our episode qui.And be sure to read Vidya’s blog, Il punto cieco dell’identità delle macchine è ormai diventato una delle principali superfici di attacco.

Domande frequenti

Q: Why are help desks becoming a major security risk?

A: Help desks are often trusted to reset passwords and modify MFA settings, making them attractive targets for social engineering.Attackers exploit this trust to gain initial access with minimal resistance.
Q: What role do non-human identities play in attacks?

A: Sprawl and operational overhead make rotation and audit of non-human identities, such as service accounts and API keys, difficult.Attackers use them to maintain persistence and move undetected across systems.
Q: Why is AD such a critical target?

A: AD controls authentication and access across the network.Gaining control of it allows attackers to manage users, policies, and systems at scale.
Q: Isn’t MFA and endpoint security enough to stop these attacks?

A: These tools focus on human behavior and may not detect slow, legitimate-looking privilege escalation.Attackers can operate within normal patterns and avoid triggering alerts.
Q: What does a recovery-first security approach mean?

A: It means preparing for the reality that breaches will happen and prioritizing the ability to detect, contain, and reverse them quickly.This approach helps reduce downtime and can help limit overall impact.
Q: What are the most important steps to take immediately?

A: Start by auditing your AD, removing unnecessary accounts, rotating old credentials, and monitoring for suspicious sequences of help desk and identity-related activities.
Dan Conrad è responsabile tecnico e CTO sul campo presso Commvault.

More related posts


Thumbnail_Blog-Okta-Early-Access-2026

Commvault® Extends Identity Resilience to Okta

Read more about Commvault® Extends Identity Resilience to Okta
Thumbnail_Blog-Lateral-Access-2026

Staying Resilient Against Lateral Access Exploits

Read more about Staying Resilient Against Lateral Access Exploits
Thumbnail_3_AD_Blogs_2025

Active Directory Forest Recovery: Why Manual Methods Are No Longer Viable

Read more about Active Directory Forest Recovery: Why Manual Methods Are No Longer Viable
Thumbnail_6_AD_Blogs_2025

AD Recovery Testing: How to Know Your Recovery Plan Will Actually Work

Read more about AD Recovery Testing: How to Know Your Recovery Plan Will Actually Work

Punti di forza

  • Le identità non umane (NHI) superano ormai di gran lunga il numero degli utenti umani e stanno crescendo a un ritmo molto più rapido, creando una superficie di attacco significativa e poco regolamentata.
  • Gli autori degli attacchi ricorrono sempre più spesso a tecniche di ingegneria sociale, come il phishing vocale (vishing), per aggirare le difese umane e ottenere l’accesso alle credenziali a livello di sistema.
  • Most NHIs operate with excessive permissions and lack proper lifecycle management, contributing to accumulated “identity debt.”
  • Gli strumenti di sicurezza tradizionali non riescono a rilevare le minacce a livello di macchina perché gli NHI si comportano in modo diverso dagli utenti umani.
  • Le organizzazioni devono passare da strategie incentrate sulla prevenzione ad approcci incentrati sul ripristino, dando priorità all’individuazione rapida e alla neutralizzazione degli attacchi basati sull’identità.

For the past decade, enterprise security investment has followed the human. Better authentication. Stronger multi-factor authentication (MFA). Phishing simulation. Identity-centric architecture. These investments were the right response to the threat landscape at the time.

The threat landscape has moved.

Today’s most sophisticated adversaries aren’t trying to defeat your MFA. They’re using it as a door. A convincing phone call to your IT help desk, an MFA reset, and a compromised human account – that’s the entry. What they’re actually after is what’s behind it: the sprawling, under-governed layer of NHIs that connects every system in your environment.

La portata del problema è sbalorditiva

Service accounts, API keys, OAuth tokens, AI agents – NHIs now outnumber human users by a ratio of 144 a 1, and they’re growing 4 a 10 volte più velocementedegli account umani. Eppure,meno del 25% of organizations have formal policies governing their creation or decommissioning. Nearly all of them carry excessive permissions – rights that far exceed what their function requires.

This isn’t a new risk that suddenly appeared. It’s accumulated identity debt: years of provisioning without governance, automation without accountability, cloud expansion without visibility. And adversaries have noticed.

Il vishing è il punto di accesso

Groups like ShinyHunters and Scattered Spider – operating under what researchers call the Scattered LAPSUS$ Hunters (SLH) cluster – have industrialized social engineering to exploit exactly this gap. Voice phishing rose del 449% nel 2025. These aren’t opportunistic calls. They’re coordinated operations: purpose-built scripts, recruited callers, incentivi finanziari fino a 1.000 dollari per successful help desk impersonation.

The call isn’t the attack. The call is the credential reset that gets an attacker past the human perimeter. The attack begins when they migrate to the machine layer – stealing OAuth tokens, creating administrative service accounts, embedding access into credentials that are rarely monitored and almost never rotated.

The human account gets remediated. The machine-layer access persists. The attacker has already moved on.

Three Vulnerabilities that Traditional Controls Can’t See

Standard security tools are designed around human behavior. They flag anomalous logins, unusual geolocation, suspicious email traffic. NHIs operate differently, and that difference is the blind spot.

OAuth abuse, for instance, looks like normal API traffic – even after a password reset. Thousands of undocumented service accounts operate in large enterprises with administrative privileges, often long after the projects that created them ended. Long-lived API keys embedded in DevOps pipelines carry broad access with no device context and no login alert.

MFA doesn’t cover them. Endpoint detection doesn’t see them. Email filtering is irrelevant to them.

Il cambiamento di paradigma: dalla prevenzione al recupero

The logical response to a threat that often evades traditional detection is to stop assuming you can prevent every intrusion and start designing for rapid recovery from the ones that succeed.

That means treating NHIs as Tier 0 assets – with the same governance controls applied to domain administrators or cloud control planes managed with human identities. It means replacing static secrets with short-lived tokens and automatic rotation.

It also means correlating cross-domain signals: A help desk interaction followed by an MFA reset followed by a new token creation is a high-confidence indicator of compromise, and catching it early is the difference between containment and a prolonged breach. It means mapping NHIs to human identities for accountability.

Most importantly, it means having the capability to detect unauthorized privilege escalations and roll back malicious identity changes in real time – returning the environment to a known-trusted state before the damage extends.

Prevention still matters. But given the governance gap many organizations are carrying, recovery speed is becoming a primary resilience metric. Organizations should build identity programs designed for the attacks that are already happening, not the ones that were common five years ago.

Visit the Readiversee dai un’occhiata al nostro eBookLa crisi d’identità non umana*, che esplora l’intera portata della superficie di attacco delle macchine e il quadro di riferimento per la resilienza dell’identità.

Domande frequenti

Domanda 1: Cosa sono le identità non umane (NHI)?

A: Gli NHI comprendono account di servizio, chiavi API, token OAuth e agenti di intelligenza artificiale che consentono a sistemi e applicazioni di interagire tra loro. A differenza degli utenti umani, spesso operano in modo automatico e su larga scala, il che li rende più difficili da monitorare e controllare.

Domanda 2: Perché gli NHI sono considerati un rischio per la sicurezza?

Gli NHI dispongono spesso di autorizzazioni eccessive e non sono soggetti a un’adeguata governance, il che li rende bersagli appetibili per gli hacker. Poiché vengono raramente monitorati o sottoposti a rotazione, le credenziali compromesse possono rimanere in uso per lunghi periodi senza essere individuate.

Domanda 3: In che modo gli hacker sfruttano gli NHI?

A: Gli autori degli attacchi ottengono solitamente l’accesso iniziale tramite tecniche di ingegneria sociale, come il voice phishing, per poi passare al livello dei sistemi. Rubano i token, creano nuovi account di servizio o incorporano un accesso persistente nelle credenziali che non sono sottoposte a un monitoraggio rigoroso.

Q4: Why don’t traditional security tools detect these threats?

A: La maggior parte degli strumenti di sicurezza è progettata per monitorare il comportamento umano, come le anomalie negli accessi o i tentativi di phishing. Gli NHI generano un traffico di sistema che appare normale, il che consente alle attività dannose di mimetizzarsi tra le operazioni legittime.

Q5: What is meant by a “recovery-first” security approach?

A: Un approccio incentrato sul ripristino mira a individuare rapidamente le violazioni e a riportare i sistemi a uno stato sicuro, piuttosto che partire dal presupposto che tutti gli attacchi possano essere prevenuti. Ciò comporta l’identificazione delle modifiche non autorizzate e il loro ripristino in tempo reale.

Domanda 6: In che modo le organizzazioni possono migliorare la sicurezza del sistema sanitario nazionale?

A: Le organizzazioni possono considerare gli NHI come risorse critiche, attuare politiche di governance rigorose, sostituire le credenziali statiche con token a breve durata e correlare i segnali tra i vari sistemi. L’assegnazione degli NHI a responsabili umani migliora inoltre la responsabilità e la supervisione.

Vidya Shankaran è il Field CTO di Commvault.

More related posts


Thumbnail_Blog-SHIFT-Identity-Resilience-2026-Linkedin

Your Identity Infrastructure Is a Target. Here’s What Commvault Is Doing About It.

Read more about Your Identity Infrastructure Is a Target. Here’s What Commvault Is Doing About It.
Thumbnail_Blog-Rise-of-AI-Agents-in-Resops-2026

Commvault and Microsoft: The Rise of AI Agents in ResOps

Read more about Commvault and Microsoft: The Rise of AI Agents in ResOps
Thumbnail_Blog-Unified-Resilience-2026

Why AI Is Breaking Your Resilience Strategy (And What to Do About It)

Read more about Why AI Is Breaking Your Resilience Strategy (And What to Do About It)
Thumbnail_Blog_Resilient-Against-the-AI-Machine

Resilient Against the AI Machine

Read more about Resilient Against the AI Machine

Organizations today are building applications faster, automating workflows at scale, and turning data into insights, powered by platforms like Microsoft Power Platform. What started as a low-code productivity layer has quickly become mission-critical, embedded in the processes that support revenue generation, day-to-day operations, and strategic decision-making.

But as the reliance on these business intelligence assets grows, so does the associated risk. The same platform accelerating innovation can also amplify the impact of operational errors, misconfigurations, and malicious actions.

A misconfigured workflow, a deleted report, or a broken application can disrupt business processes, compromise decision-making, and erode trust in the systems the business relies on. And when something goes wrong, recovery is rarely straightforward.

Commvault is helping address these challenges with enterprise-grade data protection and recovery for Microsoft Power Platform, starting with Power BI – allowing organizations to help keep the insights, workflows, and apps they build protected and rapidly recoverable. 

Power BI: Il divario tra analisi e recupero

At the center of many Power Platform deployments is Microsoft Power BI, providing analytics and business intelligence, transforming data into reporting, forecasting, and operational visibility.

When Power BI assets are lost or compromised teams can quickly lose access to trusted insights, interrupting reporting cycles, and delaying business decision-making.

In practice, however, protection strategies lag behind the importance of these assets. Many organizations rely on manual file exports or limited native capabilities that weren’t designed for comprehensive recovery. When something breaks, teams are often forced to rebuild manually with no ability to restore exactly what’s needed. This makes recovery slow, error-prone, and difficult to scale.

Commvault Cloud Backup & Recovery for Microsoft Power Platform

Now generally available, Commvault Cloud Backup & Recovery for Microsoft Power Platform helps organizations protect and recover their business-critical assets, such as reports, from accidental deletion, corruption, and malicious activity.

  • Protezione automatizzata basata su criteri: applica backup guidati da criteri a tutte le risorse dell’area di lavoro di Power BI, garantendo una copertura coerente e scalabile senza interventi manuali.
  • Ripristino rapido e dettagliato: ripristina singoli report e cartelle a un momento specifico nel tempo, evitando ricostruzioni manuali e contribuendo a ridurre al minimo i tempi di inattività e le interruzioni.
  • Backup isolati e immutabili: contribuisci a proteggere i dati dal ransomware e dalle modifiche non autorizzate grazie a backup progettati per impedire modifiche o cancellazioni non autorizzate.
  • Conformità semplificata: garantire la conservazione a lungo termine (fino a 10 anni), registri di audit centralizzati e reportistica a supporto dei requisiti normativi e interni.

Platform unificata Platform la resilienza

Commvault Cloud una platform unificata platform proteggere i carichi di lavoro SaaS, cloud e on-premise, tra cui Microsoft 365, Dynamics 365, Salesforce, macchine virtuali, database ed endpoint. Grazie Platform Microsoft Power Platform , i clienti possono ottimizzare la protezione, il ripristino e la resilienza per un numero maggiore di carichi di lavoro, contribuendo a ridurre la proliferazione degli strumenti e a semplificare le operazioni.

Come iniziare

Commvault Cloud Backup & Recovery for Power Platform is delivered as a SaaS solution, designed for fast deployment and minimal operational overhead. Organizations can connect their Power BI environment, apply policy-based protection, and begin backing up critical data in a matter of steps.

Il rilevamento automatico garantisce la protezione dei nuovi report e delle nuove cartelle man mano che gli ambienti si evolvono, mentre la gestione centralizzata offre un unico punto di controllo per monitorare, gestire e ripristinare i dati su larga scala.

What’s Next: Expanding Across Power Platform

Intendiamo ampliare la protezione e la resilienza in tutta Platform Microsoft Power Platform includere Power Apps e Power Automate, estendendo la copertura alle applicazioni e ai flussi di lavoro che sono alla base della vostra attività. I piani, le tempistiche e le funzionalità sono soggetti a modifiche e non devono essere considerati come elementi determinanti nelle decisioni di acquisto.

Proteggi ciò che alimenta la tua attività

Con Platform dell’utilizzo di Microsoft Power Platform , cresce anche la necessità di una protezione resiliente e di livello aziendale. Con Commvault Cloud, è possibile:

  • Proteggi le risorse critiche da cancellazione, danneggiamento e attacchi
  • Rapidly recover exactly what you need – without rebuilding everything
  • Mantenere la fiducia nei dati, nelle decisioni e nell’automazione
Sei pronto a rendere più resiliente il tuo investimento in Microsoft Power BI?

Scopri di più e guarda Commvault Cloud in azione sucommvault.com/platform/Power Platform.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza

  • La migrazione delle macchine virtuali a Red Hat OpenShift Virtualization è un percorso graduale che richiede una protezione costante in tutti gli ambienti ibridi.
  • Una platform unificata e nativa di Kubernetes per la protezione dei dati platform ridurre la complessità ed elimina la necessità di ricorrere a strumenti o processi separati.
  • Reliable resilience – including immutable backups and threat detection – is critical during migration, when risks are highest.
  • Le opzioni di ripristino flessibili consentono alle organizzazioni di adattarsi rapidamente in caso di fallimento delle fasi di migrazione o di variazioni delle tempistiche.
  • Il consolidamento della protezione per le macchine virtuali e i container contribuisce a ridurre la proliferazione degli strumenti e a garantire una governance coerente.

If you’re an IT leader today, chances are your virtualization strategy is under active review.

Rising costs, licensing uncertainty, and long-term vendor lock-in have many organizations reassessing their reliance on traditional hypervisors. At the same time, Kubernetes has matured into the operational foundation for modern applications.

These two realities are converging – and for many enterprises, Red Hat OpenShift Virtualization is emerging as a preferred destination for running virtual machines within a Kubernetes-native operating model.

This transition is accelerating across industries. As organizations modernize infrastructure on their own terms, Red Hat OpenShift Virtualization is increasingly viewed as a way to modernize the platform without the need for application refactoring. With that momentum comes a critical question:

How do you migrate virtual machines while maintaining consistent protection, resilience, and recoverability throughout the process?

To answer it, you need to examine how most enterprise migrations actually unfold – and where protection and resilience become critical.

La migrazione è un percorso, non un evento isolato

Seasoned IT leaders know that infrastructure transitions rarely happen all at once.

For enterprises opting to move from hypervisors like VMware to Red Hat OpenShift Virtualization, the transition typically unfolds in phases. During this time, organizations inevitably operate in a mixed state:

  • Le macchine virtuali basate su VMware continuano a supportare le operazioni aziendali fondamentali.
  • Macchine virtuali che girano da poco su Red Hat OpenShift Virtualization.
  • Applicazioni in container che condividono gli stessi cluster Red Hat OpenShift.

This coexistence period introduces complexity and risk. Data is in motion, environments are changing, and protection gaps can appear if tooling and processes don’t evolve alongside workloads.

È fondamentale garantire una protezione affidabile

Commvault offre da tempo soluzioni di protezione e ripristino dei dati sia per gli ambienti VMware che per i carichi di lavoro Kubernetes in esecuzione su Red Hat OpenShift. Lo stesso modello di protezione nativo per Kubernetes e basato su policy si estende ora alle macchine virtuali in esecuzione su Red Hat OpenShift Virtualization. Ciò che colpisce davvero i clienti è la coerenza:

  • Un’unica platform la protezione e il ripristino.
  • Operazioni basate su criteri applicate in modo uniforme a tutti i carichi di lavoro.
  • Progettato per integrarsi con gli strumenti e i processi già in uso, al passo con l’evoluzione degli ambienti.

Le macchine virtuali in esecuzione su Red Hat OpenShift Virtualization sono protette utilizzando gli stessi flussi di lavoro e gli stessi meccanismi di governance delle applicazioni containerizzate. Questo approccio unificato sta riscuotendo successo tra le organizzazioni che stanno adottando Red Hat OpenShift come standard e che desiderano un modo più semplice e coerente per gestire i dati in tutti gli ambienti. Questa funzionalità è già disponibile.Commvault Cloudsupporta la protezione degli ambienti Red Hat OpenShift Virtualization in linea con la versione 11.40 (Long-Term Support) e la versione 11.42 (Innovation), il che significa che i clienti possono già implementare queste funzionalità in produzione.

You Shouldn’t Need to Manage Protection Differently

Once VMs move to Red Hat OpenShift Virtualization, they shouldn’t require special handling from a protection standpoint.

Commvault Cloud discovers and protects Red Hat OpenShift Virtualization VMs alongside containerized applications, helping give teams centralized visibility, consistent policy enforcement, and simplified recovery operations. Virtualized and containerized workloads are managed together – without introducing operational silos.

For organizations managing diverse application portfolios, this treatment of VMs inside Kubernetes helps reduce operational friction while maintaining enterprise-grade controls.

La resilienza informatica è fondamentale quando la migrazione aumenta i rischi.

I periodi di migrazione rappresentano una fase particolarmente vulnerabile. Il cambiamento genera complessità, e la complessità aumenta l’esposizione alla perdita di dati e al ransomware. Commvault Cloud garantire la resilienza durante questa fase grazie a:

  • Backup isolati fisicamente e immutabili per i carichi di lavoro di Red Hat OpenShift Virtualization.
  • Dati di backup che supportano la ricerca delle minacce e l’analisi forense, aiutando i team a verificare la prontezza al ripristino prima di ripristinare i carichi di lavoro.
  • Advanced recovery capabilities designed to help organizations minimize operational disruption.

Che i carichi di lavoro si trovino in fase di pre-migrazione, nel bel mezzo della transizione o già pienamente operativi su Red Hat OpenShift Virtualization, il livello di resilienza rimane invariato.

La flessibilità nel recupero infonde fiducia

Every modernization initiative needs room for adjustment.

Commvault supports both in-place and out-of-place recovery for Red Hat OpenShift Virtualization virtual machines, including full VM context and configuration. If a migration step doesn’t go as planned – or timelines need to shift – teams may recover quickly and move forward without compromising availability or data integrity.

Protezione nativa per Kubernetes oltre le macchine virtuali

Per molte aziende, la virtualizzazione rappresenta solo una parte di una strategia più ampia di modernizzazione delle applicazioni. Commvault Cloud offre Cloud una protezione incentrata sulle applicazioni e nativa per Kubernetes per i carichi di lavoro containerizzati, inclusi i volumi persistenti e i metadati delle applicazioni, su tutte le distribuzioni Kubernetes certificate dal CNCF. Ciò garantisce la mobilità e il ripristino delle applicazioni cloud, contribuendo al contempo a mantenere la coerenza operativa tra i diversi ambienti.

Ridurre la proliferazione degli strumenti man mano che l’infrastruttura si evolve

Platform transitions often introduce new tools, new processes – and new complexity.

By using Commvault Cloud as a unified protection platform for:

  • Macchine virtuali VMware.
  • Macchine virtuali (VM) di Red Hat OpenShift Virtualization.
  • Applicazioni in container.

Le organizzazioni possono contribuire a ridurre la proliferazione degli strumenti, semplificare l’amministrazione e garantire una governance coerente anche man mano che le strategie infrastrutturali si evolvono.

Come tutto si incastra

During any migration, it helps to understand how the pieces work together. Red Hat’s Migration Toolkit for Virtualization takes care of moving VMs from VMware into Red Hat OpenShift Virtualization.

Commvault Cloud helps provide the protection and resilience that stays with your workloads throughout the process, so data can remain protected before, during, and after migration. This can help keep recoverability from falling behind as workloads move.

Continuing the Conversation at Red Hat Summit

We’re already working with customers that are actively moving virtual machines onto OpenShift Virtualization – and we’re continuing these discussions at Red Hat Summit, May 11–14 in Atlanta.

At the Commvault booth, we’ll be:

  • Un dialogo con i responsabili IT sulle sfide concrete in materia di resilienza.
  • Consigli pratici per affrontare la migrazione con fiducia.
  • Dimostrazione Cloud Commvault Cloud per Red Hat OpenShift Virtualization.

If maintaining resilience and recoverability throughout your virtualization strategy is a priority, we’d welcome the opportunity to connect.

Andare avanti con fiducia

Red Hat OpenShift Virtualization is becoming a foundational component of modern enterprise infrastructure. But you can’t rush migration at any cost; you must build protection, resilience, and recovery into the process from the beginning.

With Commvault Cloud, protecting Red Hat OpenShift Virtualization workloads isn’t a future aspiration. It’s something customers already are doing – using a unified platform to modernize confidently while staying resilient and recoverable.

“Red Hat OpenShift Virtualization delivers a reliable, consistent foundation for organizations to support their entire virtualized estate,” says Steve Gordon, Senior Director, Product Management, Hybrid Cloud Platforms, at Red Hat. “By leveraging an optimized integration like Commvault Cloud with Red Hat OpenShift Virtualization, our customers can move forward with greater confidence, knowing their workloads are protected consistently before, during, and after migration.”

Domande frequenti

D: Perché la migrazione delle macchine virtuali è considerata un processo articolato in più fasi?

A: La maggior parte delle aziende non è in grado di migrare tutti i carichi di lavoro contemporaneamente, pertanto opera in un contesto ibrido in cui gli ambienti legacy e quelli nuovi funzionano in parallelo. Questo approccio graduale comporta una certa complessità, rendendo essenziali una protezione e una visibilità costanti durante l’intera transizione.

D: Che ruolo svolge la resilienza durante la migrazione delle macchine virtuali?

A: La resilienza consente alle organizzazioni di garantire la protezione dei dati, di riprendersi rapidamente dai guasti e di difendersi da minacce come il ransomware. Durante la migrazione, quando i sistemi sono in fase di transizione, misure di resilienza efficaci possono aiutare a prevenire la perdita di dati e le interruzioni operative.

D: In che modo Commvault Cloud la protezione in tutti gli ambienti?

A: Commvault Cloud un’unica platform protezione basata su criteri per le macchine virtuali VMware, le macchine virtuali OpenShift Virtualization e le applicazioni containerizzate. Questo approccio unificato consente di garantire operazioni coerenti senza dover introdurre nuovi strumenti o flussi di lavoro.

D: Perché è importante la protezione nativa di Kubernetes?

A: La protezione nativa di Kubernetes si adatta alle modalità di distribuzione e gestione delle applicazioni moderne, coprendo sia i container che le macchine virtuali. Consente una gestione semplificata dei dati, la mobilità e il ripristino all’interno di ambienti cloud.

D: In che modo la flessibilità del ripristino aumenta la fiducia nella migrazione?

A: Le opzioni di ripristino flessibili, come il ripristino in loco e fuori sede, possono aiutare i team a ripristinare rapidamente i carichi di lavoro in caso di problemi. Questa flessibilità contribuisce a ridurre i tempi di inattività e consente alle organizzazioni di adeguare i piani di migrazione senza compromettere l’integrità dei dati.

D: In che modo le organizzazioni possono ridurre la complessità durante le transizioni infrastrutturali?

A: By adopting a unified data protection platform, organizations can manage all workloads – virtualized and containerized – through a single interface. This approach helps reduce tool sprawl, simplify administration, and maintain consistent governance across evolving environments.

Jason Gizaè Senior Manager del reparto Global Content Partner Marketing presso Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza

  • La la Readiverse Academy ha introdotto un percorso di certificazione strutturato e articolato in livelli, che spazia dalle conoscenze di base alle competenze avanzate cloud .
  • Le certificazioni sono in linea con i ruoli professionali reali e consentono ai partecipanti di sviluppare competenze pertinenti alle loro responsabilità negli Cloud Commvault Cloud .
  • The program includes four tiers – Practitioner, Specialist, Professional, and Expert – each increasing in depth and operational capability.
  • L’apprendimento si articola attorno a tre pilastri fondamentali: platform , cyber resilience e workload .
  • Le opzioni di formazione flessibili, che comprendono sia corsi autogestiti che tenuti da un docente, consentono ai professionisti di progredire in base ai propri impegni e ai propri obiettivi.

The environments you protect with Commvault® Cloud are increasingly complex, and the expectations on your teams that run them are higher than ever. It’s no longer just about knowing the platform. It’s about being able to operate, protect, and recover, often under pressure.

If you’ve already started your learning journey in the la Readiverse Academy, welcome back. And if you’re new here, you’re joining at the right time.

Today, we’re introducing a structured, tiered certification approach that gives learners a clear, skill‑based path from foundational platform knowledge to advanced cloud engineering expertise.

Creiamo contenuti su misura per te

Commvault Cloud environments demand expertise across multiple responsibilities, often within the same role. Administrators, security specialists, cloud engineers, and workload owners require different depths and breadths of knowledge. And not everyone needs to learn the same things, in the same order, to be effective.

The new la Readiverse Academy certification tiers reflect that reality. Learners progress through clearly defined levels that build on one another so that your certification aligns to what you actually do and validates those capabilities to the teams you work with.

  • Commvault Cloud Practitioner – foundational platform and resilience knowledge.
  • Commvault Cloud Specialist – expanded operational and security depth.
  • Commvault Cloud Professional – advanced recovery and workload expertise.
  • Commvault Cloud Expert – full cloud engineering and resilience leadership.

Each tier is earned through a combination of coursework, hands‑on lab activities, and validated assessments. As learners progress, the scope and depth of operational capability demonstrated increases accordingly.

Un percorso chiaro: da principiante a esperto

Il programma di certificazione si articola attorno a tre pilastri fondamentali di competenze che caratterizzano ogni livello:

  • platform di base platform
  • Concetti di resilienza informatica
  • Workload competenze specifiche

Ogni livello prevede requisiti specifici relativi a tali pilastri. Gli studenti possono seguire singoli corsi oppure combinare i requisiti indicati per raggiungere gli obiettivi di certificazione.

Already in la Readiverse Academy? What this Means for You.

With a new structure like this, the most important question is what it means for the progress you’ve already made. If you’ve already completed courses or earned certifications in the la Readiverse Academy, congratulations! Your investment matters, and we want to be clear about what happens next.

Those certifications represent your history and accomplishments with Commvault. The new program is aligned to our expanded portfolio of cyber resilience features for Commvault Software, Commvault SaaS, and hybrid environments. As your needs grow to require more from Commvault, these courses and certifications will help you configure, manage, and optimize Commvault to meet your organization’s unique needs.

There is no direct progression from the previous certification tracks to the new program, but your existing certifications validate your expertise on the former product releases. As those releases are retired, those certifications will reach end of life as well. Learners who are already invested in the la Readiverse Academy are well positioned to progress quickly.

Who Should Take la Readiverse Academy Courses and Certifications

la Readiverse Academy certifications are designed for professionals working across Commvault SaaS, Commvault Software, and hybrid environments.

  • Platform administrators managing day‑to‑day operations.
  • Specialisti della sicurezza specializzati nella protezione dei dati e nel rafforzamento della sicurezza degli ambienti.
  • Cloud responsabili della configurazione del piano di controllo e della resilienza avanzata.
  • Workload che devono possedere competenze in ambiti specifici relativi ai dati.

All training is available for self‑paced learning, with select courses also offered in instructor‑led formats, so learners can progress in a way that fits their role and schedule.

Come iniziare o proseguire il proprio percorso di apprendimento

Whether you’re starting fresh or continuing your journey, the next step is simple and designed to meet you where you are.

  • Accedi o registrati sucommvault.com.
  • Non conosci ancora Commvault? Inizia con il corso “Commvault Cloud ”.
  • Ti occupi del workload ? Dai un’occhiata al nostro catalogo di corsi che coprono praticamente ogni argomento.
  • Cerchi strategie per favorire il ripristino dopo un attacco informatico? Il corso sulla resilienza informatica è il punto di partenza ideale.

Cosa ci aspetta

Our goal is to make advancement predictable, transparent, and aligned to real‑world roles to help learners know what’s next and how to prepare for it.

We are committed to giving every Commvault Cloud user the knowledge to operate, protect, and recover their environment with confidence. Because when it matters most, certification isn’t about credentials. It’s about being resilient and ready to recover.

Domande frequenti

Q: What is the purpose of the la Readiverse Academy certification program?

A: Il programma offre un percorso formativo strutturato e incentrato sulle competenze, che aiuta i professionisti a passare dalle platform di base platform a competenze avanzate cloud . Allinea la formazione alle responsabilità del mondo reale per consentire ai partecipanti di applicare efficacemente le proprie conoscenze in contesti complessi.

D: Quali sono i diversi livelli di certificazione disponibili?

A: Esistono quattro livelli: Commvault Cloud , Specialist, Professional ed Expert. Ogni livello si basa su quello precedente, con un progressivo aumento della profondità tecnica, dell’ambito operativo e delle capacità di leadership.

Q: Who should enroll in la Readiverse Academy courses?

R: I corsi sono pensati per platform , specialisti della sicurezza, cloud e workload che operano in ambienti SaaS, software e ibridi. Ciascun ruolo può seguire un percorso formativo su misura in base alle proprie responsabilità.

D: Come si ottengono le certificazioni?

A: Le certificazioni si ottengono attraverso una combinazione di corsi, esercitazioni pratiche e valutazioni convalidate. Man mano che gli studenti progrediscono, dimostrano livelli crescenti di competenza workload platform, della sicurezza e workload .

Q: What happens to existing la Readiverse Academy certifications?

A: Le certificazioni esistenti rimangono valide come prova delle competenze acquisite in passato, ma sono legate alle versioni precedenti del prodotto. Man mano che tali versioni vengono ritirate dal mercato, le certificazioni giungeranno al termine del loro ciclo di vita, incoraggiando gli studenti a passare al nuovo programma.

D: Come si può iniziare a utilizzare il nuovo programma?

R: I nuovi studenti possono iniziare con il corso “Commvault Cloud , mentre gli utenti già registrati possono effettuare l’accesso per proseguire il proprio percorso formativo. Sono disponibili ulteriori corsi in base a obiettivi specifici, quali workload o cyber resilience .

Suzanne Klausner è direttore della strategia di supportazione dei clienti presso Commvault.

More related posts


Thumbnail_Blog-Ready-or-Not-2026

Why Every CIO Needs a ‘Ready. Or Not.’ Mindset

Read more about Why Every CIO Needs a ‘Ready. Or Not.’ Mindset
Thumbnail_Blog_Readiness-Update-2024

Boost Your Cyber Resilience and Readiness

Read more about Boost Your Cyber Resilience and Readiness
Social_Readiverse_Blog_LinkedIn-1

The Readiverse: Your Go-To Learning Resource for Cyber Resilience and Readiness

Read more about The Readiverse: Your Go-To Learning Resource for Cyber Resilience and Readiness

Punti di forza

  • I flussi di lavoro di ripristino tradizionali possono causare una deriva dell’infrastruttura negli ambienti gestiti da Terraform, poiché prevedono il provisioning di nuove risorse al di fuori dello stato.
  • Clumio Backtrack è progettato per ripristinare i dati direttamente nei bucket S3 e nelle tabelle DynamoDB esistenti, contribuendo a preservare l’identità delle risorse.
  • Il ripristino in loco contribuisce a ridurre la necessità di importazioni manuali di Terraform, di riconfigurazione degli endpoint e di riconciliazione dello stato durante gli incidenti.
  • Allineare i flussi di lavoro di ripristino ai principi dell’Infrastructure as Code (IaC) contribuisce a garantire l’integrità della configurazione e la prevedibilità operativa.
  • La progettazione del ripristino è fondamentale quanto quella del backup per i team che gestiscono ambienti di produzione tramite Terraform.

IaC brings consistency, repeatability, and version control to cloud environments. Terraform becomes the source of truth for what exists, how it is configured, and how it should behave. Recovery introduces a new challenge.

Traditional restore operations often create new resources – new S3 buckets, new DynamoDB tables, new endpoints. From Terraform’s perspective, those resources were not defined in code. They do not exist in state.

That creates drift. In routine operations, drift is manageable. During an incident, it compounds. This is where recovery design matters as much as backup design.

Il problema della deriva nell’IaC

In un modello di ripristino tipico:

  • Una risorsa protetta viene ripristinata come nuova risorsa.
  • La risorsa originale rimane in uno stato danneggiato, sovrascritto o non funzionante.
  • Lo stato di Terraform non riconosce la nuova risorsa.
  • I team devono importare manualmente le risorse in State.
  • Potrebbe essere necessario aggiornare le configurazioni delle applicazioni.

For platform teams managing production infrastructure through Terraform, this introduces friction at exactly the wrong moment. The challenge isn’t backup reliability itself, but how restore workflows integrate with infrastructure-as-code practices.

Presentazione del ripristino in loco con Clumio Backtrack

Clumio Backtrack è una funzionalità di ripristino che consente di ripristinare i dati direttamente nelle risorse AWS esistenti, anziché dover configurare un’infrastruttura sostitutiva. Se configurato tramite il provider Clumio Terraform, Backtrack consente di implementare flussi di lavoro di ripristino in linea con l’infrastruttura definita nel codice.

Clumio Backtrack supporta sia Amazon S3 che Amazon DynamoDB. Per un approfondimento tecnico sui flussi di lavoro di ripristino specifici per DynamoDB, consulta il nostro articolo sul blog dedicato aClumio Backtrack per DynamoDB.

Anziché provvedere alla fornitura di risorse sostitutive, Backtrack aiuta a ripristinare:

  • Oggetti S3 direttamente nel bucket originale.
  • Dati DynamoDB inseriti direttamente nella tabella originale.

From Terraform’s perspective, the infrastructure is intended to remain unchanged, with defined resources continuing to match the declared configuration. This helps reduce the need for manual resource imports, temporary restore tables, endpoint rewiring, and state reconciliation under pressure.

Un esempio pratico

Si consideri un ambiente di produzione gestito interamente tramite Terraform. Una tabella DynamoDB tiene traccia dell’inventario; un bucket S3 archivia le risorse dell’applicazione; i ruoli e le politiche di gestione delle identità e degli accessi sono codificati; e le politiche di protezione sono definite tramite Terraform. Se si verifica un danneggiamento prima di un evento di traffico di grande entità, gli approcci tradizionali di ripristino potrebbero creare nuove risorse che dovranno essere reintegrate in Terraform.

Con Backtrack, il ripristino è progettato per avvenire entro i limiti delle risorse esistenti, contribuendo a mantenere intatta l’infrastruttura definita e a preservare l’identità delle risorse. Questo approccio mira a eliminare la necessità di aggiornare Terraform per adattarlo a un bucket o a una tabella appena creati, trattando il ripristino come un’operazione a livello di dati piuttosto che come un’operazione di sostituzione dell’infrastruttura.

Perché questo è importante per Platform

Per i team che adottano l’IaC, i flussi di lavoro di ripristino dovrebbero garantire la conservazione dell’identità delle risorse, l’allineamento dello stato, l’integrità della configurazione e la prevedibilità operativa. Il ripristino in loco contribuisce al raggiungimento di tali obiettivi limitando le modifiche all’infrastruttura durante gli eventi di ripristino.

Ripristino su Cloud

Backtrack is designed to operate at cloud scale – whether restoring a small number of objects or large datasets. Recovery performance varies based on workload size and environment configuration, but the architectural objective remains consistent: restore data without introducing new infrastructure drift.

For Terraform-driven environments, that distinction matters.

In quali contesti si applica questo approccio

Il ripristino in loco è particolarmente indicato per:

  • Carichi di lavoro DynamoDB ad alta produttività
  • Bucket S3 con un numero elevato di oggetti
  • Sistemi di produzione gestiti interamente tramite Terraform
  • Ambienti complessi in cui è difficile reindirizzare le dipendenze delle applicazioni verso nuove risorse

Quando l’infrastruttura viene definita in modo dichiarativo, i flussi di lavoro di ripristino dovrebbero seguire la stessa logica.

Come iniziare

Per scoprire Clumio Backtrack e la sua integrazione con Terraform:

Definire la protezione come codice è solo una parte del quadro. La progettazione di flussi di lavoro di ripristino che preservino l’integrità dell’infrastruttura completa il modello.

Domande frequenti

D: Quali problemi comportano i ripristini tradizionali negli ambienti gestiti da Terraform?

A: I ripristini tradizionali spesso creano nuove risorse, come bucket S3 sostitutivi o tabelle DynamoDB, che non sono definite nello stato di Terraform. Ciò può causare una deriva dell’infrastruttura e costringere i team a importare manualmente le risorse e a riconciliare le configurazioni durante gli incidenti più critici.

D: In che modo Clumio Backtrack si differenzia dai metodi di ripristino standard?

A: Anziché implementare una nuova infrastruttura, Clumio Backtrack è progettato per ripristinare i dati direttamente nella risorsa AWS esistente. Questo approccio consente di preservare l’identità della risorsa e di mantenere lo stato di Terraform allineato alla configurazione dichiarata.

D: Quali servizi AWS sono supportati da Clumio Backtrack?

R: Clumio Backtrack supporta Amazon S3 e Amazon DynamoDB. È progettato per ripristinare gli oggetti S3 nel bucket originale e i dati DynamoDB nella tabella originale, contribuendo a mantenere la coerenza con l’infrastruttura definita nel codice.

D: Perché il ripristino in loco è importante per platform ?

A: Platform si affidano all’infrastruttura come codice per garantire coerenza e controllo. Il ripristino in loco contribuisce a mantenere l’allineamento dello stato, l’integrità della configurazione e la prevedibilità operativa senza introdurre ulteriori modifiche all’infrastruttura durante gli eventi di ripristino.

D: In quali casi il ripristino in loco risulta particolarmente utile?

A: It is especially useful for high-throughput DynamoDB workloads, Bucket S3 con un numero elevato di oggetti, and production systems fully managed through Terraform. It also can be beneficial in environments where redirecting application dependencies to newly created resources would be complex or risky.

D: Come possono le squadre iniziare a utilizzare l’integrazione tra Clumio Backtrack e Terraform?

A: Le squadre possono consultare ildocumentazione relativa al provider Clumio Terraform, esaminare ilcodice sorgente del provider su GitHub, and watch the video dimostrativo di Backtrack referenced in the blog to understand implementation and workflow details.

Lawrence Chang è Direttore tecnico di Clumio e Vir Choksiè responsabile principale del marketing di prodotto presso Commvault.

More related posts


Thumbnail_Blog-AWS-Data-Protection-Terraform-Clumio-2026

Automating AWS Data Protection with Terraform and Clumio

Read more about Automating AWS Data Protection with Terraform and Clumio
Thumbnail_Blog_Clumio-Tech-2025

Restore only what matters: Clumio Backtrack for DynamoDB

Read more about Restore only what matters: Clumio Backtrack for DynamoDB
Thumbnail_Blog-GoogleWorkspace-2026

How the Move to Clumio Delivered 66.7% Savings on AWS Backups

Read more about How the Move to Clumio Delivered 66.7% Savings on AWS Backups
Thumbnail_Blog_AWS-Marketplace-AI

Commvault Featured in New AI Agent Solutions in AWS Marketplace

Read more about Commvault Featured in New AI Agent Solutions in AWS Marketplace
Man-and-woman-working-on-laptops-profile-Crocus-Thumbnail

Protecting Your Amazon S3 Data with Clumio: A Comprehensive Solution

Read more about Protecting Your Amazon S3 Data with Clumio: A Comprehensive Solution

Clumio

Read more about Clumio

Punti di forza

  • La maggior parte delle esercitazioni teoriche serve a confermare l’efficacia delle prestazioni anziché mettere in luce le reali lacune nella risposta agli incidenti.
  • Affinché gli esercizi siano efficaci, devono prevedere elementi di attrito, ambiguità e pressione, in modo da rispecchiare le situazioni reali.
  • Limitare l’ambito dell’esercizio a pochi scenari critici e definire il successo come l’individuazione dei problemi piuttosto che come il semplice risultato di fare bella figura può portare a intuizioni più significative e concrete.
  • La partecipazione trasversale, e non solo quella dei team tecnici, è fondamentale per valutare con precisione la risposta dell’organizzazione.
  • La vera resilienza si dimostra attraverso test di ripristino concreti, non solo con scenari teorici.

There is a moment most security leaders recognize, even if they do not say it out loud. The tabletop just wrapped. The team is filing out. Everyone looks reasonably satisfied. And somewhere in the back of your mind, a quiet question surfaces: Did we actually learn anything?

If you are honest, the answer is often no.
That is not because tabletop exercises are a bad idea. They are one of the most valuable tools a security leader has. The problem is how most organizations run them – and what they are actually measuring when they do.

La trappola delle prestazioni

The most common mistake in tabletop exercises has nothing to do with the scenario. It has to do with the goal. Most teams, consciously or not, build exercises designed to demonstrate competence rather than discover gaps.
The scenario generally follows a clean arc. Information arrives in a logical sequence. The right people say the right things. Everyone feels prepared. And that feeling – confident, well-rehearsed, almost collegial – is exactly the problem.
Real incidents do not run on clean arcs. They arrive with incomplete information, conflicting signals, unavailable people, and a business demanding answers faster than the facts support. If your tabletop does not create that kind of friction, you have not tested incident response. You have practiced a conversation.
When the exercise is designed to validate rather than stress-test, a second problem follows: People stop being honest. Nobody says, “I don’t know who owns that decision” or “we have never actually tested that recovery path.” They say what sounds right. And the gaps that should surface in a controlled environment stay hidden until they surface in a real one.

Cosa verifica effettivamente un buon esercizio

Before you build a scenario, you need to answer a simpler question: What do you actually want to learn? Not 20 things. Three or four.
Can your team make a shutdown decision fast enough, and does everyone know who has the authority to make it? When security, IT, legal, and communications are all in the room with conflicting priorities, can they actually reach decisions together? Can you explain the business impact of an incident clearly enough for leadership to act – not just understand? And if you had to restore a critical system in the next four hours, could you really do it?

Once you know what you are testing, build a scenario with real friction. Make a key person unavailable mid-exercise. Introduce a customer escalation. Have a regulator ask a question the team cannot answer from the runbook.
Give people incomplete information and see how they make decisions anyway. The value is not in watching people succeed under pressure. It is in finding the places where the process breaks down while the stakes are still low enough to fix it.

Dite questo ad alta voce all’inizio: oggi il successo significa individuare i problemi, non fare bella figura. Quella sola frase cambia ciò che le persone sono disposte a dire in quella stanza.

Il problema delle persone

Una simulazione che coinvolga solo i reparti di sicurezza e IT è una discussione tecnica, non un’esercitazione di risposta agli incidenti. Se l’ufficio legale non è presente, se l’ufficio comunicazioni non è presente, se i responsabili di business e la dirigenza sono assenti, non state testando come la vostra organizzazione risponda effettivamente a una crisi. State solo verificando come un gruppo ristretto di persone competenti analizzi un caso ipotetico. Gli incidenti reali vengono gestiti a tutti i livelli dell’azienda. L’esercitazione dovrebbe rispecchiare questa realtà.

Parlarne non basta

This is where most organizations stop short. A paper exercise is important – but it is not confidence.
Talking through a recovery scenario tells you something. Actually restoring a system tells you something different. Can you bring identity back to a clean point in time? Can you validate that what you are recovering is trustworthy? Can you restore a Tier 1 application and confirm it comes back cleanly, without carrying the infection with it?

Those are not questions you can answer in a conference room. At some point, the plan has to meet the environment – and you need to know whether they match.

Al termine dell’esercitazione

The debrief tells you whether the exercise mattered. If the hot wash is quiet, vague, or full of “good reminders,” the exercise did not push hard enough. A well-run tabletop should leave you with a short list of real findings, clear owners, and deadlines. If you cannot answer what broke, who is fixing it, and by when, you ran an event, not an exercise.
The goal was never to pass the exercise. It was to learn something important while the cost of being wrong was still just time.
Watch our recent episode of the STRIVE podcast, where I join my colleague Chris Mierzwa, Senior Director, Portfolio Marketing, for una conversazione approfondita sulle esercitazioni teoriche.

Domande frequenti

D: Perché la maggior parte delle esercitazioni teoriche non riesce a fornire un valore concreto?

A: Molte esercitazioni sono concepite per far apparire le squadre ben preparate, piuttosto che per mettere in luce i loro punti deboli. Ciò porta a discussioni prestabilite che non rispecchiano l’imprevedibilità e la pressione degli incidenti reali.

D: Quale dovrebbe essere l’obiettivo di un’esercitazione teorica?

A: Dovrebbe concentrarsi sulla risposta a un numero limitato di domande fondamentali, quali la rapidità del processo decisionale, la chiarezza delle responsabilità e la capacità di recupero. Questo approccio aiuta i team a individuare lacune significative anziché limitarsi a osservazioni superficiali.

D: In che modo le organizzazioni possono rendere le esercitazioni più realistiche?

A: Introdurre elementi di incertezza, informazioni mancanti e interruzioni impreviste nel corso dello scenario. Questi elementi costringono i team a pensare in modo critico e ad agire sotto pressione, in condizioni più simili a quelle di un incidente reale.

D: Chi dovrebbe partecipare a un’esercitazione teorica?

A: Oltre ai reparti di sicurezza e IT, dovrebbero partecipare anche team come quelli dell’ufficio legale e della comunicazione, i responsabili aziendali e i dirigenti. Ciò consente all’esercitazione di rispecchiare il modo in cui gli incidenti reali vengono gestiti a livello dell’intera organizzazione.

D: Perché non basta parlare del processo di recupero?

A: La discussione può mettere in luce i piani, ma solo dei test concreti dimostrano se i sistemi possano effettivamente essere ripristinati in modo corretto e rapido. È necessaria una verifica pratica per confermare la prontezza al ripristino.

D: Cosa determina il successo di un’esercitazione teorica?

A: Un esercizio efficace porta a risultati chiari, a responsabili ben definiti e a scadenze precise per l’adozione delle misure correttive. Se questi elementi mancano, è probabile che l’esercizio non abbia messo sufficientemente alla prova il team.

Chris Bevil is Principal, Global Cyber Resilience & AI, at Commvault.

More related posts


Readiverse-Featured-Image-888-x-500

Ready Is Good. Resilient Is Better.

Read more about Ready Is Good. Resilient Is Better.
Thumbnail_5_MV_Blogs_2025

Recovery Testing: The Missing Piece in Most Cyber Resilience Programs

Read more about Recovery Testing: The Missing Piece in Most Cyber Resilience Programs
Urgent-Need-for-Cyber-Resilience

The Urgent Need for Cyber Resilience

Read more about The Urgent Need for Cyber Resilience
Thumbnail_Blog_Modern-Playbook-2025

Your Modern Playbook for Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Rapid Response and Clean Recovery

Punti di forza

  • Commvault’s data access governance, powered by Satori, unifies visibility, access control, and auditability across structured data, unstructured files, SaaS apps, and AI workloads.
  • Una politica di accesso unica e coerente può disciplinare sia gli utenti umani che i modelli di intelligenza artificiale, contribuendo a ridurre i silos e a limitare l’eccessiva esposizione dei dati sensibili.
  • L’individuazione, la classificazione e la valutazione continua dei rischi contribuiscono a fornire informazioni prioritarie su dove si trovano i dati sensibili e dove il rischio di esposizione è più elevato.
  • Il mascheramento e la redazione dinamici basati su criteri consentono di applicare il principio del privilegio minimo, garantendo l’uso autorizzato dei dati e contribuendo al contempo a proteggere i campi sensibili.
  • I registri di audit centralizzati e quasi in tempo reale offrono una visibilità completa sulle query degli utenti, sui prompt dell’IA e sugli eventi relativi agli accessi regolamentati, contribuendo a garantire la conformità e la responsabilità.

With AI now embedded in every workflow, from copilots and chat assistants to analytics tools, all these endpoints have become ravenous for data to ingest. Commvault’s Le funzionalità di governance dell’accesso ai datidi Commvault, basate sulla tecnologia Satori, sono progettate per soddisfare al meglio questa “fame” di dati dell’intelligenza artificiale, unificando visibilità, controllo degli accessi e tracciabilità in tutto il vostro panorama dei dati.

Una base unificata per la governance dei dati nell’era dell’intelligenza artificiale

Commvault’s data access governance features bring structured databases, unstructured files in SaaS apps, and AI workloads under one governance model, instead of treating them as separate silos. Organizations now can apply a single access policy to both human users and AI models, so that the same rules determine who or what can see sensitive information, regardless of where it lives.

By integrating Satori into the Commvault Centro di comando, these capabilities extend Commvault’s traditional protection into live data and AI usage, not just backups and snapshots. This helps security and data protection teams move from reactive incident response to proactive control over how data is discovered, accessed, and used in real time.

Individuazione, classificazione e valutazione del rischio in tempo reale

Uno dei pilastri fondamentali delle nostre capacità di governance dei dati èl’individuazione e la classificazione unificatedei dati su cloud e SaaS. Man mano che le organizzazioni si collegano ad ambienti quali AWS, Azure, Google Cloud, Snowflake, Databricks e altri, Commvault mappa automaticamente gli archivi di dati e li classifica in modo continuo, indipendentemente dal fatto che si tratti di dati strutturati o non strutturati.A ogni risorsa viene assegnato un punteggio di rischio, che offre ai team una visione gerarchizzata di dove si trovano le informazioni sensibili e dove l’esposizione al rischio è maggiore. Anziché affidarsi a scansioni periodiche, la platform il passo con i movimenti dei dati, i nuovi archivi e le modifiche alla classificazione, aiutando i team a individuare i problemi in anticipo e a concentrarsi innanzitutto sulle aree a più alto rischio.

Accesso con privilegi minimi tramite mascheramento dinamico e oscuramento

Traditional data protection often stops at knowing where sensitive data is; Commvault’s capabilities emphasize controlling how that data is revealed. Using policy-driven masking and redaction, organizations can enforce least-privilege access so that users, services, and AI models only see the specific information they are authorized to see, with sensitive fields anonymized or hidden as needed.

Because the same masking and redaction policies apply across all connected environments, organizations can consistently safeguard access instead of fragmented, application-by-application rules. This helps reduce the risk of data overexposure, where too many people or systems have access to more data than they legitimately need.

Sicurezza e gestione sicura e tempestiva

A standout capability is policy-driven AI security that operates at the prompt and response level. Before data is ever sent to an AI model, Commvault, powered by Satori, can intercept the interaction, detect sensitive fields (such as regulated personal details), and apply inline masking or redaction according to existing data access policies.

Unlike solutions that simply block entire prompts or rely solely on downstream data loss prevention (making security someone else’s concern), this approach allows employees to keep using AI assistants productively while keeping sensitive data under governance. Because redaction occurs before the model processes the data, it also helps prevent sensitive information from influencing or contaminating AI training datasets, protecting both the users and the broader AI environment.

Le tracce di audit centralizzate favoriscono la conformità

The final piece of our Le funzionalità di governance dell’accesso ai dati is una registrazione completa e centralizzata dei log di audit. Every interaction – whether a user query, an AI prompt, or a governed access event – is captured with details such as who accessed what, which policy was applied, and what redactions occurred, in near–real time.

This unified audit visibility spans live data, AI prompts, and access governance events, giving security, IT, and compliance leaders a single authoritative record rather than disparate logs from point tools. For CISOs and CIOs, this means faster compliance reviews and clear proof that governance is not just documented on paper but actively enforced across the environment.

Aiutare le organizzazioni ad adottare l’intelligenza artificiale in modo sicuro

Nel loro insieme, queste nuove funzionalità offrono alle organizzazioni un approccio coerente per governare i dati in un mondo basato sull’IA: visibilità unificata su cloud, SaaS e IA; un’unica politica per utenti e modelli; mascheramento e oscuramento dinamici per un accesso con privilegi minimi; e protezione dei prompt dell’IA conforme alle politiche, supportata da tracciati di audit completi. Il risultato è il passaggio da controlli reattivi a una governance proattiva dell’accesso ai dati, pronta per l’IA, che aiuta i team ad abbracciare l’innovazione dell’IA mantenendo il controllo sulle informazioni più sensibili.

Domande frequenti

Q: What makes Commvault’s approach to AI data governance different from traditional data protection?

A: La protezione dei dati tradizionale si concentra spesso sui backup e sulla risposta agli incidenti dopo che si è verificata una fuga di dati. Commvault estende la governance agli ambienti operativi e alle interazioni basate sull’intelligenza artificiale, consentendo un controllo proattivo su come i dati vengono individuati, consultati e utilizzati in tempo reale. Questo cambiamento aiuta le organizzazioni a gestire il rischio prima che si trasformi in una violazione.

Q: How does l’individuazione e la classificazione unificate improve security?

A: La scoperta e la classificazione continue consentono di mappare ed etichettare automaticamente i dati strutturati e non strutturati presenti su cloud e piattaforme SaaS. Assegnando un punteggio di rischio a ciascuna risorsa, i team ottengono una visione gerarchica dell’esposizione dei dati sensibili. Ciò contribuisce a identificare più rapidamente le aree ad alto rischio e a concentrare meglio gli interventi correttivi.

D: Che cos’è il mascheramento dinamico e perché è importante per i carichi di lavoro basati sull’intelligenza artificiale?

A: Il mascheramento dinamico e la redazione limitano ciò che gli utenti, i servizi e i modelli di IA possono visualizzare in base a criteri predefiniti. I campi sensibili possono essere resi anonimi o nascosti, pur consentendo l’accesso legittimo ai dati rilevanti. Questo approccio favorisce la produttività, contribuendo al contempo a ridurre il rischio di un’eccessiva esposizione.

D: Come funziona la protezione dei prompt dell’IA basata sulle politiche?

A: La sicurezza IA basata sulle politiche intercetta i prompt e le risposte prima che i dati raggiungano il modello di IA. Consente di individuare le informazioni sensibili e di applicare il mascheramento o la redazione in linea secondo le politiche esistenti. Ciò permette ai dipendenti di continuare a utilizzare gli strumenti di IA, garantendo al contempo che i dati soggetti a regolamentazione rimangano sotto controllo e non vengano inclusi nei set di dati di addestramento.

D: In che modo le tracce di audit centralizzate supportano le attività di conformità?

A: La registrazione completa degli audit rileva i dettagli relativi a chi ha consultato quali dati, quali politiche sono state applicate e quali operazioni di oscuramento sono state effettuate. Questa visibilità unificata abbraccia sia i dati in tempo reale che le interazioni basate sull’intelligenza artificiale, fornendo ai responsabili della sicurezza e della conformità una documentazione chiara e attendibile. Ciò consente di effettuare revisioni più rapide e di dimostrare che i controlli di governance vengono attivamente applicati.

D: In che modo queste funzionalità aiutano le organizzazioni ad adottare l’intelligenza artificiale in modo sicuro?

A: By combining unified visibility, consistent policy enforcement, dynamic masking, and complete audit trails, Commvault’s data governance capabilities help give organizations a cohesive framework for governing AI-era data. These controls help enable innovation while helping maintain control over sensitive information. The result is a more confident and safe path to AI adoption.

Nico Guerrera è Senior Technical Marketing Manager presso Commvault.

More related posts


Social_Blog_Satori_GigaOm_Leader_2026_Linkedin

Satori Named Leader in GigaOm’s Data Access Governance Radar Report

Read more about Satori Named Leader in GigaOm’s Data Access Governance Radar Report
Thumbnail_Blog-Conversational-Resilience-2025-Linkedin

Conversational Resilience: The New Way to Manage and Protect Enterprise Data

Read more about Conversational Resilience: The New Way to Manage and Protect Enterprise Data
Thumbnail_Blog_Satori-Acquisition-2025

Commvault Closes Acquisition of Satori, Strengthening Data and AI Security Platform

Read more about Commvault Closes Acquisition of Satori, Strengthening Data and AI Security Platform
Thumbnail_Blog-Data-Rooms-2025-Linkedin

Data Activate: Unlocking the Power of Trusted Data for AI Innovation

Read more about Data Activate: Unlocking the Power of Trusted Data for AI Innovation

Punti di forza

  • L’infrastruttura di identità rappresenta una delle principali superfici di attacco che, se compromessa, può bloccare le operazioni aziendali.
  • Commvault’s vulnerability assessment helps highlight misconfigurations and risky settings through clear exposure indicators and remediation guidance.
  • L’auditing in tempo reale consente ai team di individuare sottili modifiche dannose non appena vengono apportate e di tracciare l’attività degli aggressori in tempo reale.
  • Il rollback con un solo clic può contribuire a ripristinare rapidamente le modifiche non autorizzate, aiutando a ridurre al minimo i tempi di inattività e a limitare la diffusione dell’attacco.

La sicurezza informatica e l’importanza dell’identità

When most people think about cybersecurity, they picture stolen files or encrypted databases. But there’s a layer underneath all of that which, if compromised, makes everything else irrelevant – your infrastruttura identitaria.​

Identity management systems like Active Directory(AD),ID EntraeOkta are the systems that decide who gets to log in, what they can accessewhether your business can function at all. When attackers get in there, users can’t authenticate, applications go darkeoperations grind to a halt. It’s not a data problem at that point, it’s a control problem.​

Recupero automatico delle foreste with clean OS rebuilds helps enable organizations to restore identity systems securely without reintroducing threats. Here’s how.

Know What You’re Vulnerable to Before the Attackers Do

Commvault’s vulnerability assessment gives your AD environment a posture score.  Think of it like a health grade for your directory. Most environments have more exposure than people realizeethis makes that visible.​

Our tool helps surface indicators of exposure (IOEs), which are specific misconfigurations or risky settings that could be exploited. One common example is accounts with passwords set to never expire. Stale, non-rotating credentials are one of the most common ways attackers maintain long-term access to an environment.

Commvault doesn’t just flag the issue, it helps identify which accounts are affected, walks through remediation stepselets you export the list to help simplify scripting the fix.

Catch It While It’s Happening

Knowing your weaknesses is step one. Seeing when someone is actively exploiting them is step two.

Commvault’s identity management auditing helps capture a real-time feed of every change made to identity systems like Active Directory and ID Entra – details like who made the change, when, from whereewhat the values looked like before and after.

Attackers don’t usually blow the doors off; they make subtle, targeted changes. A compromised account might create a backdoor user, quietly add it to domain admins, then link a malicious Group Policy Object (GPO) designed to deploy ransomwareeevery one of those steps shows up in the audit feed.​

Once you spot a suspicious account, filtering can help you instantly pull up every change that account ever made, helping give you the full picture of what the attacker touched.​

Ripara rapidamente i danni

Detection only matters if you can act on it. From the same auditing view, you can roll back a malicious change with a single click, helping restore the environment to its last known good state without jumping between tools or writing a custom script. The aim is to help minimize downtime and limit how far the attack spreads before it is caught.​

Quando succede il peggio: il recupero delle foreste

Sometimes an attack gets througheyou need to rebuild from scratch. AD forest recovery, rebuilding your entire directory environment after a ransomware hit, is notoriously complex, often involving 50 to 100+ individual steps, depending on how many domains and domain controllers you have.​

Commvault helps automate this with orchestrated runbooks that sequence every step: Rebuilding domain controllers in the right order based on their flexible single master operation (FSMO) roles, restoring SYSVOL, verifying metadataere-establishing trust between domains. A topology view of the entire AD forest helps make it visually clear which domain controllers should come back online first.​

The standout piece here is what Commvault calls Recovery del sistema operativo pulito. Instead of restoring potentially compromised virtual machines, it rebuilds domain controllers on brand-new VMs. Restoring an infected machine risks bringing the malware right back with it. Recovering onto fresh infrastructure means you’re not just getting your data back; you’re actually starting clean.​

Un’unica dashboard per l’ambiente on-premises e Cloud

Most organizations today aren’t running purely on-premises or purely in the cloud, they’re hybrid, with AD handling legacy access and ID Entra handling modern cloud-based identities. Commvault’s unified control plane can help cover both from a single console: assessments, auditing, detectionerecovery across both platforms.​

The value is straightforward: fewer tools, less complexityea cleaner story to tell leadership when they ask how infrastruttura identitaria is being protected end to end.​

Identity resilience deserves its own dedicated conversation, separate from making backups and separate from protecting endpoints. The combination of proactive vulnerability scanning, real-time change auditing, fast rollbackeclean forest recovery helps your organization treat your directory infrastructure as a security priority in its own right.

Domande frequenti

Q: Why is infrastruttura identitaria such a critical security focus?

A: I sistemi di gestione delle identità controllano l’autenticazione e l’accesso all’interno di un’organizzazione. Se compromessi, gli aggressori possono bloccare completamente le operazioni, rendendo inutili le altre misure di sicurezza.

D: Cosa sono gli indicatori di esposizione (IOE)?

A: Gli IOE sono configurazioni errate specifiche o impostazioni rischiose negli ambienti di gestione delle identità che gli aggressori possono sfruttare. Individuarli può fornire visibilità sui punti deboli e aiutare i team a risolvere tali problemi.

D: In che modo l’auditing in tempo reale contribuisce a bloccare gli attacchi?

A: Il monitoraggio in tempo reale consente di tenere traccia di ogni modifica apportata ai sistemi di gestione delle identità, indicando chi l’ha effettuata e quali modifiche sono state apportate. Questa visibilità aiuta i team di sicurezza a individuare tempestivamente comportamenti sospetti e a indagare sull’intero ambito di un attacco.

D: È davvero possibile annullare rapidamente le modifiche dannose?

Sì, Commvault consente di annullare direttamente le modifiche non autorizzate dalla stessa interfaccia. Ciò contribuisce a ridurre i tempi di risposta e a ripristinare i sistemi in uno stato sicuro senza ricorrere a script complessi.

D: Cosa rende così difficile il ripristino di una foresta AD?

A: La ricostruzione di una foresta AD comporta numerose fasi interdipendenti, tra cui il ripristino dei controller di dominio e il ristabilimento delle relazioni di fiducia. La complessità aumenta con le dimensioni dell’ambiente.

Q: What is Commvault’s Clean OS Recoveryewhy does it matter?

A: Clean OS Recovery consente di ricostruire i controller di dominio su sistemi nuovi e non compromessi, anziché ripristinare i computer infetti. Questo approccio contribuisce a eliminare il malware residuo e può favorire un ripristino sicuro.

Nico Guerrera è Senior Technical Marketing Manager presso Commvault.

More related posts


Thumbnail_Blog-Okta-Early-Access-2026

Commvault® Extends Identity Resilience to Okta

Read more about Commvault® Extends Identity Resilience to Okta
Thumbnail_Blog-Lateral-Access-2026

Staying Resilient Against Lateral Access Exploits

Read more about Staying Resilient Against Lateral Access Exploits
Thumbnail_Blog-Linkedin 1

Security Best Practices

Read more about Security Best Practices

Punti di forza

  • La gestione del backup e del ripristino secondo il modello Infrastructure as Code (IaC) contribuisce a ridurre le discrepanze di configurazione e ad allineare la protezione dei dati alle moderne pratiche cloud .
  • Il provider Clumio per Terraform consente di definire in modo dichiarativo gli account AWS, le politiche e le regole di protezione, gestendone il controllo delle versioni.
  • La protezione basata su tag è progettata per proteggere automaticamente le risorse esistenti e future, contribuendo a ridurre gli interventi manuali e a garantire una scalabilità efficiente in tutti gli ambienti.
  • La definizione delle politiche di backup in Terraform contribuisce a migliorare la visibilità, la riproducibilità e la governance attraverso flussi di lavoro standard basati sulle pull request.
  • Questo approccio può rivelarsi particolarmente utile per gli ambienti AWS con più account e per le organizzazioni che hanno già adottato Terraform come standard.

Cloud viene sempre più spesso definita come codice. Le istanze EC2, i ruoli di gestione delle identità e degli accessi (IAM), i cloud privati virtuali e i database sono ora ospitati in repository sottoposti a controllo di versione e vengono distribuiti in modo prevedibile tramite IaC. Tuttavia, le politiche di Backup and Recovery sono spesso ancora configurate manualmente nelle console web. Questo divario crea dei rischi. Quando l’infrastruttura è dichiarativa ma la protezione dei dati non lo è, i team rischiano:

  • Deriva della configurazione.
  • Protezione non uniforme tra i vari account.
  • Errori di compilazione.
  • Visibilità limitata su ciò che è effettivamente protetto.

For organizations already using Terraform, backup and recovery should be managed the same way as the rest of the stack – through code.Clumio’s Terraform provider enables AWS data protection to be defined declaratively alongside infrastructure. You can explore the provider and its documentation here: Clumio by Commvault.In this post, we’ll walk through how to automate AWS workload protection using Terraform and Clumio by Commvault – and why that approach scales more effectively for modern cloud teams.

Collegamento degli account AWS.

Configurazione separata della protezione su più servizi AWS.

  • Creazione di criteri di backup.
  • Definizione delle regole di protezione.
  • Assegnazione manuale delle risorse.
  • Ripetere tale procedura per ogni account o ambiente.
  • Anche in contesti ben gestiti, ciò comporta:
  • Configurazione manuale ripetitiva.

Applicazione incoerente delle politiche.

  • Protezione ritardata per le risorse appena create.
  • Controllo delle versioni limitato.
  • Terraform contribuisce già a risolvere questo problema per l’infrastruttura. Il provider Clumio per Terraform estende tale modello alla protezione dei dati.
  • Da zero alla protezione: l’uso di quattro file

È possibile configurare la protezione di più servizi AWS utilizzando un numero limitato di file Terraform, anziché una sequenza di operazioni manuali nell’interfaccia utente.

From Zero to Protected – Using Four Files

Definizione dei fornitori (AWS + Clumio)

Il primo passo consiste nel dichiarare i provider. Terraform deve sapere che:

  1. Definizione dei fornitori (AWS + Clumio)

Stai utilizzando il provider Clumio.

  • You’re using AWS.
  • You’re using the Clumio provider.

“Introduzione“..

  1. Collegare gli account AWS a Clumio

Next, the Clumio module establishes the connection between AWS and Clumio. This abstracts away the IAM role configuration required for data protection. Instead of manually configuring roles and permissions, the module handles the integration in a repeatable way.The provider is publicly availablesu GitHub.This means your integration is defined in code, version-controlled and reproducible across environments.

  1. Definire le politiche di backup come codice

La definizione delle politiche di backup è il campo in cui l’IaC dà il meglio di sé. In una configurazione basata su Terraform:

  • È possibile impostare diversi obiettivi di punto di ripristino (RPO) per i diversi tipi di risorse.
  • All’interno della stessa politica è possibile definire più livelli di conservazione (ad esempio, conservazione a breve e a lungo termine).
  • La stessa politica può essere applicata automaticamente in base a condizioni prestabilite.

Instead of navigating multiple consoles, a single Terraform configuration defines frequency, retention, and resource scope. That policy is reusable and reviewable like any other infrastructure configuration.

  1. Protezione automatica basata su tag

Uno degli elementi più scalabili di questo approccio è la protezione basata sui tag. È possibile configurare una regola di protezione in modo che protegga automaticamente qualsiasi risorsa contrassegnata con una specifica coppia chiave/valore. Ad esempio: created_by = demo_script Ciò significa che:

  • Le risorse esistenti che corrispondono al tag sono protette.
  • Le risorse future con quel tag vengono incluse automaticamente.
  • Non è necessario alcun intervento manuale.

For S3 specifically, protection groups also use tags to manage hundreds of buckets as a single logical unit, allowing centralized policy changes at scale. This helps reduce configuration drift.

Applicazione della configurazione

Once defined, Terraform initializes the working directory, previews planned changes, and applies the configuration. Terraform is designed to respect dependencies between resources, creating them in the correct order.The configuration helps connect AWS accounts, activate policies, enforce protection rules, and protect tagged resources. And critically – the entire protection strategy exists in version-controlled code.

Perché questo è importante per Cloud

For teams operating with IaC principles, backup configuration should follow the same discipline as infrastructure provisioning.Defining backup in Terraform provides several practical benefits:

  • Controllo delle versioni: le politiche di backup sono definite nel codice e possono essere riviste, sottoposte a controllo delle versioni e approvate tramite flussi di lavoro standard basati su pull request.
  • Riproducibilità: la stessa configurazione può essere implementata in modo coerente negli account di sviluppo, staging e produzione.
  • Deriva ridotta: le configurazioni Terraform possono essere riapplicate per garantire il rispetto dello stato dichiarato, contribuendo a riportare le modifiche manuali o fuori banda in linea con la configurazione prevista.
  • Chiara visibilità: la logica di protezione è visibile nel codice anziché nascosta nelle impostazioni dell’interfaccia utente.
  • Separazione tra configurazione e interfaccia: lo stato di sicurezza viene definito in modo dichiarativo, indipendentemente dallo stato della console.

Quando questo approccio è opportuno

L’automazione del backup con Terraform è particolarmente utile per:

  • Ambienti AWS con più account.
  • Settori regolamentati che richiedono una configurazione verificabile.
  • Platform che gestiscono infrastrutture condivise.
  • Organizzazioni che hanno già adottato Terraform come standard.

If your infrastructure is defined as code, your data protection strategy should be too.

Come iniziare

Per approfondire questo approccio:

È inoltre possibile valutare Clumio tramiteMercato AWS.

Domande frequenti

D: Perché le politiche di backup dovrebbero essere gestite come codice?

R: Quando l’infrastruttura è definita come codice, ma le politiche di backup vengono configurate manualmente, possono emergere lacune e incongruenze. Gestire il backup come codice aiuta ad allineare la protezione ai flussi di lavoro di implementazione, a ridurre gli errori manuali e a fornire una visibilità, soggetta al controllo delle versioni, sulla propria strategia di protezione dei dati.

D: Quali funzionalità offre il provider Clumio per Terraform?

A: The Clumio Terraform provider allows AWS data protection resources – such as account connections, backup policies, and protection rules – to be defined declaratively. This helps enable teams to manage backup configurations alongside infrastructure in the same Terraform workflow.

D: In che modo la protezione basata sui tag migliora la scalabilità?

A: La protezione basata su tag è progettata per applicare automaticamente le politiche a qualsiasi risorsa che corrisponda a una coppia chiave/valore specificata. Ciò contribuisce a proteggere le risorse esistenti e future senza necessità di assegnazioni manuali, facilitando la gestione della protezione su larga scala tra account e servizi.

D: In che modo Terraform contribuisce a ridurre lo scostamento di configurazione negli ambienti di backup?

A: Terraform mantiene uno stato dichiarato per l’infrastruttura e le politiche di protezione. La riapplicazione delle configurazioni contribuisce a riportare le modifiche manuali o fuori banda in linea con lo stato previsto, contribuendo a migliorare la coerenza tra i vari ambienti.

D: In quali casi è più opportuno automatizzare il backup con Terraform?

A: Questo approccio risulta particolarmente vantaggioso negli ambienti AWS con più account, nei settori regolamentati che richiedono configurazioni verificabili, platform che gestiscono servizi condivisi e nelle organizzazioni che già utilizzano Terraform come standard per l’IaC.

D: In che modo i team possono iniziare a utilizzare la protezione dei dati AWS basata su Terraform?

A: I gruppi possono iniziare esaminando ildocumentazione relativa al provider Clumio Terraform, esaminando ilprovider’s GitHub source codee guardando la demo “Quick Start”. Un altro passo pratico da compiere è valutare Clumio tramiteMercato AWS.

Lawrence Chang è Direttore tecnico di Clumio e Vir Choksiè responsabile principale del marketing di prodotto presso Commvault.

More related posts


Thumbnail_Blog-GoogleWorkspace-2026

How the Move to Clumio Delivered 66.7% Savings on AWS Backups

Read more about How the Move to Clumio Delivered 66.7% Savings on AWS Backups
Thumbnail_Blog_AWS-Marketplace-AI

Commvault Featured in New AI Agent Solutions in AWS Marketplace

Read more about Commvault Featured in New AI Agent Solutions in AWS Marketplace
Man-and-woman-working-on-laptops-profile-Crocus-Thumbnail

Protecting Your Amazon S3 Data with Clumio: A Comprehensive Solution

Read more about Protecting Your Amazon S3 Data with Clumio: A Comprehensive Solution
Zz05MThhZTc3NmU0MTQxMWVmYTYwZWJlYTg2ZTllNjQ5Yw

A Blueprint for Effective Cloud Recovery

Read more about A Blueprint for Effective Cloud Recovery

Clumio

Read more about Clumio

Every organization that has ever failed a recovery – and there are more than anyone publicly acknowledges – had one thing in common: They believed they could recover before they tried.

The belief came from somewhere. A completed tabletop exercise. A backup system that showed green. An annual disaster recovery test that passed. All of it documented. All of it, at some point, accurate. None of it current when the incident actually hit.

This is the confidence gap. And it is the gap that continuous recovery validation is designed to close.

What ‘Testing’ Actually Means in Most Organizations

Se si chiede alla maggior parte dei responsabili della sicurezza o dell’IT con quale frequenza testino la propria capacità di ripristino, la risposta è in genere “una volta all’anno”, a volte “due volte all’anno”. Il test consiste nel ripristinare un sottoinsieme di sistemi dal backup in un ambiente di prova, verificare che si avviino correttamente e redigere un rapporto. Talvolta, parallelamente, viene condotta anche un’esercitazione teorica. Ciò che questo tipo di test non fa: verificare che i dati di backup siano privi di malware; confermare che la sequenza di ripristino funzioni per i servizi interdipendenti. Non verifica la Recovery delle identità, essenziale quando sono state proprio le credenziali compromesse a consentire l’attacco. Non conferma che il team incaricato di eseguire effettivamente la Recovery conosca le procedure operative attuali. Né produce prove sufficientemente significative da dimostrare a un’autorità di regolamentazione, a un revisore o a un consiglio di amministrazione che la capacità di Recovery sia reale e aggiornata. In breve, convalida un momento specifico. Le operazioni di resilienza (ResOps) richiedono che la convalida sia uno stato continuo.

Il modello di convalida continua

Continuous recovery validation is not a single test run more frequently. It is a set of integrated practices that produce ongoing, evidence-based proof of recoverability across critical services.

Automated backup integrity scanning. Every backup, continuously evaluated for anomalies, encryption patterns, and malware signatures. Not at restore time – before restore time. The goal is to know whether your recovery points are clean before you need them, not during an incident.

Scheduled Cleanroom Recovery drills. Bi-annual at minimum, restoring from immutable backup points into an isolated Cleanroom Recovery environment – not production, not a production-adjacent test environment, but a genuinely isolated space where forensic analysis can happen without risk of reinfection. These drills produce documented evidence of recoverability against defined impact tolerances.

Identity recovery validation. With l’uso improprio delle credenziali: il vettore di violazione più comune, Active Directory and Entra ID recovery must be tested alongside data recovery. Organizations that restore systems without restoring a verified-clean identity layer may find attackers re-enter through the same door.

Service Resilience Indicator (SRI) dashboards. SRIs – continuous signals drawn from backup telemetry, dependency mapping, and test results – that give CISOs, CIOs, and boards a live view of recoverability posture. Not a point-in-time report. An ongoing operational signal.

Each of these practices feeds what Deloitte and Commvault call the resilience backlog: a continuously updated, prioritized list of gaps identified through testing and tracked to resolution. It is the mechanism by which validation drives improvement rather than just producing reports.

Cosa si intende per “tempo medio necessario per la pulizia delle modifiche di ripristino”

Traditional recovery metrics – recovery time objective (RTO) and recovery point objective (RPO) – measure speed and data recency. They say nothing about whether the data being restored can be trusted. Mean Time to Clean Recovery (MTCR) fills that gap: It measures the time required to restore data that is verifiably clean, not just technically available.

MTCR matters because in a ransomware incident, the adversary’s goal is often to corrupt recovery options, not just encrypt production systems. An organization that restores quickly but restores from a compromised backup has not recovered. It has re-infected itself.

Building MTCR into your resilience measurement framework, alongside RTO and RPO, changes what you optimize for and what you report to the board. Speed plus recency plus integrity: that is the complete picture of recovery readiness.

Una resilienza che si può dimostrare

The organizations that navigate cyber disruptions with the least damage share one characteristic: They treat recovery capability as something to be continuously demonstrated, not periodically asserted. They know their MTCR. Their SRIs are current. Their cleanroom recovery has been tested in the last 90 days.

That posture is not the result of better technology alone. It is the result of an operating discipline – ResOps – that makes resilience continuous, measurable, and governable. Commvault’s platform provides the technical foundation: clean recovery, automated validation, and the unified visibility across data, identity, and services that ResOps requires at scale.

For the organizational side of that equation – how to define impact tolerances, align executive leadership, and build the governance structure that sustains the discipline – see the Deloitte companion blog, La discussione sulla resilienza che il vostro consiglio di amministrazione non sta ancora affrontando. Per conoscere il quadro completo di ResOps, compresi i sei ambiti di ResOps e il modello di misurazione che collega la recuperabilità tecnica alla responsabilità a livello di consiglio di amministrazione, si prega di consultare il white paper congiunto:Dalla minima funzionalità alla resilienza operativa: il ResOps nella pratica.Bill O’Connell è responsabile della sicurezza presso Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Cloud dovuto offrirci flessibilità, oltre a:

  • Servizi di eccellenza.
  • Innovazione Cloud.
  • Nessuna dipendenza da un unico fornitore.

But when a cyber incident hits, that flexibility often becomes complexity.
In this episode of STRIVE, I sat down with Senior Director of Product Management Akshay Joshi – whose career spans IBM, AWS, Microsoft, Clumio, and now Commvault – to unpack one uncomfortable truth: Most organizations think they’re ready for multi-cloud recovery.
Until they’re not. Watch the episodio.

.

  • Backup at the service level doesn’t equal recovery at the application level. Protecting individual data sources is not the same as restoring a synchronized application ecosystem.
  • Recovery complexity multiplies across clouds. Different recovery points, different accounts, different admin teams – each adds friction when time matters most.
  • Native hyperscaler tools are necessary – but not sufficient. They protect within their own cloud but don’t orchestrate across clouds.
  • Isolation is the first domino in a cyber event. The larger the environment’s aperture, the harder it is to contain impact.
  • Resilience must be designed in – not retrofitted later. Dependency mapping and recovery planning should begin at application design, not after deployment.
  • AI-enabled automation adds power – and new risk. Agentic workflows require tight permission controls and governance discipline.

The Gap Between “On Paper” and Reality

On paper, recovery seems simple: When do you recover to? What do you recover? Where do you recover it?

But, as Akshay explains, each of those questions fractures in a multi-cloud world. Different services may have different recovery points. Some microservices may be impacted while others aren’t. Recovery may require re-architecting if restored cross-regionally or cross-account.
What looks straightforward in documentation becomes deeply complex in execution. And when ransomware hits, teams don’t calmly reference playbooks – they scramble.

Il primo domino: l’isolamento

Each threat vector expands proportionally with environmental complexity. Multi-cloud doesn’t just diversify infrastructure – it expands operational aperture.

Backup a livello di servizio vs. Ripristino a livello di applicazione

Here’s where most organizations get caught.
They back up:

  • Dati di Azure con Azure Backup
  • Dati AWS con AWS Backup
  • Cloud di Google Cloud con uno strumento separato

Individually, each service may be protected. Collectively, the application may not be recoverable in a synchronized state.
Native tools don’t communicate across clouds. They aren’t inherently multi-cloud in orchestration. They aren’t tuned to optimize recovery time objective (RTO) or recovery point objective (RPO) at scale for cross-cloud architectures.
And when recovery depends on aligning multiple data sources across hyperscalers, orchestration becomes the difference between hours and days. This is exactly why unified recovery strategies exist – not to replace hyperscalers, but to coordinate them.

Dependency Mapping Isn’t Optional Anymore

We’ve been talking about application dependency mapping for more than a decade. But in a multi-cloud world, it’s no longer a “nice to have.” Applications now span multiple hyperscalers, multiple DevOps teams, multiple admin domains, and multiple vendor backup tools.
Fragmented ownership slows recovery. Vendor fragmentation complicates orchestration. Operational silos create delays at the worst possible time. Resilience must be operationalized from the beginning – not bolted on after deployment.

Anteprima: PerchéCloud fallisce senza una mappatura delle dipendenze

In this moment from the STRIVE conversation, Akshay explains why operationalizing resilience at the architecture stage is critical for surviving real-world cyber events.

Designing for Recovery – Not Just Protection

One of the most powerful points in this episode: Modern applications should be designed not only around performance and scale – but around recoverability. That means:

  • Prestare la stessa attenzione all’RTO quanto all’RPO.
  • Progettare tenendo contocloud .
  • Migliorare la visibilità ove possibile.
  • Ridurre la frammentazione dei fornitori e delle attività amministrative.
  • Verifica del ripristino in diversi ambienti.

Recovery speed impacts revenue. Recovery clarity impacts reputation. Downtime impacts customer trust. Multi-cloud innovation must be matched by multi-cloud recovery discipline.

Il livello di intelligenza artificiale e automazione

Nessuna discussione è completa senza affrontare il tema dell’IA. I flussi di lavoro basati su agenti sono sempre più integrati nelle piattaforme SaaS aziendali. Ma l’automazione introduce nuove considerazioni:

  • Di quali autorizzazioni dispongono gli agenti?
  • Con quale frequenza vengono eseguiti i backup?
  • Quali sono le implicazioni in termini di costi derivanti dalle decisioni relative all’automazione?
  • Gli agenti vengono considerati come identità con accesso regolamentato?

AI can accelerate resilience – but without guardrails, it also can amplify risk. The key is controlled delegation.

Perché abbiamo avuto questa conversazione su STRIVE

STRIVE isn’t about repeating what everyone already knows. It’s about confronting the gaps that surface during real-world cyber events. Multi-cloud adoption isn’t slowing down. But unless recovery strategies evolve alongside architecture, complexity will outpace preparedness.
That’s why this discussion matters. And that’s why we brought Akshay in – someone who’s operated across hyperscalers and understands both their power and their limitations.

Guarda l’episodio completo

In the full STRIVE episode, you’ll discover:

  • Il vero divario tra il backup a livello di servizio e il ripristino a livello di applicazione.
  • Perché l’isolamento è il primo tassello nella catena degli attacchi ransomware.
  • In che modo la frammentazione dei fornitori complica l’orchestrazione.
  • Su cosa devono trovare un accordo i CISO e i responsabili DevOps.
  • Come l’intelligenza artificiale cambia l’equazione della resilienza.

Guardalo subito.
If you operate across AWS, Azure, or Google Cloud – this conversation is essential.

Domande frequenti

Q: Why isn’t native hyperscaler backup enough?

A: Native tools protect data within a specific cloud but don’t orchestrate recovery across clouds. Multi-cloud applications require coordinated restoration across services and providers.

D: Qual è la principale lacuna nelcloud ?

R: Il divario tra il modo in cui vengono eseguiti i backup (per singolo servizio) e il modo in cui deve avvenire il ripristino (a livello di applicazione).

Q: What does “environmental aperture” mean?

R: Si riferisce alla varietà di account, cloud, identità e servizi presenti in un ambiente. Man mano che tale varietà aumenta, il rischio e la complessità crescono in modo proporzionale.

D: Perché la mappatura delle dipendenze è fondamentale?

R: Le applicazioni si estendono ormai su più cloud e team. Senza una mappatura delle dipendenze dei servizi, la sequenza di ripristino diventa una questione di congetture.

D: In che modo l’intelligenza artificiale influisce sul ripristino di emergenza?

R: I flussi di lavoro basati sull’intelligenza artificiale possono aiutare ad automatizzare le decisioni relative al backup e al ripristino, ma richiedono rigorosi controlli degli accessi, una gestione dei costi e un’adeguata supervisione.

D: Da dove dovrebbero iniziare le organizzazioni per migliorarecloud ?

A: Inizia valutando:

    • Allineamento del ripristino a livello di applicazione.
    • Opportunità di consolidamento dei fornitori.
    • Sincronizzazione tra i team.
    • Strategia di isolamento in caso di incidenti.
    • Frequenzacloud .

Chris Mierzwa è direttore senior del reparto Portfolio Marketing presso Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza

  • Commvault Edge Docking for SaaS trasformare l’implementazione edge in un processo centralizzato e cloud, gestito da un’unica console. Commvault Edge era precedentemente noto come HyperScale Edge.
  • La configurazione automatizzata e il provisioning basato su API consentono di ridurre i tempi di implementazione a pochi minuti in tutti i siti distribuiti.
  • I flussi di lavoro standardizzati contribuiscono a migliorare l’uniformità, la sicurezza dei dati e la scalabilità negli ambienti periferici.
  • La connettività SaaS continua consente di effettuare aggiornamenti, interventi di manutenzione e ottimizzazioni in modo continuativo senza bisogno di interventi manuali.
  • Le funzionalità di sicurezza integrate, come i backup immutabili e l’architettura zero-trust, contribuiscono a rafforzare la protezione contro le minacce in continua evoluzione.

L’implementazione della protezione dei dati in edge non dovrebbe richiedere una configurazione manuale in ogni sito. ConCommvault Edge per SaaS, Commvault trasforma l’implementazione in edge in un’esperienza semplificata e basata sul cloud. Combina la potenza di Commvault Edge con il controllo centralizzato del piano di gestione SaaS.

Ridurre al minimo la complessità dell’implementazione perimetrale

Gli ambienti edge stanno vivendo una forte espansione.Secondo le previsioni di IDC, la spesa IT dedicata all’edge raggiungerà i 380 miliardi di dollari entro il 2028. Organizations are pushing compute closer to data – retail stores, branch offices, manufacturing plants, healthcare facilities – each generating and storing critical information that must be protected.

The current edge-setup process is resource-intensive, requiring physical access and time-consuming configuration steps. This extends deployment timelines and increases operational costs when scaling to multiple sites. What should take minutes can stretch into an extended period of time and potential complexity. And while organizations struggle with deployment logistics, critical edge data remains unprotected or inconsistently backed up across distributed locations.

The threat landscape doesn’t wait. Verizon’s documents a surge in breaches exploiting edge devices – and every unprotected site represents a potential entry point for ransomware, data theft, and business disruption.

SaaS per Commvault Edge

Commvault sta contribuendo a trasformare l’implementazione per l’edge conil SaaS Docking per Commvault Edge (formerly HyperScale Edge) – a capability that brings cloud-native speed and simplicity to on-premises protection. From the Command Center, IT teams can configure, deploy, and manage every Commvault Edge system through a single SaaS console. It’s a single pane of glass that helps manage hybrid and cloud-native workloads across every site, device, and workload.

New systems follow a guided, standardized setup workflow that enables protected and consistent configuration from day one. Once powered on, each system automatically connects to Commvault SaaS, validates its configuration, registers with the platform, and begins installation. This helps minimize on-device setup and reduce the operational effort required to deploy at scale.

For larger rollouts, Commvault API-driven automation helps enable rapid onboarding of multiple systems simultaneously, supporting repeatable deployment across sites and regions.

Once systems are deployed, the global Command Center provides unified management across all locations. Each Commvault Edge system remains connected to Commvault SaaS for regular updates, maintenance, and optimization. From this single platform, you can deploy, patch, scale, and maintain every system with confidence. Deploy faster. Manage smarter. Protect data everywhere.

Pensato per crescere, progettato per la semplicità

Commvault Edge Docking for SaaS is designed to deliver measurable operational advantages for IT and security leaders:

Accelerated time to value: Deploy new edge systems faster without manual, site-by-site provisioning.

Centralized visibility and governance: Manage configuration, monitor health, deploy updates, and scale infrastructure from a single SaaS management plane.

Reduced operational overhead: Limit the need for on-device configuration and streamline rollout processes, helping free IT resources for higher-value initiatives.

Consistent, rapid deployment: Standardized workflows help reduce configuration drift, deliver consistent data security posture and policy enforcement, and improve reliability across distributed environments.

Data security by design: Every system runs on , Commvault’s hardened Linux-native foundation. It’s a system that helps enable recovery that’s not just fast, but safe, with immutable local backups, multi-layer ransomware protection, and zero-trust architecture.

Perché è importante

Traditional edge deployments stretch across weeks or months when deploying at scale. Commvault Edge Docking for SaaS reinforces our commitment to delivering hybrid data protection with the speed and simplicity of SaaS, helping reduce operational costs, eliminate deployment bottlenecks, and achieve faster time to value.

But speed isn’t the only benefit. Consistency also matters. When every site deploys with the same protected baseline, compliance becomes more manageable. Automatic rollout of updates helps security posture stays current. And when recovery workflows are designed to work the same way everywhere, teams can respond confidently under pressure.

This is what unified resilience looks like at scale on the edge: Protection that deploys fast, is simple to manage, and helps provide reliable recovery across hundreds or thousands of distributed sites.

Vederlo in azione

Sei pronto a modernizzare la tua strategia di implementazione edge? Per saperne di più, visita la nostra pagina dedicataCommvault Edgee prenota una demo per vedere Commvault Edge Docking for SaaS azione, oppure contatta il tuo rappresentante Commvault per scoprire come SaaS possa trasformare la tua strategia di resilienza per l’edge.

Domande frequenti

D: Che cos’è Commvault Edge Docking for SaaS?

R: Si tratta di una funzionalità di Commvault che consente alle organizzazioni di implementare e gestire i sistemi Commvault Edge tramite un piano SaaS centralizzato. Questo approccio contribuisce a semplificare la configurazione, l’implementazione e le operazioni quotidiane in ambienti distribuiti.

D: In che modo questa soluzione riduce la complessità dell’implementazione?

R: Grazie all’utilizzo di flussi di lavoro automatizzati e a un controllo centralizzato, elimina la necessità di una configurazione manuale sito per sito. I sistemi sono in grado di configurarsi autonomamente e di connettersi allaplatform SaaS , contribuendo a ridurre i tempi e lo sforzo necessari per l’installazione.

D: È possibile estenderlo a più sedi?

R: Sì, l’automazione basata su API consente di integrare rapidamente più sistemi contemporaneamente. Ciò la rende la soluzione ideale per le organizzazioni che gestiscono centinaia o migliaia di siti periferici.

D: Quali funzioni di sicurezza sono incluse?

A: The solution runs on VaultOS™, which includes immutable backups, multi-layer ransomware protection, and a zero-trust architecture. These features help provide stronger, more resilient data protection at the edge.

D: In che modo la gestione centralizzata apporta vantaggi ai team IT?

R: I team IT dispongono di un’unica interfaccia per monitorare, aggiornare e gestire tutti i sistemi periferici. Ciò contribuisce a migliorare la visibilità, ridurre i costi operativi e garantire l’uniformità delle politiche in tutti gli ambienti.

D: Perché è importante per gli ambienti edge moderni?

R: Con la diffusione dell’edge computing, i metodi di implementazione tradizionali risultano troppo lenti e richiedono un impiego eccessivo di risorse. Questa soluzione consente un’implementazione rapida, una sicurezza dei dati costante e un ripristino affidabile, aiutando le organizzazioni a stare al passo con la crescita e i rischi.

Justin Wolf è Senior Product Manager e Chad Bersche è responsabile principale di prodotto presso Commvault.


Blog correlati

More related posts


Thumbnail_Blog_HPE-Active-Peer-Persistence-2024-_1_

A Powerful Partnership for the Future of Data Resilience

Read more about A Powerful Partnership for the Future of Data Resilience
Thumbnail_Blog_Commvault-Cloud-2025-Linkedin

Elevate Your Cyber Resilience with Commvault Cloud Enhancements

Read more about Elevate Your Cyber Resilience with Commvault Cloud Enhancements

Artificial intelligence is redefining what’s possible for modern enterprises: accelerating innovation, sharpening decision-making, and unlocking new efficiencies at scale. Behind every AI-driven insight lies a physical reality—one powered by energy, infrastructure, and data.

As AI adoption grows, so does the need to efficiently manage and protect data at scale.

The future of AI will not be defined by intelligence alone, but by how responsibly that intelligence is built and sustained.

Tre fattori chiave dell’impatto ambientale

The environmental impact of AI is rooted in the compute infrastructure that powers it. Training and running AI models requires high-performance systems that consume electricity. But compute intensity is only part of the story.

AI depends on vast amounts of data—stored, moved, and processed across systems, each contributing to resource use.

All of this is supported by data centers, where servers must be powered and cooled. Cooling systems can represent a meaningful portion of energy use, making data infrastructure design a critical factor in AI sustainability.

Finally, the environmental impact of AI is influenced by how electricity is generated: the same workload can result in very different carbon emissions depending on the energy source.

Frenare l’inefficienza, non l’innovazione

L’intelligenza artificiale sta crescendo rapidamente, poiché le organizzazioni la implementano in tutte le funzioni, generano una maggiore quantità di dati e ampliano le infrastrutture per stare al passo con questa evoluzione. Spesso passa inosservata un’inefficienza fondamentale: metà dei dati aziendali non viene mai consultata dopo essere stata archiviata.1Companies pay to store it without realizing value from it. This is where the environmental footprint of AI can expand—not through innovation, but through inefficiency.

Addressing this starts with better visibility and control over data.

Dati più intelligenti: una potente leva per la sostenibilità

Poiché l’intelligenza artificiale si avvale di grandi insiemi di dati, le organizzazioni possono contribuire a ridurre l’impatto ambientale correggendo le pratiche inefficienti nella gestione dei dati che generano carichi di lavoro superflui. Le soluzioni Commvault offrono diverse funzionalità che aiutano le aziende a gestire e sfruttare i dati in modo efficiente:

  • Deduplication to remove redundant data
  • Tiering to align storage and processing with access needs
  • Compression to reduce storage requirements

Una gestione consapevole dei dati contribuisce a migliorare l’efficienza e a ridurre il consumo di risorse.

Sostenibilità e resilienza: due facce della stessa strategia

Data environments filled with redundant and unorganized data are not only energy-intensive, they are also harder to secure, govern, and recover. Complexity increases risk and complicates business continuity plans.

By helping organizations manage, protect, and leverage their data, Commvault supports systems that are both resilient and sustainable. Smarter data management can help reduce waste, improve efficiency, and strengthen cyber resilience.

Il percorso da seguire

Il futuro dell’intelligenza artificiale sarà determinato dalle scelte che le organizzazioni compiono oggi. I leader in questo settore:

  • Treat data as a strategic asset—not just a growing volume
  • Progettare sistemi di intelligenza artificiale tenendo conto dell’efficienza e della gestione del ciclo di vita
  • Integrare la resilienza in ogni fase delle loro attività

With smarter data management, optimized infrastructure, and responsible design, organizations can reduce the environmental impact of AI—while unlocking its full potential.

Less waste. More resilience.


1Lo stato dei dati oscuri

Aakanksha Kashyap is ESG Specialist at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza:

  • Gli attacchi informatici prendono sempre più di mira sia gli ambienti di produzione che quelli di backup, rendendo indispensabile un ripristino pulito e verificabile.
  • Il rilevamento integrato di anomalie e minacce rafforza cyber resilience i dati compromessi, verificando i punti di ripristino affidabili e accelerando il ripristino.
  • Se integrate nei flussi di lavoro relativi alla protezione dei dati, le funzionalità di rilevamento delle anomalie e delle minacce possono contribuire a fornire le prove necessarie per garantire un ripristino rapido, sicuro e affidabile.

Perché la resilienza informatica dipende dal rilevamento integrato di anomalie e minacce

Anomaly detection identifies unusual behavior in backup data that may indicate compromise. Threat detection identifies known malicious activity using signatures, heuristic analysis, and scanning techniques. Together, they help validate recovery points and enable clean data recovery.

For years, security leaders focused on preventing breaches. In today’s era of persistent attacks and AI-driven threats, organizations increasingly assume compromise and design systems that can withstand disruption and recover safely when it occurs.

Modern adversaries don’t always hide their presence – they reveal it when it serves their objective. Attackers try to infiltrate environments quietly, observe systems over time, and position themselves inside critical infrastructure. The moment an attack becomes visible is rarely the moment it begins; it is the moment the attacker chooses to act.

By then, compromised data may already be woven into backup copies. Integrated anomaly and threat detection can help organizations identify compromised backup data, validate clean recovery points, and assist recovery after a cyberattack.

For security and IT teams, the challenge is no longer simply detecting an attack but predicting and managing an attacker’s possible impact. Understanding what was affected, what remains trustworthy, and how the organization can recover safely without escalating business disruption is the solution.

This is why cyber resilience benefits tremendously from integrated anomaly and threat detection. When detection capabilities are embedded into data protection and recovery workflows, they help provide the shared intelligence that teams need to identify compromised data, validate trusted recovery points, and guide response decisions with evidence rather than guesswork.

This approach aligns with the emerging ResOps™ operating modeldi nuova concezione, in cui i team di sicurezza, IT e ripristino operano sulla base di una visione d’insieme condivisa e di percorsi di ripristino convalidati per rispondere congiuntamente agli incidenti.

La nuova realtà: la ripresa richiede prove concrete, non supposizioni

Traditional threat detection tools focus on spotting threats along the perimeter. But once attackers are inside, visibility can become fragmented and determining which systems and data have been affected becomes a challenge.

Further, attackers increasingly target backup environments specifically to undermine recovery. And the moment organizations cannot confidently prove that backups remain untouched, suspicion becomes unavoidable. The result is uncertainty. Restore quickly and risk reinfection? Or delay recovery while investigating which copies remain trustworthy? IT teams are forced to guess which data is safe while downtime accumulates.

By building intelligence directly into data protection workflows, anomaly and threat detection helps transform recovery from a reactive guess into a disciplined, evidence-driven process. These capabilities can help organizations pinpoint tampered copies, validate data cleanliness, and assemble the most recent uncompromised recovery points – helping you accelerate cyber recovery and reduce operational impact.

Rilevamento delle anomalie: il tuo primo segnale di ciò che non conosci

Anomaly detection acts as a sentinel, guarding your protected data integrity. It establishes a baseline of normal behavior – file sizes, growth patterns, deduplication changes, access attempts – and alerts teams when something deviates from that norm. These deviations can surface signs of silent tampering long before malware signatures do. In an era of novel and polymorphic threats, anomaly detection helps offer what static tools can’t: visibility into the unexpected.

Rilevamento delle minacce: difesa mirata contro attività dannose note

While anomalies reveal what’s unusual, threat detection exposes what is malicious. By scanning protected data directly for ransomware, malware signatures, encryption patterns, and custom indicators of compromise (IoCs), threat detection helps validate that the data you protect is not already compromised.

Perché è importante un approccio combinato

Né il rilevamento delle anomalie né quello delle minacce, da soli, forniscono un quadro completo della situazione. Insieme, costituiscono una strategia di difesa a più livelli: il rilevamento delle anomalie può evidenziare segnali sospetti, mentre quello delle minacce può approfondire l’analisi per verificare l’esistenza di intenzioni malevole. Questa combinazione aiuta le organizzazioni a distinguere le anomalie innocue dalle vere e proprie violazioni e a disporre di dati affidabili e convalidati per un ripristino rapido.

Meeting Today’s Challenges with Commvault® Cloud

Gli hacker prendono sempre più di mira gli ambienti di backup e il malware nascosto nei dati di backup può aumentare il rischio di reinfezione durante il ripristino. Le organizzazioni hanno bisogno di una verifica basata sui dati per garantire un ripristino sicuro e affidabile.Commvault Cloud addresses this by combining data protection workflows with anomaly detection, threat intelligence, AI-enabled analytics, and isolated clean instances. With anomaly and threat insights applied before, during, and after backup operations, Commvault can help empower organizations to recover faster, cleaner, and confidently.

Read the full white paper, “Can You Prove You’re Recoverable Right Now?”.

Domande frequenti

Q: What is anomaly detection in data protection?

A: Anomaly detection identifies unusual behaviors – such as unexpected backup size changes or abnormal file activity – that may signal tampering, ransomware, or emerging threats within protected data.

Q: Why do CISOs need threat detection in their backup workflows?

A: Backup environments are now prime attacker targets. Threat detection helps prevent organizations from storing or restoring compromised data, which helps reduce reinfection risk and improve chances for clean recovery.

Q: How does Commvault help enable clean data recovery?

A: Commvault uses AI-assisted threat scanning, encryption detection, custom IoC matching, and cyber deception to help validate backup integrity and assemble the most recent uncompromised data for rapid recovery.

Q: Why combine anomaly and threat detection?

A: Anomalies identify the unknown; threat detection validates the known. Together, they provide comprehensive visibility into suspicious activity, helping enable faster investigation and more confident data recovery.

Elenco di Paulineè responsabile del marketing di prodotto presso Commvault

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience