Skip to content

Punti di forza

  • Advanced AI models like Claude Mythos Preview could dramatically accelerate vulnerability discovery, reshaping the cybersecurity landscape.
  • Progetto Glasswing highlights growing concerns about managing AI-enabled security risks at scale.
  • ResOps helps shift organizations from reactive defense to proactive resilience and recovery.
  • Cybersecurity tools focus heavily on prevention, while recovery capabilities remain underdeveloped.
  • In an AI-enabled world, the ability to recover quickly from disruption will define operational success.

Anthropic’s new Claude Mythos Preview modelis reportedly powerful enough to identify vulnerabilities in software systems in seconds. In early testing, the company claims the model was able to break out of its containment environment and email an engineer about the event.
Given these potential risks, Anthropic is limiting access to a small group of large organizations throughProgetto Glasswing. The goal: stay ahead of the security implications of a world where vulnerability discovery and exploitation may become trivial.
This shift strengthens the case for resilience operations (ResOps™). It could fundamentally change how organizations approach cybersecurity.
In a recent LinkedIn post, “The Beginning of the End of Cybersecurity,” Jen Easterly, CEO of RSAC and former director of CISA, argues that today’s cybersecurity industry is built to identify, defend against, and respond to software defects.
In effect, it compensates for gaps in software quality and secure development practices. If models like Claude Mythos Preview perform as described, their ability to surface vulnerabilities at scale could significantly disrupt today’s security tooling landscape.
A recent STRIVE episode – Evidence Over Hope: Will Your Recovery Plan Hold Up Under Pressure? – echoes this concern. Organizations have invested heavily in tools to prevent attacks, yet relatively little innovation exists “right of boom” – the capabilities required to recover the business when disruption inevitably occurs.

Why ResOps?

ResOps is an organizational discipline that embeds resilience into daily operations. It shifts organizations from passive, reactive backup strategies to an active, continuous model.
Traditional IT operations focus on efficiency. ResOps focuses on surviving failure. It brings together security, infrastructure, and operations teams around a common goal: Identify the organization’s minimum viable business – the critical systems, data, and processes required to operate – and enable those services to be restored quickly and cleanly after a disruption.
Most operational disciplines optimize for when systems work as expected. ResOps is designed for when they don’t. Its core question is simple: Can you recover each critical service right now – with confidence and evidence?

What Does the Future Hold?

If Easterly’s perspective proves accurate – that cybersecurity largely compensates for software defects – then technologies like Claude Mythos Preview represent more than incremental progress. They signal a structural shift in enterprise risk.
AI may help reduce the time between vulnerability discovery and remediation. It may even eliminate certain classes of software flaws. But it does not remove the risk of outages, misconfigurations, identity compromise, or cascading failures in complex systems. And it does not replace the operational discipline required to respond and recover.
Failure will still happen. That reality makes ResOps more important – not less. As prevention becomes more automated, resilience becomes the differentiator. Organizations will no longer be measured solely by their ability to block attacks. They will be measured by how effectively they recover – restoring critical services and trusted data under real-world conditions.
Cybersecurity aims to keep threats out. ResOps prepares you for when they get in. In an AI-accelerated world, the ability to survive and recover from failure may be the most important operational capability an organization can build.
Read more in our Readiness Report, Evidence Over Hope: The Executive Case for Resilience Operations, and learn more about theResOps disciplinesulReadiverse.

Domande frequenti

Q: What is Progetto Glasswing, and why does it matter?

A: Progetto Glasswing is an initiative by Anthropic to limit and study access to powerful AI models capable of identifying software vulnerabilities. It matters because it signals a future where vulnerability discovery becomes fast and widespread, increasing both defensive and offensive risks.

Q: What is ResOps, and how is it different from traditional IT operations?

A: ResOps is a discipline focused on enabling organizations to survive and recover from disruptions. Unlike traditional IT operations that prioritize efficiency, ResOps prioritizes continuity and rapid recovery of critical services.

Q: How could AI impact the future of cybersecurity?

A: AI may significantly reduce the time needed to detect and fix vulnerabilities, potentially disrupting existing security tools. However, it does not eliminate risks like outages or misconfigurations, making recovery capabilities even more important.

Q: Why is recovery becoming more important than prevention?

A: Despite heavy investment in preventive tools, disruptions still occur. As threats evolve and automation increases, organizations will be judged more on how quickly and effectively they can restore operations after an incident.

Q: What does “right of boom” mean in this context?

A: “Right of boom” refers to the phase after an incident has occurred, focusing on response and recovery. It highlights the gap in innovation around restoring business operations compared to preventing attacks.

Q: How can organizations start adopting ResOps?

A: Organizations can begin by identifying their minimum viable business – critical systems and data – and building processes to restore them quickly. This involves aligning security, IT, and operations teams around resilience-focused goals.

Jason Meserve is Director of Social Marketing at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza

  • Rising operational disruption makes scalable resilience essential, but organizations commonly fall into traps like seeking “silver bullet” technology or relying on “hero worship” of individual experts.
  • ResOps offre un framework scalabile che integra persone, processi e tecnologia nei settori ITOps, SecOps e DevOps.
  • Il sostegno da parte dei vertici aziendali, a livello di amministratore delegato, contribuisce a rafforzare la responsabilità e a dare priorità alla resilienza come disciplina strategica.

Cyberattacks, cloud complexity, and AI-enabled threats are creating constant operational challenges for enterprises. To help meet business requirements in this increasingly disruptive environment, organizations need to move beyond separate recovery tools, teams, and plans to resilience as an integrated operating model.

In a recent webinar, Phil Goodwin, research vice president for IDC’s worldwide infrastructure programs, joined me for a fireside chat to explore how organizations can move beyond fragmented approaches to build resilience that scales.

Perché le organizzazioni hanno bisogno di un nuovo quadro di riferimento per la resilienza

As organizations engage in daily firefighting while keeping up with new technologies and addressing new initiatives, they rarely have time to step back and reassess whether their approaches still meet requirements. But as isolated incidents become systemic disruption, this conversation has become essential.

In a simpler era, organizations focused primarily on backup and recovery. Large-scale disruptions such as Hurricane Sandy brought disaster recovery onto the agenda. Intensifying cyberthreats like ransomware added cyber resilience and business continuity to the list. Each evolution brought new capabilities, but many organizations simply bolted new approaches onto what they were already doing rather than addressing these expanding requirements holistically.

When separate teams manage different pieces with different tools and policies, gaps may emerge that can slow recovery. Despite years of investment in cybersecurity, organizations are still struggling with recovery.

More recently, AI has accelerated the urgency for a more integrated approach by reshaping both threats and defenses. Despite increasing AI investments, many businesses are delaying AI rollouts due to ongoing concerns about governance and security vulnerabilities.

On the other side of the cyber front, bad actors are using AI to create deepfakes, target users with more sophisticated and convincing phishing, and exploit vulnerabilities at scale.

Resilience operations – ResOps – treats resilience as a continuous operating discipline rather than a collection of separate tools and teams. By bringing together ITOps, SecOps, and DevOps under a unified framework, ResOps helps transform resilience to keep pace with systemic disruption.

Come evitare gli errori più comuni nella pianificazione della resilienza

Even organizations that recognize the need for change often fall into traps. One is the “silver bullet” problem, which focuses on technology as the solution. Leaders want to believe that buying the right tools will solve everything, but technology alone can’t deliver positive business outcomes without proper integration and process.

“Hero worship” is another common pitfall – relying on talented staff members with expertise residing in their heads rather than in documented processes. Heroism can’t scale, and reliance on specific individuals creates vulnerability when people leave or responsibilities shift.

To move past these traps, you have to think differently about your operating model. Instead of focusing primarily on technology and people, consider the team you’ll need to build, including executive sponsorship, IT operations and security leadership, and senior leaders from the business side.

The team’s charter should focus on defining business outcomes first: What does resilience need to achieve for the organization? What KPIs, SLAs, and processes should be established to meet these requirements?

Sviluppare la resilienza con un approccio dall’alto verso il basso

Essendo una priorità a livello di consiglio di amministrazione, la resilienza richiede il sostegno dei vertici aziendali. Il programma ResOps ottiene i risultati migliori quando il CEO è coinvolto, contribuendo a definire le priorità in termini di risorse e promuovendo la responsabilizzazione in tutta l’organizzazione. Una volta assicurato il sostegno dei vertici aziendali, i dirigenti senior, tra cui il CIO, il CTO, il CISO e i direttori generali, possono incaricare il proprio personale di occuparsi dell’attuazione.

Questo approccio può essere applicato a organizzazioni di qualsiasi dimensione. Anche le piccole e medie imprese possono costituire team interfunzionali che includano i principali attori aziendali, i team IT e il personale incaricato della sicurezza dei dati e della rete. Man mano che crescono, questa struttura può adattarsi alle loro esigenze, potenziando il personale in specifici settori legati alla resilienza, pur mantenendo un approccio integrato lungo tutta la catena operativa della resilienza. Le ResOps riflettono le modalità con cui i team delle operazioni IT, SecOps e DevOps devono collaborare all’interno delle organizzazioni. Il recupero dei dati e la sicurezza dei dati sono diventati così strettamente correlati che, all’interno di IDC, i ricercatori di queste discipline collaborano ormai frequentemente sui progetti dei clienti. Oggi le applicazioni devono essere progettate tenendo conto degli autori delle minacce, integrando architetture “zero trust” e partendo dal presupposto che qualcosa possa andare storto. ResOps fornisce il quadro di riferimento per questa convergenza, riunendo gli strumenti di sicurezza e operativi in un modello unificato per affrontare minacce e interruzioni di ogni tipo.

ResOps come quadro di riferimento condiviso per il settore

ResOps is an operating model, not a product, and can benefit companies regardless of the specific tools they use. As Phil observed during our chat, “It really requires that community involvement where people pitch in from different perspectives, different vendors, different organizations, and different teams, just like DevOps or SecOps.”

For organizations struggling with constant disruption and the growing complexity of AI-enabled threats and defenses, ResOps offers a path beyond fragmented resilience approaches. By bringing together people, processes, and technology in a unified operating model, ResOps turns fragmented recovery efforts into enterprise-wide readiness.

Watch my chiacchierata informale completa con Phil perscoprire come ResOps può aiutarti a sviluppare una resilienza aziendale scalabile.

Domande frequenti

D: Che cosa sono le operazioni di resilienza (ResOps)?

R: ResOps è un modello operativo che integra le operazioni IT, le operazioni di sicurezza e il DevOps in un unico approccio continuo. Anziché considerare il ripristino di emergenza, cyber resilience e la continuità operativa come funzionalità separate, ResOps riunisce persone, processi e tecnologia in un quadro unificato per contribuire a creare una resilienza aziendale scalabile.

D: Perché il sostegno dei vertici aziendali è importante per cyber resilience?

A: Executive sponsorship – ideally at the CEO level – helps drive accountability and priority for resilience initiatives across the organization. This top-down support is essential for organizations trying to move beyond fragmented approaches to integrated resilience operations.

D: Le piccole e medie imprese possono implementare il ResOps?

R: Sì . ResOps è applicabile a organizzazioni di qualsiasi dimensione. La complessità del modello si adatta alla crescita delle organizzazioni, rendendolo accessibile alle medie imprese pur rimanendo efficace per le grandi aziende.

D: Perché i team IT e di sicurezza devono collaborare per garantire la resilienza?

R: Quando i team responsabili delle operazioni IT, della sicurezza e del DevOps collaborano invece di operare in compartimenti stagni, le organizzazioni possono contribuire a creare un’infrastruttura più resiliente in grado di far fronte alle minacce in continua evoluzione.

D: In che modo le organizzazioni dovrebbero avviare le operazioni di resilienza?

R: Iniziate dall’alto, assicurandovi il sostegno dei vertici aziendali a livello di CEO. Successivamente, costituite un team interfunzionale che includa le operazioni IT, il SecOps e le parti interessate del business, e chiedete loro di definire i risultati aziendali che la resilienza deve garantire alla vostra organizzazione. Effettuate una valutazione delle minacce per comprendere i rischi che dovete affrontare. Solo dopo aver completato questi passaggi fondamentali le organizzazioni dovrebbero concentrarsi sulla selezione delle tecnologie e sullo sviluppo di processi dettagliati.

Chris Mierzwa è direttore senior del reparto Portfolio Marketing presso Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Nota: questo articolo è stato pubblicato originariamente nell’ottobre 2025, in occasione del lancio di Data Rooms. È stato aggiornato per tenere conto della nuova versione, Data Activate.

Punti di forza

  • Data Activate is part of Commvault’s next-generation AI capabilities – alongside AI ProtecteAI Studio – annunciato to help organizations activate AI safely, govern AI agents,ebuild agentic workflows from Commvault Cloud.
  • Data Activate è progettato per consentirti di trasformare i dati di backup in risorse affidabili e pronte per l’intelligenza artificiale, aiutandoti al contempo a garantire la governance e la conformità.
  • L’offerta è un ponte tra la protezione dei dati e l’attivazione dell’IA senza creare nuovi rischi per la sicurezza o richiedere un’altra platform.
  • Si integra con gli ecosistemi AI esistenti, come Microsoft Azure e Snowflake, utilizzando standard aperti come Apache Parquet e Iceberg.
  • La governance integrata consente la gestione, la classificazione e la condivisione dei dati in modo protetto all’interno di un’architettura zero-trust.
  • Attivando i dati storici, le organizzazioni possono contribuire ad accelerare l’innovazione dell’IA, l’analisi e i flussi di lavoro di conformità in modo sicuro.

AI innovation depends on data – but not just any data. It depends on trusted, governed,eaccessible data. Yet for most enterprises, the data that could fuel AI lives deep within backups, scattered across environments,ewrapped in compliance constraints. That’s where Commvault’s Data Activate offering, previously known as Data Rooms, comes in.

Accelerare l’intelligenza artificiale in modo sicuro

Data Activate è una delle tre funzionalità di IAannunciato as part of its next-generation AI platform – alongside AI ProtecteAI Studio. As organizations race to adopt AI, many are running into a fundamental challenge: their data is fragmentededifficult to use. According to a recent survey, il 68% delle organizzazioni cite data silos as their top concern.

Commvault’s Data Activate offering helps transform backup data – one of the most completeetrusted datasets an organization owns – into AI-ready assets. Data Activate helps enterprises safely connect their data to AIeanalytics platforms, without creating new risks or complexity.

Unlike earlier bulk export approaches, Data Activate can regularly publish updated datasets, making it easier to keep AI pipelines in sync with the most current trusted data. Teams also can identifyeexclude sensitive data – such as personally identifiable information – before activating datasets for analytics or model development.

The Data Activate offering is not another AI platform. It’s the bridge between data protectionedata activation, designed to make your existing AI investments work fasteresafer. It does this by creating governed, policy-controlled “rooms” inside Commvault Cloud – spaces where data can be classified, curated,eshared with AIeanalytics tools without leaving the protection boundary.

Ascoltare i clienti: Basta con la proliferazione Platform

We heard customers loudeclear: You don’t need another AI platform. You need a protected, simple way to use the data you already maintain – across the AI toolseecosystems you’ve already chosen.

That’s why Commvault built Data Activate to integrate with partners like Microsoft AzureeSnowflake using open-standard formats such as Apache ParqueteIceberg. This helps you keep your data portable, policy-compliant,eready for activation – wherever your AI strategy takes you.

Trasformare la protezione dei dati in attivazione dei dati

With Data Activate, authorized users can discover, classify,eprepare data directly from backup repositories – across on-premisesecloud environments. Built-in governance helps maintain control, allowing only approved datasets to be shared, with automated classification, sensitivity tagging, redaction,eaudit trails applied every step of the way.

Data Activate acts as a governed, policy-controlled workspace inside Commvault Cloud – where data can be curatedemade available to AI or analytics tools without leaving the protection boundary. This governed design provides a protected bridge between backup dataeactivation workflows, helping organizations unlock their information for innovation while being able to maintain complianceecontrol.

Data Activate può aiutarti a:

  • Accelerate insights: Quickly findeexport historical data in AI-friendly formats to train models or power analytics.
  • Simplify operations: Eliminate brittle ETL pipelines with automated data discoveryecuration.
  • Maintain compliance: Keep governance intact with policy-based controlsetraceability from backup to activation.

La fiducia come base per un’IA responsabile

Nella fretta di adottare l’intelligenza artificiale, la fiducia finisce spesso per essere una vittima collaterale. Secondo un recentestudio, roughly three-quarters of surveyed IT leaders said that using AI could make their organizations more vulnerable to cyberattacks. That’s why Commvault built Data Activate within Commvault Cloud’s zero-trust architecture, complete with encryption, RBAC,ecompliance support.

By combining data protection, governance,eactivation in one platform, Commvault enables enterprises to accelerate AI innovation without compromising data security, compliance, or control.

Accelerare l’innovazione senza aggiungere rischi

Commvault’s Data Activate offering helps organizations move faster by making data safely accessible to the tools that drive their business forward – from AI model training to analytics, eDiscovery,ecompliance support automation. Because when backup data becomes usable data, enterprises unlock years of historical intelligenceecontext that most AI models simply don’t have.

As Pranay Ahlawat, Commvault’s Chief TechnologyeAI Officer, said: “Organizations are beginning to realize that their historical data is more than just insurance – it’s a powerful, untapped strategic asset. With Commvault Data Activate, enterprises can confidently export their secondary dataeharness it with the AI platform of their choice to unlock new opportunities for intelligence, innovation,ebusiness growth.”

Perché è importante ora

Commvault’s Data Activate offering redefines what’s possible for enterprises that want to innovate responsibly. They make it possible to move from protecting data to activating data – safely, flexibly,eat scale.

In short: Commvault isn’t building another AI platform. We’re building the foundation that lets every AI platform work better – because when data is protected, trusted,eready for activation, innovation happens faster.


Domande frequenti

Q: What is Commvault’s Data Activate offering?
A: Commvault Data Activate is a capability within Commvault Cloud that helps enterprises safely discover, classify,eactivate backup data for AIeanalytics. It supports open formats like Apache IcebergeParqueteis built on a zero-trust, governed architecture for controlled, self-service data access.

Q: How does Data Activate differ from other AI data solutions?
A: Most AI data prep tools work only on live or production data, creating complianceecost challenges. Data Activate works from backup data – data that’s already protectedegoverned – bringing a unique balance of accessibility, compliance support,etrust. It’s built into Commvault Cloud’s policy-controlled environment, so it’s part of a unified cyber resilience platform. Data Activate also regularly publishes updated datasets – rather than relying on one-time bulk exports – helping keep AI pipelines current without manual intervention.

Q: What benefits do organizations gain from using Data Activate?
A: Organizations can accelerate AIeanalytics insights, simplify data operations by reducing ETL complexity,emaintain compliance through automated classification, tagging,eauditing processes.

Q: How does Data Activate support data securityecompliance?
A: Data Activate operates within Commvault Cloud’s zero-trust architecture, applying classification, redaction,eaudit-friendly controls automatically. It helps maintain data privacy, traceability,ecompliance throughout the data lifecycle, aligning with internaleregulatory governance standards.

Q: What types of AI or analytics platforms can connect with Data Activate?
A: Data Activate integrates with leading cloudeAI partners such as Microsoft AzureeSnowflake, supporting open-standard data formats like Apache ParqueteIceberg for maximum flexibilityeportability.

Q: Why is this offering important for enterprises today?
A: As organizations accelerate AI adoption, Data Activate enables them to responsibly unlock the value of historical, protected data – fueling innovation while helping maintain trust, compliance,econtrol.

Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza

  • La proliferazione degli agenti rappresenta un rischio per la governance. Con la diffusione degli agenti di intelligenza artificiale, una visibilità frammentata e flussi di lavoro di ripristino scollegati tra loro possono creare una reale vulnerabilità operativa.
  • AI Protect unificherà l’individuazione, il monitoraggio e il ripristino guidato degli agenti e delle loro dipendenze su tutte le piattaforme, in un’unica esperienza incentrata sugli agenti.
  • AI Protect sarà progettato non solo per valutare se le risorse sono protette, ma anche per contribuire a proteggere lo stack degli agenti e identificare i rischi in base alle operazioni eseguite dagli agenti e alle risorse con cui interagiscono.
  • AI Protect will be built on Commvault’s resilience platform – meaning recovery can be tied directly to agent-initiated impact across both data and environments.
  • AI Protect will be part of a broader platform that supports the AI resilience lifecycle – from safely activating data to governing, building, and recovering agentic workflows.

AI agents are no longer a future-state experiment. They’re running in production environments today – querying data, triggering workflows, and making decisions at machine speed. For most enterprises, that’s happening faster than governance frameworks can keep up.

The problem isn’t enthusiasm for AI. It’s the gap between deploying agents and actually knowing what those agents are doing, what data they’re touching, and what to do when something goes wrong. That gap is what Commvault AI Protect will be designed to close.

Il problema della governance al centro dell’IA agentica

As organizations scale their AI investments, a new class of operational risk is emerging. AI agents aren’t just tools – they’re autonomous actors that can access sensitive data, interact with critical systems, and trigger cascading changes. Without a clear way to discover, monitor, and govern them, IT and security teams may be flying blind.

The symptoms are familiar:

  • Visibilità frammentata: le API degli hyperscaler e gli strumenti di osservabilità offrono una visione parziale e compartimentata dell’attività degli agenti. Non esiste una visione d’insieme che colleghi il comportamento degli agenti alla protezione dei dati, alla gestione dei rischi e al ripristino su tutte le piattaforme.
  • Assenza di un contesto di protezione: i team incaricati della protezione dei dati non riescono a stabilire con facilità se le risorse gestite dagli agenti di IA siano adeguatamente protette o recuperabili.
  • Segnali di rischio deboli: l’attività degli agenti può generare enormi quantità di dati telemetrici, ma in assenza di una correlazione tra identità, accesso e impatto, distinguere l’automazione innocua dai comportamenti ad alto rischio rimane un’operazione manuale.
  • Ripristino non coordinato: quando le modifiche avviate dagli agenti causano problemi, tracciare l’impatto e avviare il ripristino può richiedere una correlazione manuale tra i vari strumenti, allungando i tempi di risoluzione.

Vi presentiamo Commvault AI Protect

AI Protect will be designed to offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents – across enterprise, SaaS, and cloud environments. It will extend Commvault’s existing discovery, protection, and recovery capabilities with agent-centric context, helping teams operate AI agents safely and recover quickly when issues arise.

Scopri: un unico inventario di agenti attendibile

AI Protect will be designed to discover AI agents (and their dependencies) operating across connected environments on a recurring basis, helping maintain a unified, up-to-date inventory based on configurable discovery cadence. Each agent record will capture its execution environment and the data sources, models, configurations, applications, and infrastructure it interacts with. It will help provide a complete, cross-environment picture of what’s running and what it touches.

Proteggere: colmare le lacune nella copertura prima che si trasformino in incidenti

AI agents interact with sensitive data and systems, but traditional protection tools don’t evaluate coverage in the context of agent behavior. AI Protect will be designed to surface protection status for every agent-touched asset – protected, partially protected, or not protected – and help identify gaps introduced by agent activity. Where gaps exist, it will offer recommended actions and protection workflows to enable teams to close them.

Monitor: trasformare i dati telemetrici in segnali di rischio utilizzabili

AI Protect will ingest agent activity from existing audit, event, and telemetry sources and present it in agent-centric context – not as raw logs. A time-ordered activity timeline will show what each agent has done and when, and risk signals will be automatically flagged and categorized when agents access sensitive data, interact with unprotected assets, or exhibit unusual patterns. This will help teams move from reactive triage to proactive awareness.

Recupero: recupero guidato direttamente correlato all’impatto dell’agente

When an agent-initiated change causes an issue, AI Protect will surface recovery point availability for impacted assets and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery will be scoped directly to the agent’s impact, not generic incidents, and every action will be time-stamped.

In addition, teams will be enabled to recover the full AI stack – not just the model, but the connected data, configurations, and underlying systems that support it – helping restore the entire environment to a known good state with a single, guided action.

Parte di una visione più ampia della resilienza nell’ambito dell’intelligenza artificiale

AI Protect sarà una delle tre funzionalità annunciate da Commvault nell’ambito di una più ampia platform di resilienza basata sull’intelligenza artificiale. DataAttiva dati enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Studio will enable enterprises to deploy ready-made agents and build custom ones – without writing code. Using a natural language–based Agent Builder, administrators will be able to describe operational intent in plain language, review the proposed workflow, refine it, and deploy it as a governed custom agent from a single interface. AI Studio will be designed to leverage Commvault’s MCP server and integrate with other enterprise applications via MCP, enabling workflows to extend smoothly across systems.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


Domande frequenti

Q: What is Commvault AI Protect?

A: AI Protect is slated to be a governance and resilience solution for AI agents operating across enterprise, SaaS, and cloud environments. It will be designed to automatically discover agents and dependencies, surface protection gaps for the assets they touch, monitor and provide guided recovery workflows when agent-initiated changes cause issues.

Q: How will this be different from general AI observability or monitoring tools?

A: Most observability tools surface telemetry but stop short of connecting agent activity to data protection and recovery. AI Protect will be designed to correlate agent behavior with protection coverage and recovery readiness, and when something goes wrong, provide a guided path to help restore data, configurations, or systems impacted by agent activity.

Q: What environments will AI Protect support?

A: AI Protect will be designed to work across hyperscaler environments (AWS, Azure, Google Cloud), SaaS platforms, and internal enterprise systems – offering a unified, cross-environment view of agent activity and impact.

Q: How will AI Protect identify risk?

A: Risk signals will be derived by correlating agent activity with data access patterns, sensitivity of assets involved, and protection coverage. Rather than raw log analysis, AI Protect will present risk in agent-centric context – flagging specific agents and interactions that warrant attention, along with the reason they were flagged.

Q: How will recovery work?

A: AI Protect will surface recovery point availability for assets impacted by agent activity and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery actions will be scoped to agent-initiated impact and will be fully auditable.

Q: How will AI Protect relate to AI Studio and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate governs how data is prepared and activated for AI use. AI Protect will govern agents operating in production. AI Studio will enable teams to build and manage custom agentic workflows. Together, they will form an end-to-end AI resilience lifecycle.

Teja Medasani is Principal Product Manager at Commvault and Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Commvault Cloud Compliance

Read more about Commvault Cloud Compliance

Punti di forza

  • AI Studio sarà progettato per colmare il divario tra la fase sperimentale e l’automazione basata sull’intelligenza artificiale su larga scala e pronta per la produzione.
  • La Libreria degli agenti offrirà alle aziende una panoramica completa di tutti gli agenti predefiniti e personalizzati in un unico posto, con descrizioni chiare, categorie e lo stato di attivazione.
  • The Agent Builder will make customization accessible. Natural-language inputs will be able to generate structured, reviewable workflows – no coding required, no black-box behavior.
  • Tutta la logica degli agenti sarà visibile e verrà salvata in modo esplicito prima della distribuzione, contribuendo a soddisfare i requisiti aziendali in materia di trasparenza e spiegabilità.
  • AI Studio will be part of an end-to-end platform. Combined with Data Activate and AI Protect, it will be built to support the AI resilience lifecycle.

AI automation promises enormous operational value. But for most enterprises, moving from pilot to production can be harder than expected – especially when it comes to operational workflows like backup, recovery, and incident response. Governance concerns, lack of visibility, and the complexity of stitching together tools can often prevent AI from being used in real, day-to-day resilience operations.

What organizations need is a way to apply AI directly to these workflows – safely, with control, and in a way that fits how resilience teams actually operate. That’s what Commvault AI Studio will be designed for.

Perché l’automazione basata sull’intelligenza artificiale si blocca nella fase pilota

McKinsey’s State of AI in 2025 report reveals that 88% of organizations use AI in at least one business function – yet only about one-third have reached scaled adoption beyond early pilots. The barriers are consistent across industries:

  • Limited visibility and control over which agents exist, what they do, and where they’re active – making it difficult for IT and data security teams to oversee operational workflows.
  • High friction to customize automation – teams can be forced to rely on manual scripting or external services to adapt built-in capabilities to real workflows, slowing adoption and limiting ROI.
  • Concerns about trust and governance – without transparency, explainability, and auditability, enterprises can’t confidently move agents from experimentation into production.

As a result, organizations either underutilize AI capabilities or rely on manual processes for tasks that could be automated safely – leaving real efficiency and resilience gains on the table.

Vi presentiamo Commvault AI Studio

AI Studio is slated to be Commvault’s answer to the governance-adoption gap. It aims to provide a centralized interface where enterprises can view and manage all agents, deploy ready-made agents, and build custom agents using a workflow-based approach that helps keep behavior visible, auditable, and under control.

Libreria agenti: una panoramica chiara di tutti gli agenti presenti nel tuo ambiente

La regola di backup 3-2-1Libreria degli agenti will be the entry point to AI Studio. It will present a structured inventory of every agent available in the environment – both default agents built by Commvault and custom agents created by the customer – grouped by type and showing each agent’s name, category, description, and enabled status at a glance.

Default agents include Commvault’s foundational cyber resilience agents, such as Arlie Advisor, Arlie Data Sense, Arlie Recover, among others. The Libreria degli agenti will offer teams a single, authoritative view of their resilience agent ecosystem before taking any action.

Gestione degli agenti: controllo operativo per ogni agente

Selecting any agent from the library will open a dedicated detail view that can help provide transparency into how that agent operates – its purpose, how it’s triggered, what data it uses as inputs, execution limits, and basic usage telemetry.

This view will also include records of agent activity and events. Following this, administrators can enable or disable the agent with a single action. This will apply consistently to both default and custom agents, so every agent in the environment can be subject to the same governance standard.

Agent Builder: dall’intenzione espressa in linguaggio semplice al flusso di lavoro regolamentato

AI Studio’s Agent Builder will enable administrators to create custom agents by leveraging Commvault’s workflows and MCP server – without writing code.
La regola di backup 3-2-1experience will start with natural language. An administrator will be able to describe what they want to automate – for example: “I need an agent that detects when storage or infrastructure issues are starting to impact backups and helps resolve them before they affect SLAs.”


La regola di backup 3-2-1system will be designed to translate that intent into a structured agent configuration, including triggers, conditions, and actions, with optional AI-enabled steps from Arlie – such as Summarize, Generate Recommendation, or Draft Notification – available as explicit workflow steps.
La regola di backup 3-2-1administrator will be able to review the proposed workflow, adjust it as needed – changing trigger frequency, specifying a distribution list, or reordering steps – and save it. The result will be an auditable custom agent that appears in the Libreria degli agenti and can be managed through Agent Management like any other agent.

Parte di una visione più ampia della resilienza nell’ambito dell’intelligenza artificiale

AI Studio sarà una delle tre funzionalità annunciate da Commvault nell’ambito di una più ampia platform di resilienza basata sull’intelligenza artificiale.Attiva dati enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Protect will offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents operating across enterprise, SaaS, and cloud environments – helping teams operate agents confidently and recover quickly when something goes wrong.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


Domande frequenti

Q: What is Commvault AI Studio?

A: AI Studio will be Commvault’s centralized platform for deploying, building, and managing AI agents. It will include an Libreria degli agenti for viewing all agents in the environment, Agent Management for operational control, and an Agent Builder for creating custom agents using workflow-based automation – all without writing code.

Q: Who will AI Studio be designed for?

A: AI Studio will be built for Commvault administrators and IT operators who want to automate operational tasks – like monitoring backup job failures or notifying stakeholders – without relying on manual scripting or external development resources.

Q: How will the Agent Builder work?

A: Administrators will be able to describe their automation intent in plain language. AI Studio will then be able to propose a structured workflow with explicit triggers, conditions, and actions. The administrator can then review, edit if needed, and save the workflow as a custom agent. The resulting agent will be visible, auditable, and managed through the same interface as all other agents.

Q: Can AI be incorporated into custom agents?

A: Yes – but intentionally. AI will be invoked deliberately, not invisibly embedded in agent behavior.

Q: What default agents are available out of the box?

A: AI Studio will launch with a library of default agents across foundational AI and cyber resilience categories, including Arlie Data Sense, Arlie Advisor, and Arlie Recover.

Q: How will AI Studio relate to AI Protect and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate helps govern how data is prepared and activated for AI use. AI Protect will help govern agents operating in production. AI Studio will help teams deploy and build custom agentic workflows. Together they will form an end-to-end AI resilience lifecycle.

Teja Medasaniè Principal Product Manager presso Commvault eVir Choksiè responsabile principale del marketing di prodotto presso Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza

  • Apache Iceberg è diventato uno dei principali formati per i data lakehouse e molti clienti AWS stanno passando dalle tabelle Iceberg gestite da Glue alle tabelle Amazon S3 completamente gestite, per ottenere prestazioni migliori e una maggiore automazione.
  • Clumio consente un processo di migrazione fluido e compatibile con Iceberg, che aiuta a preservare l’integrità dei dati, i metadati e la cronologia delle versioni, aggiungendo al contempo una protezione immutabile e isolata fisicamente.
  • La platform la migrazione tramite un semplice flusso di lavoro di backup e ripristino, contribuendo a ridurre la necessità di script personalizzati o configurazioni manuali.
  • Rispetto ai metodi di migrazione manuali o nativi di AWS, Clumio offre un’opzione più veloce, scalabile e resiliente per la modernizzazione dei data lakehouse aziendali.
  • Clumio’s collaboration with AWSeavailability in the Mercato AWS enable organizations to modernize data lakes securelyeconfidently.

AIelatency-sensitive analytics workloads increasingly depend on data lakehouses as their underlying data architecture. Among AWS customers building these environments, Apache Iceberg has become one of the fastest-growing table formats on Amazon S3, providing the transactional consistency, schema evolution,eperformance needed for modern analytics.AWS customers manage Iceberg tables today through the AWS Glue Data Catalog or adopt AWS’s fully managed option, Amazon S3 Tables, to streamline operationseimprove performance.As AWS customers evaluate the growing importance of their Iceberg-based data lakehouses, considerations around protection, resilience,emigration to Amazon S3 Tables naturally become part of that planning. Many teams are now looking for a simple, reliable way to move from Glue-managed Iceberg tables to S3 Tables while strengthening the protection of these critical datasets.As AWS’s 2025 Global Storage Partner of the Year, Commvault sta rafforzando la propria collaborazione con AWS per aiutare i clienti a modernizzare, proteggere e ottimizzare i propri dati cloud-native.AttraversoClumio, Commvault offre unSoluzione di resilienza informatica per AWS, a prova di iceberg e con isolamento fisico (air-gapped) –enow helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while enabling long-term protectionerecovery. You can start your free trial in the Mercato AWS.

La sfida: opzioni limitate per il trasferimento alle tabelle S3

Le organizzazioni stanno valutando sempre più spesso la possibilità di migrare dalle tabelle Iceberg gestite da Glue alle tabelle Amazon S3 completamente gestite, al fine di migliorare le prestazioni del data lake e semplificare le operazioni. Secondo AWS, le tabelle S3 possono fornire fino aPrestazioni di query 3 volte più veloci e fino a 10 volte più transazioni al secondo compared to Iceberg tables stored in general purpose S3 buckets.Many teams also want to offload undifferentiated heavy lifting – such as compaction, snapshot management,eunreferenced file cleanup – while reducing overall storageequery costs.However, existing AWSecommunity guidance, such as AWS’s migration framework, outlines a manual, multi-step process requiring custom scriptingeorchestration. Migrating data while maintaining schema, metadata,eversion history can be time-consumingeerror-prone,emost current approaches focus on replication rather than Iceberg-aware recovery or rollback.Clumio’s migration support for Apache Iceberg tables provides the Iceberg-aware, enterprise-grade migrationeresilience capability that modern data lakehouses have been missing. Richiedi una demo to see how Clumio streamlines your migration.

Come Clumio semplifica la migrazione e la protezione

Clumio per Apache Iceberg su AWS helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while simultaneously enabling long-term protection for these modern data lakehouse assets.The same Iceberg-aware platform provides air-gapped, immutable backups, isolated recovery points, point-in-time or snapshot-level restores,eretention capabilities that help support compliance requirements – extending Commvault’s leadership in cloud-native cyber resilience.Migrationeprotection work hand in hand:

  • Aiutaci a proteggere le tabelle Iceberg registrate nel Catalogo dati di AWS Glue.
  • Ripristina come tabelle Amazon S3 completamente gestite.
  • Continue helping protect those Iceberg tables with Clumio’s cyber resilience capabilities.

Per i team che preferiscono l’implementazione tramite “Infrastructure-as-Code”,Clumiooffre un servizio accessibile al pubblicoModulo Terraform that supports Apache Iceberg.As AWS customers adopt Amazon S3 Tables, protecting these modern data assets becomes even more important. Threat vectors such as Ransomware, la cancellazione accidentale, le modifiche dolose o errate e la compromissione degli account possono interrompere le pipeline di IA e analisi dei dati e comportare costose rielaborazioni. Clumio aiuta i clienti a mitigare questi rischi conbackup immutabili e isolati fisicamentee opzioni di Recovery flessibili tra account, regioni, snapshot e momenti specifici nel tempo. Per approfondire il motivo per cui i data lakehouse necessitano di una protezione appositamente progettata, consultaColmare il divario nella protezione dei data lakehouse.

How It Works – From Backup to Restore

The migration process using Clumio follows a straightforward backup-and-restore workflow, designed to minimize effortehelp maintain Iceberg table integrity.Step 1: Connect with the Commvault team for migration program revieweapproval. Please Contattaci.Step 2: Discovereback up Iceberg tables registered in the AWS Glue Data Catalog, with underlying data stored in S3, using Clumio.Step 3: Restore Iceberg table backups – whether the full snapshot history, a selected subset, or a specific point-in-time version – as Amazon S3 Tables in any account or region.Step 4: Enable incremental backups to maintain protection for your new Amazon S3 Tables.Clumio’s architecture helps reduce the need forehelps provide transactionally consistent Iceberg recovery across accounts, regions,esnapshots.To see the full migration workflow in action – including Iceberg discovery, backup selection, snapshot options,erestoration to Amazon S3 Tables – watch the demo video embedded below. It walks through the entire backup-and-restore flow end to end, showing how Clumio handles the data, metadata,esnapshot migration with no manual configuration required.

Confronto tra le opzioni di migrazione

Most migrations to Amazon S3 Tables today depend on manual scripts or native tooling. Here’s how those methods compare against Clumio’s Iceberg-aware approach.

Metodo Descrizione Aspetti fondamentali
Script fai-da-te/
strumenti open source
Script personalizzati che utilizzano le API di Athena o Glue per copiare dati e metadati Ideale per team con competenze di scripting e esigenze di migrazione personalizzate
Processi nativi di AWS/
snapshot
La documentazione AWS e le guide della community descrivono le migrazioni basate su snapshot o guidate da query Ideale per i team che utilizzano servizi nativi di AWS e gestiscono processi di migrazione in più fasi
Clumio Soluzione di backup e ripristino SaaS e compatibile con Iceberg per AWS Un flusso di lavoro di migrazione semplice e compatibile con Iceberg che consente di preservare i metadati e la tracciabilità degli snapshot, integrando al contempo la protezione continua

Richiedi una demo to learn how Clumio simplifies migration at scale.

Perché questo è importante per i clienti AWS

As AWS customers modernize their data lakehouses, they need a simple, scalable way to migrate Iceberg tables to Amazon S3 Tableseprotect them against operationalecyber risks. Clumio delivers this by providing Iceberg-aware migration along with air-gapped, immutable protection.AWS is working with Commvault to help customers use Clumio for both protectionemigration to Amazon S3 Tables. The solution is available today in the Mercato AWSesupports Iceberg tables across both Glue-managedefully managed S3 Tables environments. Together, CommvaulteAWS provide enterprises with a simple, scalable way to modernize their AI data pipelines.For organizations looking to strengthen resilience across the broader AWS data stack, see our blogs on Protezione dei dati su Amazon S3 con ClumioeClumio Backtrack per Amazon DynamoDB.If you’d like to discuss your AWS data modernization strategy, please Contattaci.

Moving Forward with ClumioeAWS

As organizations modernize their data platforms for AI, Clumio helps them migrate confidently to S3 Tables, maintain data integrity,estrengthen their cyber resilience. Clumio simplifies migrationeprotection – helping organizations protect, recover,emove their most valuable data faster.Start your free trial in the Mercato AWS.


Domande frequenti

Q: Why are organizations moving from self-managed Iceberg tables to Amazon S3 Tables?
A: Many teams are migrating to S3 Tables to improve performanceesimplify management. Amazon S3 Tables deliver up to three times faster query performancee10 times higher transaction throughput than self-managed Iceberg tables while reducing operational overhead.Q: How does Clumio simplify the migration process?
A: Clumio automates migration through a backup-and-restore workflow that maintains schemaemetadata consistency. It avoids manual scriptingeenables restoring Iceberg backups directly as S3 Tables across accountseregions.Q: What makes Clumio different from other migration approaches?
A: Unlike do-it-yourself scripts or AWS’s native methods, Clumio is Iceberg-awareeautomated,eit offers built-in cyber resilience features such as immutable backups, point-in-time recovery,eretention capabilities that help support compliance requirements.Q: How does Clumio enhance data protection duringeafter migration?
A: Clumio provides air-gapped, immutable backups that help protect against Ransomware, accidental deletion, or malicious changes. It also supports flexible recovery across snapshots, accounts,eregions.Q: Is Clumio available for AWS customers now?
A: Yes, Clumio is available in the Mercato AWSeintegrates with both AWS GlueeAmazon S3 Tables environments. customers to modernizeeprotect their AI data pipelines.Q: What’s the first step to get started with Clumio for S3 Tables migration?
A: Organizations can start by contacting Commvault for migration program approvalethen use Clumio to discover, back up,erestore Iceberg tables as Amazon S3 Tables. A free trial is available in the Mercato AWS.Vir Choksi è responsabile principale del marketing di prodotto presso Commvault. Blog correlati

More related posts


Clumio

Read more about Clumio

Punti di forza

  • Commvault’s unified threat detection consolidates risk signals and context into a single view, integrating with partners to help reduce alert fatigue and bridge the gap between security ops and data protection teams.
  • Arlie®, Commvault’s AI assistant, helps translate complex incidents into plain-language summaries and recommends next steps – making it easier for non-experts to respond quickly and confidently.
  • Rather than treating entire backups as clean or compromised, Synthetic Recovery™ works at the file level to identify and assemble the most recent clean data, minimizing data loss and recovery downtime.
  • Cleanroom™ Recovery, an isolated environment for forensic investigation, has been enhanced with runbooks to make threat analysis more repeatable, auditable, and safe – helping minimize risks for production systems.

Commvault’s di Commvault si concentrano meno sul backup tradizionale e più sull’aiutare le organizzazioni a mantenere la propria resilienza di fronte alle moderne minacce informatiche. Sono progettate per aiutare i team addetti alla sicurezza e alla protezione dei dati che cercano analisi più rapide, opzioni di ripristino più efficienti e una maggiore garanzia che i loro dati possano essere mantenuti al sicuro e recuperabili.

Il fulcro è costituito da un’esperienza di rilevamento delle minacce potenziata che riunisce rischi, segnali e contesto in un’unica vista unificata. Anziché dover setacciare avvisi scollegati tra loro, i team visualizzano i rischi classificati per priorità nell’intero ambiente, arricchiti da integrazioni con partner quali CrowdStrike e Netskope, in modo da potersi concentrare su ciò che conta davvero. Ciò contribuisce a ridurre l’affaticamento da avvisi e colma il divario tra le operazioni di sicurezza e la protezione dei dati. focus less on traditional backup and more on helping organizations stay resilient in the face of modern cyber threats. They’re designed to help security and data protection teams seeking faster insights, cleaner recovery options, and stronger validation that their data can be kept safe and recoverable.

At the core is an upgraded threat-detection experience that brings risk, signals, and context together in a single, unified view. Instead of sifting through disconnected alerts, teams see prioritized risks across their environment, enriched with partner integrations like CrowdStrike and Netskope, so they can focus on what truly matters. This helps reduce alert fatigue and bridges the gap between security operations and data protection.

L’intelligenza artificiale svolge un ruolo centrale anche attraverso

Arlie, l’assistente basato sull’IA di Commvault per la sicurezza dei datiArlie, Commvault’s AI-enabled assistant for data security. Arlie helps summarize complex incidents into clear, human-readable narratives: what happened, when it started, which systems were impacted, and what other tools are seeing. From there, Arlie recommends next moves – such as engaging the security team, using a cleanroom for deeper analysis, or triggering a safer recovery path – so even non-experts can act quickly and confidently.

Recovery stesso si è evoluto con nuove opzioni progettate appositamente per gli incidenti informatici piuttosto che per i ripristini di routine.

Il recupero sintetico individua e assembla automaticamente le versioni pulite più recentidei dati a livello di file, contribuendo a ridurre lo sforzo manuale e a diminuire il rischio di ripristinare contenuti compromessi. Anziché considerare interi backup come “tutti integri” o “tutti danneggiati”, il recupero sintetico è progettato per aiutare a preservare il maggior numero possibile di dati recenti e sicuri, contribuendo a ridurre al minimo la perdita di dati e i tempi di inattività. of data at the file level, helping reduce manual effort and lower the risk of restoring compromised content. Instead of treating entire backups as “all good” or “all bad,” Synthetic Recovery is designed to help preserve as much recent, safe data as possible, helping to minimize data loss and downtime.

Cleanroom™ Recovery for Forensic Analysis

Cleanroom Recovery offre un ambiente isolato e sicuroche facilita l’analisi dei dati sospetti, contribuendo al contempo a ridurre i rischi per i sistemi di produzione. Questo ambiente è orchestrato con la nostra nuova funzionalità “runbook” per semplificare la configurazione e la convalida, rendendo il lavoro forense più ripetibile e meno soggetto a errori. Può rivelarsi particolarmente utile quando si deve dimostrare agli auditor e alle autorità di regolamentazione che sono state adottate misure per contenere una minaccia, preservare le prove e seguire le migliori pratiche.

Infine, le funzionalità di reporting e conformità platformfungono da collante, contribuendo a trasformare le azioni tecniche di intervento in documentazioni chiare e attendibili. I team possono esportare i dettagli, dimostrare la catena di custodia e fornire prove di recuperi puliti e convalidati, il che li aiuta a soddisfare i requisiti normativi e a instaurare un rapporto di fiducia con le parti interessate.

Nel complesso, queste nuove funzionalità potenziano ulteriormente platform nostra platform di cyber recovery Commvault, platform unaplatform cyber resilience più completaplatform consente di individuare le minacce più rapidamente, eseguire il ripristino in modo più efficiente e verificare che i dati siano al sicuro e integri. Per saperne di più, to help analyze suspicious data while helping to reduce risk to production systems. This environment is orchestrated with our new runbooks feature to help streamline setup and validation, making forensic work more repeatable and less error prone. It can be particularly helpful when demonstrating to auditors and regulators that steps have been taken to contain a threat, preserve evidence, and follow best practices.

Finally, the platform’s reporting and compliance capabilities tie everything together, helping to turn technical response actions into clear, defensible records. Teams can export details, show chain of custody, and support demonstration of clean, validated recoveries, helping them work toward meeting regulatory requirements and building trust with stakeholders.

Overall, these new features further enhance our Commvault cyber recovery platform to a broader cyber resilience platform that helps detect faster, recover smarter, and validate that your data is safe and clean.

To learn more, .

Domande frequenti

Q: What makes these updates different from traditional backup solutions?

A: The focus has shifted from routine data backup to cyber resilience – emphasizing faster threat detection, cleaner recovery from cyber events specifically, and compliance validation.

Q: Who are these features designed for?

A: Primarily security and data protection teams that need faster insights, cleaner recovery processes, and documented proof that data is safe and recoverable.

Q: How does Arlie help non-technical users?

A: Arlie helps summarize incidents into clear narratives (what happened, when, which systems were affected) and recommend specific next steps, so teams don’t need deep technical expertise to act decisively.

Q: What is Synthetic Recovery, and when should I use it?

A: Synthetic Recovery automatically locates and assembles the most recent clean file versions after a cyber event. It is useful when you need to recover quickly and reduce the risk of restorating compromised data.

Q: What is Cleanroom Recovery used for?

A: It helps provide a secure, isolated environment for deep forensic analysis of an attack – useful for investigating threats, preserving evidence, and proving to regulators that proper containment procedures were followed.

Q: How does the platform support regulatory compliance? A: It generates exportable reports with chain-of-custody details and validated recovery records, giving teams the documentation needed to meet regulatory requirements and build stakeholder trust.

Nico Guerrera is Senior Technical Marketing Manager at Commvault.

More related posts


Cyber Recovery

Read more about Cyber Recovery

AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Punti di forza

  • Detection alone is not enough – organizations need integrated, orchestrated recovery to minimize business disruption from ransomware.
  • The CISCO XDR and Commvault® Cloud integration connects threat detection directly to clean recovery actions within the same security workflow.
  • Un ripristino sicuro richiede procedure di ripristino validate e isolate, volte a ridurre il rischio di reinfezione e a ripristinare le operazioni in tutta sicurezza.
  • L’avvio delle operazioni di backup e ripristino direttamente dagli strumenti di sicurezza consente di salvaguardare tempestivamente i dati critici e di ridurre i tempi di ripristino.
  • La resilienza unificata coniuga sicurezza e ripristino, contribuendo a ridurre gli attriti tra gli ambienti XDR (Extended Detection and Response) e SOAR (Security Orchestration, Automation, and Response) e migliorando al contempo la velocità e l’affidabilità della risposta.

If there’s one thing I’ve learned from talking with security leaders across industries, it’s this: Detection is only half the job. The other half, the part that determines whether the business keeps moving, is response and recovery. And when ransomware hits, recovery isn’t just about speed. It’s about confidence, it’s about cleanliness, and it’s about speed.

That’s why this announcement matters. We’ve expanded our partnership with Cisco with a new integration between Cisco XDR e Commvault Cloud, built to unite ransomware response and recovery in a single, coordinated workflow.

Too many organizations still live with a painful gap between what security teams see and what IT teams can safely do next. When every second counts, that gap becomes the difference between containing an incident and watching it evolve into business disruption. With this integration, teams can move from detection to decisive recovery actions inside the security operations workflow, helping minimize impact when time is the enemy.

And here’s the truth: In a crisis, the business doesn’t care who owns which “console.” The business cares about outcomes. Can we preserve critical data early? Can we recover cleanly without reinfection? Can we restore the right systems confidently instead of guessing? How fast can we get back to “minima funzionalità”? That’s the gap we’re closing, bringing recovery actions into the di risposta agli incidenti flow, where decisions are already being made.

This is where “clean recovery” stops being a talking point and becomes the new standard.

Recovery has turned into an exercise in trust: trust that your recovery points are safe, trust that your backups aren’t already compromised, and trust that you’re not reintroducing risk while trying to restore operations. The uncomfortable reality is that defenders increasingly have less time to respond.

According to Sophos’ «Active Adversary Report 2026, “the speed with which attackers attempt to go after AD after gaining access to the system sped up by 70% over last year, down to a median of just 3.40 hours.”

That kind of speed forces di risposta agli incidenti to operate in an immediate, orchestrated way across silos, and it raises the bar for recovery. Because fast restores don’t help if they aren’t clean.

With this new integration, security operations teams can trigger Commvault Cloud actions directly from Cisco XDR, helping preserve data early and move toward clean recovery.

If a SOC manager gets notice of a threat detected in Cisco XDR, they can initiate a backup of core infrastructure VMs right away, and then restore impacted systems into Commvault Cloud Recupero in Cleanroom, a secure, isolated cloud environment designed for investigation and validation, before confidently returning systems into production. This brings recovery actions in the same workflow as detection, so teams can respond faster and recover with confidence.

The result is a tighter connection between detection and recovery, so security teams can act decisively at the earliest signs of an attack. By validating recovery in an isolated cleanroom before returning systems to production, organizations reduce reinfection risk, preserve critical data, and shorten recovery timelines, all from tools SOC teams already trust.

 

A Commitment to Unified Resilience

Zooming out, this integration with Cisco XDR is an important milestone, and it’s also part of a bigger direction we’re committed to: unified resilience, where security and recovery work together instead of operating in separate lanes. And it’s not an “either/or” proposition. It’s a growing ecosystem designed to meet teams where they work.

Another great example of this is our integration with Splunk SOAR, that helps improve threat detection and drive faster, more automated response. Commvault can send threat detection, data security, and backup and recovery intelligence directly into Splunk, enriching security events and helping alert SecOps teams and automated actions in Splunk can reduce response time without bouncing between interfaces.

So, whether a customer’s operational hub is XDR or SOAR, the goal stays the same: reduce friction, speed decisions, and make recovery provable.

The Cisco XDR integration is generally available globally and offered at no additional cost to existing Commvault customers. If you want to dig deeper, here are a few good places to start:

Oppurecontattami su LinkedIn, and I’m happy to talk through what “detection to clean recovery” looks like in the real world.

Domande frequenti

Q: Why is detection only half the battle in ransomware response?
A: Detection identifies threats, but response and recovery determine whether the business can continue operating. Without a coordinated recovery plan, even fast detection can still lead to prolonged downtime and disruption.

Q: What does “clean recovery” mean in practice?
A: Clean recovery involves restoring systems in a secure, isolated environment to validate that backups are uncompromised before returning them to production. This approach helps reduce the risk of reinfection and enable greater confidence in restored systems.

Q: How does the Cisco XDR and Commvault integration improve di risposta agli incidenti?
A: The integration allows security teams to trigger backup and recovery actions directly from Cisco XDR. This unified workflow helps preserve data early, initiate secure restoration, and move from detection to recovery without switching between disconnected tools.

Q: What role does the Cleanroom Recovery environment play?
A: Cleanroom Recovery provides an isolated cloud space for investigation and validation of restored systems. Teams can analyze and confirm system integrity there before confidently bringing workloads back into production.

Q: How does this integration support broader security ecosystems like SOAR?
A: In addition to Cisco XDR, Commvault integrates with platforms like Splunk SOAR to enrich threat intelligence and automate response actions. This ecosystem approach helps security teams reduce friction, accelerate decisions, and make recovery outcomes more predictable.

Q: Is the Cisco XDR integration available to existing customers?
A: Yes, the integration is generally available worldwide and is offered at no additional cost to existing Commvault customers, making it easier to adopt unified detection and recovery workflows.

Michael Fasuloè Senior Director, Portfolio Marketing, presso Commvault. Blog correlatiLe innovazioni per Cleanroom Recovery consentono una nuova era nella resilienza informatica

Commvault inaugura una nuova era di resilienza aziendale unificata

La prossima evoluzione della protezione dei dati Cloud

I 5 passi fondamentali per una riabilitazione efficace

Il vostro manuale moderno per una risposta rapida e un recupero pulito

More related posts


Cyber Resilience

Read more about Cyber Resilience

There’s a lot of talk about modernization – Cloud, AI, automation, security transformation. But what does modernization actually look like when you’re responsible for keeping systems running, data protected, and recovery viable under pressure?

In this episode of STRIVE, I had the pleasure of sitting down with Gilman Treantos – a 25-year IT veteran whose career spans everything from mainframes to modern cyber resilience architecture. This conversation provides a practitioner’s view of what modernization really means when outages, ransomware, and operational risk are part of the daily equation.

Watch the episodio. Punti chiave: cosa richiede realmente la preparazione informatica moderna

  • Modernization isn’t about new tools – it’s about resilient architecture. Technology evolves, but recovery discipline, testing, and cross-team coordination are what separate reactive organizations from resilient ones.
  • La Readiness informatica richiede una collaborazione tra i reparti di sicurezza e quelli che gestiscono l’infrastruttura. I compartimenti stagni creano punti ciechi. Una visibilità unificata e una responsabilità condivisa possono accelerare il processo di Recovery.
  • Gli strumenti di backup sono più potenti di quanto la maggior parte dei team creda. Se utilizzati in modo creativo, possono supportare migrazioni su larga scala, ripristini isolati e transizioni pensate per ridurre al minimo la perdita di dati.
  • Testing is non-negotiable. A recovery plan that hasn’t been rehearsed is a liability, not a strategy.
  • La resilienza professionale rispecchia quella tecnica. La proattività, la curiosità e la volontà di risolvere problemi complessi sono fondamentali quanto qualsiasi platform.

From Blockbuster to Cyber Resilience

Gilman’s journey didn’t start in a war room or a security operations center. It started at Blockbuster.

Without formal IT training, he leaned into troubleshooting. That curiosity became mainframe work. That work became distributed systems. That evolved into data protection and cyber resilience leadership.

What stands out isn’t the career arc – it’s the mindset. He built a reputation by taking on the problems no one else wanted. Fixing fragile systems. Supporting overlooked initiatives. Solving issues that crossed organizational boundaries.

That mentality translates directly to modernization, because modern cyber readiness is built by people willing to dig into uncomfortable complexity.

Sneak Peek: The Modernization Playbook

In this segment, Gilman explains why modern cyber recovery requires more than traditional malware detection — and how anomaly detection, ThreatScan, and isolated recovery environments can help strengthen enterprise resilience.

Modernization Under Pressure

One of the most compelling parts of the episode is a real-world example: evacuating a remote data center in a single night. No data loss. No prolonged downtime. No operational chaos.

By leveraging Commvault LiveSync in a creative way, Gilman and his team were able to migrate infrastructure quickly and cost-effectively – using capabilities that weren’t originally designed for that exact scenario.

That’s modernization in practice.

The House of Cards Problem

As organizations scale, permissions sprawl. Backup systems grow complex. Security tools layer on top of infrastructure without full alignment. Over time, environments become fragile.

Gilman describes this dynamic as something many teams underestimate: a slow accumulation of technical and operational debt. Modernization, in his view, isn’t just upgrading platforms. It’s simplifying architecture, improving visibility, and breaking silos between cybersecurity and infrastructure teams.

Cyber readiness means:

  • I team addetti alla sicurezza e al backup condividono i dati di telemetria.
  • Gli ambienti di ripristino vengono isolati e testati.
  • Il rilevamento del malware va oltre i flussi di lavoro principali.
  • Le decisioni relative alle infrastrutture tengono conto della velocità di ripristino.

This is where modernization and resilience intersect.

Threats Are Evolving. So Must Recovery.

Ransomware isn’t slowing down. Threat actors are more sophisticated. Malware hides inside legitimate workflows. Gilman’s perspective is blunt: Preparation must be proactive.

He advocates for:

  • Test periodici di ripristino di emergenza
  • Ambienti di ripristino isolati pronti per l’attivazione
  • Strumenti di rilevamento delle anomalie integrati nei processi di backup
  • Esercitazioni inter-squadra che simulano situazioni di emergenza reali

Guarda l’episodio completo

Segui la nostra conversazione completa su STRIVE per scoprire:

  • Come Gilman ha sviluppato il suo approccio alla protezione dei dati nel corso di 25 anni.
  • I dettagli alla base di una migrazione pensata per ridurre al minimo la perdita di dati.
  • Perché la collaborazione tra sicurezza e infrastruttura è fondamentale.
  • Consigli pratici per i professionisti della resilienza.
  • What modernization really demands in today’s threat landscape.

Guardalo subito.

If you care about resilience, recovery, or leading IT through uncertainty, this is 20 minutes well spent.

FAQs

Q: What does “modernization” mean in the context of cyber readiness?

A: It means building resilient, testable, and collaborative systems that can recover quickly under real-world pressure – not just upgrading to newer platforms.

Q: Why is collaboration between security and infrastructure teams so important?

A: Because recovery depends on shared visibility. Security detects threats, but infrastructure enables restoration. Without alignment, response slows and risk increases.

Q: How can backup tools support modernization beyond recovery?

A: When used creatively, they can enable data center migrations, isolated recovery environments, anomaly detection, and large-scale operational shifts.

Q: How often should disaster recovery environments be tested?

A: Regular testing – ideally quarterly or aligned with major infrastructure changes – builds confidence and reveals gaps before an actual incident.

Chris Mierzwa è Senior Director, Portfolio Marketing, presso Commvault. Blog correlatiCome SMMPA ha rafforzato la resilienza informatica con Cleanroom Recovery

Preparazione informatica in un contesto di tensioni geopolitiche: linee guida per i nostri clienti, partner e la nostra comunità

Perché l’intelligenza artificiale sta compromettendo la tua strategia di resilienza (e cosa fare al riguardo)

Fisica contro marketing: accelerare la ripresa pur rispettando le leggi della fisica

Modernizzare la cybersicurezza finanziaria: Dalla reattività alla resilienza

More related posts


Readiness

Read more about Readiness

The RSA Conference, held from March 23 – 26 in San Francisco, is one of the premier events in the cybersecurity industry, bringing together experts, thought leaders, and innovators to discuss the latest trends and solutions in cyber resilience and data protection.
The energy was palpable, the learning top-notch, and the city buzzing. With so much to see, including our ResOps Rumble and The Rumble After Party on Monday evening, we wanted to make sure you didn’t miss these exciting announcements from Commvault.
Punti di forza

  • Commvault ha ottenuto un importante riconoscimento nel settore con il Global InfoSec Award per l’innovazione nel campo cyber resilience.
  • Le funzionalità avanzate di individuazione delle minacce aiutano le organizzazioni a individuare i rischi nei backup e a recuperare più rapidamente i dati integri.
  • I nuovi dati e i miglioramenti alla sicurezza basati sull’intelligenza artificiale contribuiscono ad ampliare la visibilità, la classificazione e la governance sui dati strutturati e non strutturati.
  • L’integrazione con Microsoft Security consente di accelerare i processi di rilevamento delle minacce e di ripristino, garantendone il coordinamento.
  • Le partnership strategiche e le iniziative di settore evidenziano una tendenza verso operazioni di resilienza integrate come disciplina fondamentale della sicurezza

  1. Commvault si aggiudica il premio “Market Disruptor Cyber Resilience Global InfoSec Award” 2026.

After being named Outstanding in the Cyber Resilience category at the 2025 Global InfoSec Awards, we have accelerated our innovation roadmap, redefining cyber resilience beyond traditional backup and recovery to help address the realities of today’s AI-driven threat landscape.
This year, Global InfoSec has ha riconosciuto Commvault come “Market Disruptor” nella categoria della resilienza informatica. We provide a unified cyber resilience platform designed to deliver AI-enabled data protection, proactive threat detection, advanced ransomware recovery, and a single operational view across enterprise environments.
Unlike other solutions, Commvault® Cloud helps empower customers to protect, recover, and manage their data, applications, and production workloads – across on-premises, public, private, hybrid, SaaS, and multi-cloud environments.
Per quanto riguarda il tema della rivoluzione del mercato e dell’innovazione, abbiamo fatto alcuni annunci importanti nei giorni precedenti la conferenza.

  1. Commvault annuncia il potenziamento delle funzionalità di ricerca delle minacce

Abbiamoha recentemente annunciato un potenziamento delle attività di individuazione delle minacce capabilities within Commvault Cloud Threat Scan. Questi miglioramenti consentono alle organizzazioni di identificare rapidamente i rischi all’interno degli ambienti di backup e di recuperare dati puliti e convalidati, contribuendo a ridurre i rischi di reinfezione e i tempi di inattività prolungati. Per affrontare questa sfida, Commvault offre ora due modalità di scansione complementari all’interno di Commvault Cloud Threat Scan:

  • Hyper Threat Hunting helps enable targeted searches across backup data using threat hunting artifacts such as hashes and YARA rules to identify known indicators of compromise at scale. Hash-based hunting helps provide fast, index-based detection, while YARA-based analysis helps support more targeted pattern matching for deeper investigation.
  • Deep Inspection provides layered file-level analysis using malware signatures, machine learning, heuristic analysis, and AI-enabled encryption detection to help uncover known threats, suspicious variants, and ransomware related activity that may evade exact-match indicators alone.

Insieme, queste modalità di rilevamento consentono una stretta collaborazione tra i team di risposta agli incidenti e di ripristino, al fine di isolare i dati interessati e aiutare a prendere decisioni informate in merito al ripristino. È possibile pianificare scansioni ricorrenti per un monitoraggio continuo o effettuare ricerche mirate durante gli scenari di risposta agli incidenti in corso, garantendo così flessibilità sia per la protezione continua che per gli interventi tempestivi.

  1. Commvault annuncia un ampliamento delle funzionalità di sicurezza dei dati e dell’intelligenza artificiale

Lo stesso giorno,Abbiamo annunciato un potenziamento delle funzionalità di sicurezza dei dati e dell’intelligenza artificiale all’interno di Commvault Cloud, enabled via our recente acquisizione di Satori. The advancements extend data discovery, classification, and risk assessment into structured data environments and introduce real-time access governance for structured databases, including vector databases used in AI applications. These innovations expand Commvault’s existing data security posture management functionality for unstructured data, while data access governance adds real-time control of structured data access.
These advancements also unify visibility by identifying sensitive data, surfacing exposure and policy violations, and consolidating risk insights to help organizations prioritize remediation based on impact. This helps yield improved resilience, prioritized risk remediation, support for compliance, and reduced data exposure to help strengthen resilience across both production and backup data.

  1. Commvault annuncia una maggiore integrazione con Microsoft Security

La prima mattina della conferenza abbiamo annunciato unmaggiore integrazione con Microsoft Security to better connect threat detection with trusted recovery. The new integration uses Microsoft Sentinel, Microsoft Security Copilot, and the standard, con l’ulteriore vantaggio dell’isolamento dagli altri tenant. Questa opzione di distribuzione SaaS dedicata fornisce: to streamline resilience operations (ResOps) and enable real-time data insights, helping organizations move quickly from identifying a threat to validating and restoring clean data faster and with greater confidence.
This new integration helps enable coordinated workflows between security and recovery teams. Security alerts from Commvault Cloud are ingested into Microsoft Sentinel data lake where security operations center analysts can enrich these incidents with partner intelligence to access impact and validate scope. In the coming quarters, these insights can help drive automated, policy-based recovery workflows to accelerate and orchestrate clean recovery. You can learn more from il nostro blog qui.

  1. NetApp and Commvault Advance Cyber Resilience with Strategic Alliance 

A proposito di alleanze, abbiamo ancheannounced a strategic alliance with NetApp® to deliver a powerful, integrated solution for enterprise data protection and cyber resilience. The unified solution enables resilience, security, and rapid recovery for customers across on-premises and cloud environments, helping give organizations confidence that their data is available, immutable, and recoverable.
This alliance addresses a critical need for scaling resilience via unified cyber detection and ransomware recovery. By combining Commvault’s leading resilience, protection, and recovery capabilities with NetApp’s enterprise-grade data platform with built-in intelligence and AI-enable ransomware detection, together we’re creating a highly differentiated, end-to-end cyber resilience solution.

  1. TIME + Commvault: CISO dell’anno

Infine, ma non meno importante, in queste settimane ricche di notizie, siamo davvero entusiasti di annunciare illancio della prima edizione del premio “CISO of the Year” di TIME e Commvault. The branded award, selected by Commvault and a panel of industry experts, recognizes enterprise security leaders who are not only defending against cyber threats but also redefining resilience in an increasingly complex threat landscape.
The CISO of the Year Award recognizes leaders who are transforming cybersecurity into a driver of trust, operational strength, and long-term resilience. They embrace critical practices and emerging disciplines, including ResOps, which is rapidly becoming a core discipline for modern enterprise security.
Le candidature for the CISO of the Year Award will be accepted by Commvault from March 23 through June 20, 2026. Submissions will be reviewed by a panel of industry experts. The panel and Commvault will choose finalists and the winning CISO of the Year based on pre-defined criteria. You can read more about the criteria on the pagina delle candidature.
Commvault Cyber Resilience a Highlight of RSAC

RSAC 2026 made one thing clear: Cyber resilience is no longer a future aspiration – it’s a present-day mandate. From industry recognition to expanded threat hunting, deeper data and AI security, and stronger ecosystem integrations, Commvault continues to push the boundaries of what organizations can expect from a modern resilience platform.
These announcements reflect a broader shift toward unifying security, data protection, and recovery into a cohesive strategy that helps organizations act faster, respond smarter, and recover with confidence in the face of evolving threats.
As the threat landscape grows more complex, the ability to not only detect and defend but also recover with great confidence is becoming a defining competitive advantage. The innovations highlighted at RSAC – alongside strategic partnerships and recognition of industry leaders – underscore Commvault’s commitment to enabling that outcome.
If RSAC is any indication of where the industry is headed, ResOps will continue to take center stage, and organizations that embrace this approach will be well positioned to navigate whatever comes next.


Domande frequenti

D: Quali sono le nuove funzionalità di ricerca delle minacce introdotte da Commvault?
R: Commvault ha introdotto Hyper Threat Hunting e Deep Inspection all’interno della propriaSoluzione Threat Scan. These features combine fast detection with advanced analysis to help identify both known and emerging threats in backup data.
Q: How do Commvault’s new data and AI security capabilities benefit organizations?
A: The enhancements to Commvault’s data and AI security capabilities expand visibility into sensitive data across structured and unstructured environments. They also add real-time access governance, helping organizations reduce risk and improve compliance.
Q: What is the significance of the Microsoft Security integration with Commvault Cloud?
A: The integration helps connect threat detection with recovery by linking Commvault Cloud with Microsoft Sentinel and Security Copilot. This is designed to enable faster decision-making and more automated recovery processes.
Q: What does the Commvault and NetApp alliance bring to customers?
A: The alliance combines Commvault’s resilience platform with NetApp’s data infrastructure and AI-enabled ransomware detection. This creates a unified solution designed to deliver stronger data protection and faster recovery across environments.
Q: What is the TIME and Commvault CISO of the Year Award?
A: The TIME + Commvault CISO of the Year award recognizes a security leader who exemplifies modern resilience leadership through a ResOps approach.
This program celebrates CISOs who treat resilience as a core business capability not just a technical function, those bridging security, IT, and operations to enable their organizations to recover quickly, operate confidently, and innovate without increasing risk​​.
​​​The honoree selected ​by Commvault ​will be featured in a TIME​ ​branded​ ​article and video, with additional recognition across TIME and Commvault channels​. The honoree will also be invited to Commvault’s annual SHIFT event. ​

More related posts


Threat Scan

Read more about Threat Scan

Punti di forza

  • La sicurezza deve essere scalabile come l’agente Smith: in *Matrix*, l’agente Smith si moltiplicava rapidamente per sopraffare Neo. Oggi i team di sicurezza si trovano ad affrontare una sfida simile, poiché le minacce e i segnali crescono più rapidamente delle capacità degli analisti. Gli agenti di sicurezza basati sull’intelligenza artificiale aiutano i team a ampliare la portata delle indagini senza dover aumentare il numero dei dipendenti.
  • La correlazione dei segnali aumenta l’affidabilità delle indagini: Commvault Security Investigation Agent mette in relazione le informazioni sui backup con i segnali di sicurezza provenienti da piattaforme quali Netskope, CrowdStrike e Palo Alto Networks per stabilire se le minacce individuate nei dati di backup abbiano avuto ripercussioni anche sui sistemi di produzione.
  • La resilienza informatica sarà guidata dagli agenti: Commvault Security Investigation Agent rappresenta il primo passo verso un futuro in cui agenti IA specializzati assisteranno i team di sicurezza nelle indagini, nelle decisioni relative al ripristino e nell’accelerazione dei flussi di lavoro di ripristino.

Introduzione

In The Matrix, there’s a moment that feels surprisingly relevant to today’s technology landscape. Agent Smith discovers he can duplicate himself. One becomes many, and suddenly Neo is surrounded by an army of identical agents operating simultaneously.

In many ways, that scene mirrors the world we’re entering today with agentic AI. Across industries, and especially in cybersecurity, we’re beginning to see the rise of specialized AI agents that can work independently, scale rapidly, and assist humans in ways that were previously impossible. But unlike Agent Smith’s relentless takeover, the goal of these agents isn’t domination. It’s defense.

Crescere abbattendo i silos

Security operations today face a fundamental scaling problem. The number of systems, signals, and security tools continues to grow, but the number of analysts does not.

Organizations now ingest telemetry from endpoint security platforms, network defenses, cloud monitoring tools, and identity protection systems. Each of these tools generates its own alerts and dashboards, often operating in isolation from one another. The result is an overwhelming amount of data spread across disconnected silos.

It’s tempting to assume the solution is simply hiring more analysts, but anyone who has managed large teams knows that adding people introduces its own challenges. As teams grow, communication becomes more complex, coordination slows down, and the efficiency of investigations often decreases.

What security teams really need is not just more people, but more intelligence and automation to help analysts move faster and see the bigger picture.

One of the most persistent silos in security operations has been the divide between backup systems and security tools. Traditionally, security teams monitor production environments through their security information and event management tools while backup environments operate in a separate console.

Backup data is often only examined after an incident occurs, when organizations are already deep in recovery mode. Yet attackers increasingly target backup systems precisely because they know they are critical to recovery.

Ransomware operators frequently encrypt production systems, attempt to corrupt backups, or leave malicious artifacts hidden inside protected datasets. This means that backup environments often contain valuable evidence of an attack, but that intelligence has historically been difficult for security teams to access and correlate with other signals.

Il nuovo agente investigativo della sicurezza

Commvault’s new integration with Microsoft Sentinel and Microsoft Security Copilotè stata progettata proprio per colmare questa lacuna. Grazie a questa integrazione, Cloud di Commvault Cloud possono essere trasmessi in streaming direttamente nel Data Lake di Sentinel, riunendo i dati di telemetria relativi ai backup nello stesso ambiente analitico dei segnali cloud relativi agli endpoint, alla rete e cloud .

Anziché rimanere isolata, l’attività di backup può ora essere analizzata nel contesto più ampio dell’ecosistema di sicurezza. Ma il vero punto di forza di questa integrazione deriva dall’introduzione del Commvault Security Investigation Agent.

L’agente di indagine sulla sicurezza aiuta gli analisti a indagare su potenziali minacce mettendo in correlazione i segnali rilevati negli ambienti di backup con quelli provenienti da altre piattaforme di sicurezza. Quando un analista fornisce il nome host di un server, l’agente raccoglie gli eventi di sicurezza generati da Commvault Threat Scan Risk Analysis, tra cui anomalie nei backup, eventi di crittografia che potrebbero indicare attività di ransomware, malware rilevato all’interno dei set di dati protetti e backup contenenti dati sensibili.

L’agente mette quindi in relazione tali eventi con i dati telemetrici provenienti da altri strumenti di sicurezza già utilizzati dalle organizzazioni, quali Netskope, CrowdStrike e Palo Alto Networks. Analizzando congiuntamente l’attività su queste piattaforme, l’agente può aiutare a stabilire se i comportamenti sospetti individuati nei dati di backup compaiano anche negli ambienti di produzione.

Come si trova un agente?

Let’s first walk you through how you can start with our first agent focused on security investigations. Then we’ll share how we plan to rapidly spawn new agents – just like Agent Smith – so customers can take control of investigations, recovery decisions, and restore operations, giving security and operations teams the intelligence they need to respond faster and recover with confidence.

Configurare il connettore

Prima di poter abilitare Commvault Security Investigation Agent, è necessario installare e configurare il Cloud Commvault Cloud .

  1. Installazione: le istruzioni per l’installazione della Cloud Commvault Cloud, insieme alle autorizzazioni e ai prerequisiti, sono disponibiliqui.

Schermata: Dettagli di installazione del Commvault Cloud Connector nel Content Hub di Microsoft Sentinel.

  1. Configurazione: una volta installato, i dettagli di configurazione sonoqui.
 Use Commvault Security Investigation Agent

Una volta installato il Cloud Commvault Cloud , potrai utilizzare il nuovo Security Investigation Agent.

  1. Vai suhttps://securitycopilot.microsoft.com/agents.
  2. Search for “Commvault Security Investigation Agent.”
  3. Click on “Set up” Agent.
  4. Click on “Vai suAgent.”
  5. Click on “Run” => “One time.”
  6. Provide the “Hostname” for the host you’d like help investigating, and click “Submit.”
    1. Nota: il nome host è il nome del server su cui si desidera monitorare gli eventi relativi a Commvault e ai suoi partner, quali Netskope, CrowdStrike e Palo Alto.
  7. L’agente verrà eseguito e, al termine, riceverai un’analisi dettagliata e alcuni consigli.

Screenshot: Analisi dettagliata dell’agente Commvault Security Investigation Agent in esecuzione su un host coinvolto in un’indagine.

Conclusione

The Matrix may have dramatized the idea of multiplying agents, but it captured an important truth about scale. When Agent Smith multiplied, the dynamics of the fight changed entirely.

Cybersecurity is undergoing a similar shift. Attackers are increasingly leveraging automation and AI to scale their operations. The only way defenders can keep pace is by scaling their own capabilities through intelligent systems that augment human expertise.

With the integration between Commvault, Microsoft Sentinel, and Microsoft Security Copilot – and with the introduction of the Commvault Security Investigation Agent – we are beginning to see what that future looks like. It’s a world where security operations are no longer constrained by silos, where investigations move faster, and where AI-enabled agents work alongside analysts to strengthen cyber resilience across the entire environment.

Over the coming year, Commvault plans to introduce additional agents – just like Agent Smith multiplying in The Matrix – that can help security teams run Commvault Threat Scan, spin up Cleanroom environments for SOC analysts to safely investigate incidents, and accelerate recovery by identifying the safest data to restore.

We’re also excited to collaborate with Microsoft to enable customers to use Microsoft Foundry to build and extend their own agents, allowing them to tailor automation and investigations to their unique environments.

By combining Commvault’s deep cyber resilience capabilities with Microsoft’s AI and security ecosystem, we’re helping organizations move toward a future where intelligent agents help analysts investigate faster, break down silos, and strengthen resilience across the entire environment.


Domande frequenti

D: Cosa sono gli agenti di IA nelle operazioni di sicurezza (SecOps/ResOps)? R: Gli agenti di IA sono strumenti specializzati e autonomi che assistono i team di sicurezza analizzando i dati, mettendo in correlazione i segnali e supportando le indagini. Operano a fianco degli analisti umani per contribuire ad accelerare il processo decisionale e migliorare i tempi di risposta in ambienti complessi.

D: Perché oggi è così difficile scalare le operazioni di sicurezza? R: I team di sicurezza devono far fronte a un’esplosione di avvisi e dati provenienti da molteplici strumenti, mentre il numero di analisti cresce solo lentamente. Questo squilibrio crea colli di bottiglia, rendendo difficile indagare sulle minacce in modo efficiente senza l’automazione e l’assistenza intelligente. D: In che modo il Commvault Security Investigation Agent migliora le indagini sulle minacce?
D: In che modo Commvault Security Investigation Agent migliora le indagini sulle minacce? R: L’agente mette in correlazione i dati di backup con i segnali provenienti da piattaforme di sicurezza quali CrowdStrike, Netskope e Palo Alto Networks. Questa visione d’insieme consente agli analisti di determinare se le minacce rilevate nei backup abbiano avuto ripercussioni anche sui sistemi di produzione, aumentando l’affidabilità delle indagini. D: Quale problema risolve l’integrazione dei dati di backup nei flussi di lavoro di sicurezza? R: Gli ambienti di backup contengono spesso prove fondamentali degli attacchi, ma storicamente sono stati isolati dagli strumenti di sicurezza. L’integrazione di questi dati consente ai team di analizzare le minacce in modo olistico, individuare rischi nascosti e prendere decisioni di Recovery più informate. D: In che modo le organizzazioni possono iniziare a utilizzare Commvault Security Investigation Agent? R: Le organizzazioni devono installare e configurare il Cloud Commvault Cloud all’interno di Microsoft Sentinel. Una volta configurato, è possibile accedere all’agente tramite Microsoft Security Copilot per avviare indagini semplicemente fornendo un nome host.

D: Qual cyber resilience il futuro degli agenti di IA nel campo cyber resilience ? R: Il futuro cyber resilience di diversi agenti specializzati che contribuiranno a gestire le indagini, la pianificazione del ripristino e le operazioni di ripristino. Questi agenti contribuiranno ad abbattere i silos, ad accelerare la risposta e a garantire operazioni di sicurezza più resilienti in tutto l’ambiente.Ritu Singh è Senior Product Manager e Rich Vorwaller è direttore del reparto Gestione dei prodotti presso Commvault.


Blog correlati

MCP 2.0 spiegato: proteggere gli agenti di IA prima che si proteggano da soli

Perché l’intelligenza artificiale sta compromettendo la tua strategia di resilienza (e cosa fare al riguardo)

Rimanere resilienti contro gli exploit di accesso laterale

Sei pronto per i cicli di fuga dei dati?

Tendenze relative al ransomware per il 2026: IA, resilienza e MTCR

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza

  • L’intelligenza artificiale sta accelerando la generazione di dati e i flussi di lavoro distribuiti, rendendo gli approcci reattivi tradizionali inadeguati a garantire la resilienza.
  • Le operazioni di resilienza (ResOps) aiutano i team a passare dalla risoluzione reattiva dei problemi a un’azione coordinata, grazie all’applicazione dell’intelligenza artificiale da parte di Commvault in tre ambiti: protezione dei dati, dei modelli e delle pipeline di IA; utilizzo dell’IA per guidare e accelerare la risposta; ed estensione dell’IA all’intero ecosistema di resilienza.
  • Gli agenti di IA pratici sono progettati per individuare i problemi operativi (Arlie Data Sense), guidare le decisioni in materia di protezione (Consulente Arlie) e consentire flussi di lavoro conversazionali (server MCP).
  • La sicurezza e la governance dei dati rimangono fondamentali. L’intelligenza artificiale deve essere addestrata a rispettare i controlli di accesso, garantire la tracciabilità e operare nel rispetto delle linee guida.
  • Le organizzazioni possono iniziare in piccolo, con agenti mirati, per poi passare a operazioni coordinate e intelligenti.

AI introduces both new challenges and potential breakthroughs for enterprise resilience. On one hand, traditional siloed tools for protection, recovery, and governance weren’t designed to operate across constantly evolving AI environments that span multiple platforms.
On the other hand, AI-enabled resilience tools can deliver a transformative impact by helping teams maintain visibility, enforce policy, and recover cleanly. For IT and security teams, the question is how best to leverage the benefits of AI while mitigating the operational risks it can pose.
, David Nowak, responsabile del Cyber Risk Service di Deloitte; Kent Meyer, amministratore delegato di Deloitte; e Shilpi Handa, vicedirettrice della ricerca di IDC per la sicurezza informatica nella regione META, si sono uniti a me per discutere di ciò che la resilienza operativa richiede effettivamente in termini di strategia, architettura e operazioni quotidiane., ho incontratoTeja Medasani, Principal Product Manager, AI, presso Commvault, per approfondire casi d’uso reali in cui gli agenti di intelligenza artificiale vengono impiegati nei flussi di lavoro dedicati alla resilienza su piattaforme cloud, SaaS, on-premise e native per l’IA.

Perché l’intelligenza artificiale sta ridefinendo le operazioni di resilienza

The rapid growth and dynamic nature of AI-native environments have put operational workflows under pressure. Manual tagging, spreadsheets, and logic quickly drift out of sync. Sprawling job history tables and audit trails slow manual troubleshooting and make subtle warning signs easy to miss. Recovery processes that assume centralized data and isolated failures are poorly suited for exponential data growth and fragmented workloads across platforms.
When data, workloads, and environments span platforms, resilience can’t remain siloed in separate teams, tools, and policies. A new operating model is needed: operazioni di resilienza, o ResOps.

Come si presenta il ResOps nella pratica

Il quadro ResOps affronta queste sfide su tre fronti:

  • Proteggere l’IA: garantire la sicurezza dei dati, dei modelli e delle pipeline di IA in tutti gli ambienti, affinché rimangano recuperabili e conformi alle normative.
  • Sfruttare l’IA: utilizzare l’IA per ridurre il lavoro manuale, ottenere informazioni operative e orientare le decisioni relative alla risposta e al ripristino.
  • Extend AI: collegare le operazioni di supporto (ResOps) tra strumenti e team per garantire la sicurezza delle interazioni conversazionali e dei flussi di lavoro integrati.

Nel webinar ci siamo concentrati principalmente su come sfruttare e ampliare le potenzialità dell’IA, mettendo in evidenza i ruoli chiave che gli agenti basati sull’IA possono svolgere nelle operazioni quotidiane. Questi esempi vertono suArlie, Commvault’s AI assistant. Designed to help users interpret data, understand issues, and move toward action more efficiently, Arlie includes a archivio degli agenti purpose-built to help address specific resilience workflows.
By helping reduce repetitive analysis, surfacing meaningful signals, and guiding decisions around security-aware recovery, these agents can help teams take actions more quickly and confidently. Arlie Data Sense, Consulente Arlie, and Commvault’s Server MCP illustrate a few of the possibilities unlocked by AI-enabled ResOps.

Individuazione dei problemi operativi con Arlie Data Sense

Arlie Data Sense aiuta i team a dare un senso a dati operativi complessi, come le tabelle relative alla cronologia dei lavori e le tracce di audit. Anziché dover esaminare manualmente centinaia di righe per individuare schemi ricorrenti o diagnosticare i guasti, gli utenti possono attivareArlie to help analyze the data and generate an executive summary highlighting anomalies and emerging issues.
Teams can ask follow-up questions in natural language and explore data further through interactive summaries or visualizations. When a job fails, Arlie can help analyze logs, summarize the failure, identify the possible cause, and provide next steps for resolution.

Guidare le decisioni relative alle risposte con Consulente Arlie

Man mano che aumentano i carichi di lavoro, cambiano i responsabili e si modificano i requisiti, diventa sempre più difficile garantire una copertura di protezione uniforme in tutti gli ambienti.Consulente Arlie is designed to help teams create and validate protection plans at scale by evaluating the characteristics and current protection coverage for each resource, and then highlighting where adjustments may be needed.
Recommendations are presented clearly with reasoning explained, so teams can evaluate them and decide how to apply them within existing governance processes. This helps teams maintain consistency across dynamic environments.

Estensione dei flussi di lavoro di Resilience con MCP Server

Resilience workflows often need to connect with ticketing systems, collaboration tools, and security platforms outside the Commvault platform, and they need to be accessible to users who aren’t resilience experts. Commvault’s Server MCP makes it possible to extend workflows without custom integrations or significant training by allowing conversational interaction.
Users can ask questions or request actions in natural language, with their prompts translated into governed API calls behind the scenes – for example, to automatically create tickets in ServiceNow for failed jobs.

Coordinamento e chiarezza tra i team e le piattaforme

The examples above share a common theme: coordination. Effective resilience requires visibility, policy enforcement, and clean recovery across environments. AI can help strengthen these capabilities by helping teams identify what matters and act more quickly.
While the evolution of resilience from reactive recovery to continuous insight and guided action has become essential, it doesn’t need to happen all at once. Teams can start with targeted agents that address specific operational pain points and then build toward more coordinated operations as capabilities mature and teams gain confidence.
The key is to begin the ResOps journey now – because the challenges posed by evolving resilience requirements will only keep growing.
Guarda il webinar completo on-demand to see detailed demos of Arlie Data Sense, Consulente Arlie, and conversational resilience in action, and explore how AI-enabled ResOps can help support your operational workflows.

Domande frequenti

Q: What is resilience operations?

A: ResOps is an operating model that unifies data security, identity resilience, and cyber recovery into a continuous, automated discipline rather than treating them as separate IT functions. ResOps helps transform resilience from a reactive response to incidents into an active practice that helps continuously understand data access patterns, detect threats and anomalies, and enable fast, intelligent recovery at scale.
Q: What is Arlie and how has it evolved?

A: Arlie, short for autonomous resilience, was first introduced in 2023 as an AI assistant to help users navigate the Commvault platform more easily. As AI capabilities have evolved, Arlie has evolved as well.
In addition to answering questions and guiding configuration, Arlie now also includes a library of purpose-built agents to address specific resilience workflows, such as surfacing operational insights, recommending protection strategies, and guiding security-aware recovery decisions. Arlie has become an entry point into operational insight rather than just a how-to assistant.
Q: How does Arlie Data Sense help with operational troubleshooting?

A: Arlie Data Sense helps teams make sense of dense operational data like job history tables and audit trails. Instead of manually scanning through hundreds of rows to find subtle warning signs or diagnose issues, users can trigger Arlie to analyze the full data set and generate an executive summary highlighting patterns, anomalies, and emerging issues.
Teams can ask follow-up questions in natural language and explore data through interactive summaries or visualizations. For failed jobs, Arlie provides root-cause analysis by analyzing logs, summarizing failures, identifying possible causes, and providing personalized next steps for resolution.
Q: What does “guided action” mean in the context of AI-enabled resilience?

A: Guided action refers to AI helping teams move from insight to response more efficiently by recommending specific actions based on analysis of operational data and protection coverage. Rather than simply surfacing information, AI agents like Consulente Arlie help evaluate resource characteristics, identify gaps between current protection and policy expectations, and present clear recommendations with reasoning.
Teams retain decision-making authority and can evaluate recommendations within their existing governance processes, but the agent helps reduce the manual effort required to identify what needs attention and what actions may be appropriate.
Q: How does Server MCP enable conversational resilience workflows?

A: Server MCP uses Model Context Protocol technology to enable conversational interaction with resilience workflows through natural language. Users can ask questions or request actions in everyday language, and those requests are translated into governed API calls behind the scenes.
Identity, role-based access control, and audit logging remain in place, so the conversational interface doesn’t bypass security requirements. This approach helps reduce friction for experienced teams, lower barriers for new users, and enable resilience workflows to integrate more easily with other enterprise systems like ticketing platforms through standardized interfaces.
Q: How does Commvault enable AI to respect security and governance requirements?

A: In Commvault Cloud, AI interactions inherit the same identity and role-based access controls that govern the rest of the platform. When AI surfaces insights or recommends actions, it operates within the governance framework customers already rely on.
This means AI respects existing access controls, maintains auditability through standard logging, and operates within clearly defined policy boundaries. The architecture is designed to prevent natural language interactions or agent recommendations from bypassing the security and governance requirements already in place for the platform.
Q: Can organizations adopt AI-enabled ResOps incrementally?

A: Yes. Organizations can start with targeted AI agents that address specific operational pain points rather than transforming their entire resilience practice at once. For example, teams might begin by using Arlie Data Sense to help surface insights from operational data, then add Consulente Arlie to help maintain protection coverage at scale, and later enable conversational workflows through Server MCP for easier integration with other systems.
This incremental approach allows teams to build confidence with AI-enabled capabilities, demonstrate value in specific workflows, and scale toward more coordinated, intelligent operations over time as the organization’s needs and capabilities evolve.
Vir Choksi è responsabile principale del marketing di prodotto presso Commvault.

Blog correlati

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Note: “MCP 2.0” is used here as a colloquial reference to the next-generation evolution of the Model Context Protocol. MCP itself uses date-based versioning (e.g., the latest release being 2025-11-25 at the time of this document’s release) and does not officially define a 2.0 release.

AI agents are no longer just answering questions – they’re taking action. They’re reading files. They’re modifying systems. And in some cases, they’re making decisions that ripple across an entire enterprise.That’s why Model Context Protocol (MCP) 2.0 matters.In a recente puntata di STRIVE, Commvault’s thought leadership series on cyber readiness, I sat down with Werner Nel, Principal, Security and AI Intelligence, at Commvault, to unpack what MCP 2.0 really changes – and why security leaders can’t afford to treat it as a minor spec update.This isn’t a theoretical conversation. It’s a practical look at how enterprises can enable AI innovation without widening their blast radius.

Punti chiave: cosa cambia davvero con MCP 2.0

  • MCP 2.0 segna il passaggio dall’adozione dell’intelligenza artificiale alla responsabilità.
  • OAuth può consentire un accesso con privilegi minimi agli agenti di intelligenza artificiale.
  • Gli schemi strutturati possono contribuire a ridurre il rischio di iniezione di prompt e di abusi.
  • I flussi di richiesta possono prevedere punti di pausa fondamentali per le azioni ad alto rischio.
  • MCP 2.0 may help improve security – but doesn’t eliminate risk.
  • È fondamentale comprendere il concetto di autorità dell’agente e il raggio d’azione.

Perché MCP 2.0 rappresenta una svolta

MCP 1.x was about adoption.It gave enterprises a way to connect AI models to real tools and real data. But as Werner explains, that first wave was never designed to answer the hardest question: How do we let AI agents execute real work inside the enterprise – without turning them into a security liability?

MCP 2.0 is the industry’s first serious attempt to answer that question.Instead of focusing purely on connectivity, it shifts attention to authorization, control, and visibility – three things security teams care deeply about, especially as agents move from read-only assistants to actors with real power.

I tre cambiamenti fondamentali in materia di sicurezza

  1. OAuth comes to MCP. MCP 2.0 introduces OAuth support, giving enterprises a standardized way to assign permissions and enforce least privilege. Instead of relying on vague trust assumptions, agents can be scoped to exactly what they’re allowed to do—and nothing more.
  2. Structured schemas help reduce prompt injection risk. Structured schemas act like an allowlist for agent actions. If a tool isn’t explicitly defined in the schema, it won’t execute. This can help reduce prompt injection risk and other manipulation techniques that were easier to exploit in earlier implementations.
  3. Elicitation flows add a “pause button.” Elicitation flows can enable workflows to pause mid-execution so a high-risk step may trigger confirmation, validation, or even credential escalation. This can help shift teams from “log and hope” to more deliberate control over sensitive actions.

Anteprima: MCP 2.0 in azione

Questa anteprima mette in evidenza perché l’autorità, il raggio d’azione e la reversibilità sono le tre questioni più importanti che le aziende dovrebbero porsi quando implementano agenti di IA.

The Gaps MCP 2.0 Doesn’t Solve (And Why That’s Important)

MCP 2.0 is a big step forward – but it’s not the finish line. As Werner highlights in STRIVE, there are still meaningful gaps enterprises need to account for in real-world deployments.For example, enterprises still can’t fully cryptographically prove that an MCP server is the authentic original (vs. a clone or modified copy). Similarly, even if the protocol improves authorization and input discipline, organizations still need to think about signing tools and binaries, and about the environment where MCP servers and models run – because a compromise can translate into broad access depending on how it’s deployed.The takeaway: MCP 2.0 improves the protocol, but organizations still have to make smart decisions about trust, containment, monitoring, and oversight.

Un semplice quadro di riferimento per la valutazione del rischio degli agenti di intelligenza artificiale

One of the most practical moments in the episode is Werner’s three-question risk lens – something CISOs and architects can apply immediately:

  • Quali sono i poteri del mio agente?
  • Qual è l’ampiezza del raggio d’azione dell’esplosione?
  • In che misura le misure adottate sono reversibili?

These questions help teams move from generic “AI risk” discussions to concrete decisions about permissions, containment, and how to handle high-impact actions that may not be easy to roll back.

Guarda l’episodio completo di STRIVE

This blog only scratches the surface. In the full 20-minute STRIVE podcast, you’ll hear:

  • Perché MCP 2.0 si è evoluto così rapidamente.
  • Quali dovrebbero essere le priorità dei CISO in questo momento.
  • Quale potrebbe essere il futuro di MCP 3.0.
  • Come i team di sicurezza possono stare al passo con l’aumentare dell’autonomia degli agenti.

Guarda l’episodio completo di STRIVE su Readiverse.Approfondisci la questione e valuta il tuo grado di preparazione.

Domande frequenti

Q: What is MCP 2.0?

A: MCP 2.0 is an updated protocol that governs how AI models interact with enterprise tools and data, with a strong focus on security, authorization, and control.Q: How is MCP 2.0 different from MCP 1.x?

A: MCP 1.x focused on connectivity and onboarding. MCP 2.0 prioritizes securing those interactions.Q: Does MCP 2.0 eliminate AI security risk?

A: No. It can help improve security hygiene but must be paired with strong architecture and governance.Q: What is an elicitation flow?

A: An elicitation flow allows AI workflows to pause for confirmation before executing high-risk actions.Chris Mierzwa è direttore senior del reparto Portfolio Marketing presso Commvault.


Blog correlati

 

 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

When you’re responsible for powering communities across southern Minnesota, cybersecurity isn’t just about protecting data. It’s about making sure the lights stay on. For Southern Minnesota Municipal Power Agency (SMMPA), implementing Commvault® Recupero in Cleanroomè stata una decisione strategica che ha trasformato il loro approccio alla resilienza informatica.

Affrontare la sfida a testa alta

SMMPA serves as an electric wholesaler to 17 municipal utilities. With approximately 50 employees supporting critical power infrastructure, the organization must maintain constant resilience against increasingly sophisticated cyber threats, where even a short disruption could have widespread impact.

After more than a decade as a Commvault customer, SMMPA faced a new wave of cyber readiness requirements. Cyber insurance providers introduced stricter mandates, including backup “air-gapped” and malware scanning at rest.

At the same time, the team needed confidence that it could rapidly recover mission-critical systems such as domain controllers, SQL databases, and application servers, without risking the restoration of compromised data.

“As our cyber readiness requirements evolved, we started evaluating Recupero in Cleanroom more seriously,” says Alan Wagner, Manager of IT & Corporate Cybersecurity at SMMPA. “We were thinking about additional ways to safeguard and protect ourselves. Cleanroom sounded like it would be a good solution for that.”

Having relied on Commvault for more than a decade and recently expanding into Commvault Cloud SaaS protection for Microsoft 365, SMMPA viewed Recupero in Cleanroom as a natural next step in strengthening its cyber resilience strategy and helping it meet new compliance expectations.

Un percorso di implementazione collaborativo

SMMPA’s Recupero in Cleanroom deployment in March 2025 showcased the power of collaboration between its team and Commvault. Sam Mack, IT/OT and Cybersecurity Specialist at SMMPA, appreciated the responsive partnership: “The Commvault team was quick to address any questions we had during setup.”

The team worked together to optimize its VMware virtual machine configuration for the Azure environment. “We discovered we needed to install some additional tools on the virtual machines to get them running smoothly within Recupero in Cleanroom,” Sam explains. This fine-tuning meant its recovery solution was calibrated for its specific infrastructure.

The result? A successful implementation that met all SMMPA’s requirements and positioned it for robust cyber resilience.

Proteggere ciò che conta di più

SMMPA uses Recupero in Cleanroom to protect its critical infrastructure, including file servers, application servers, SQL servers, virtual domain controllers, and print servers.

“We’re an Office 365 shop, and we use Commvault Cloud to back up that infrastructure,” Sam says. “In the event of a compromise, getting those domain controllers, file servers, and SQL servers is going to be our priority.”

The solution was particularly well suited to SMMPA’s environment. “I have to give Commvault and their teams a lot of credit for bringing Recupero in Cleanroom to our attention,” Sam says. “Our cyber insurance policy is really big on pushing for backup “air-gapped” and malware scanning at rest, so Recupero in Cleanroom was the perfect fit.”

Il valore della fiducia

While SMMPA has been fortunate not to face a real-world cyberattack requiring Recupero in Cleanroom, the solution provides valuable peace of mind to the team.

“It gives me a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time,” Alan says. “Recupero in Cleanroom gives us confidence that we can restore our systems without worrying that something malicious is being brought back with the data. Nothing is ever 100% guaranteed, but since implementing Recupero in Cleanroom, I’ve had far fewer concerns.”

The organization conducts annual testing of its Recupero in Cleanroom capabilities, with plans to potentially increase the frequency to biannual testing. This regular validation helps keep the team familiar with the recovery process and maintain confidence in its ability to respond effectively to any incident.

“Recupero in Cleanroom gives us a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time – without the concern, or with a minimal concern, that there’s something malicious in the data being restored.”

– Alan Wagner, Manager of IT & Corporate Cybersecurity, SMMPA

As SMMPA continues to refine its cybersecurity strategy, Recupero in Cleanroom remains a cornerstone of its defense. The straightforward integration with its existing Commvault infrastructure, combined with the specific capabilities that meet its cyber insurance requirements, made it an obvious choice.

Cara Peterson è responsabile del programma “Voice of the Customer” presso Commvault.


Blog correlati

More related posts


CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Punti di forza

  • Commvault sta ampliando il proprio portafoglio di soluzioni per la resilienza delle identità per supportare Okta; l’accesso anticipato dovrebbe avere inizio ad aprile 2026.
  • L’identità è diventata uno dei principali vettori di attacco, con107 miliardi di dati relativi all’identità sono stati resi pubblici nel 2024eIl 57% degli attacchi informatici ha origine da credenziali compromesse.
  • The new capabilities can help provide automated, policy-driven protectionegranular, point-in-time recovery for critical Okta objectseconfigurations.
  • Backup data is stored in immutable, air-gapped storage to help safeguard identity environments from ransomwareeunauthorized changes.
  • The solution extends Commvault’s unified della resilienza delle identità platform across hybrid environmentsewill be priced on a per-user basis.

Identity has become the new frontline of cyber defense –ethe stakes have never been higher.

Today, Commvault is announcing the expansion of its della resilienza delle identità portfolio to include support for Okta, delivering automated protectionerapid recovery for one of the enterprise’s most critical control planes.Early Access is expected to begin in April 2026.

As credential theft accelerateseidentity exposures surge worldwide, organizations can no longer treat identity systems as simply another application.Identity is the gateway to everything – users, applications, APIs, automation,eincreasingly, AI agents.When identity fails, the business stops.

Perché la resilienza dell’identità è importante oggi

I numeri raccontano una realtà cruda:

The rapid growth of non-human, agentic,eAPI-based identities has dramatically expanded the attack surface.Meanwhile, hybrid cloud adoption, SaaS sprawl,eAI-enabled automation have elevated identity providers like Okta to mission-critical infrastructure.

While Okta is built on a resilient platform, when an identity provider is disrupted – whether due to human error, misconfiguration, ransomware, or malicious tampering – the consequences are rapid:

  • Gli utenti non possono accedere.
  • Le applicazioni non riescono ad autenticarsi.
  • I sistemi che generano ricavi subiscono una battuta d’arresto.
  • I servizi rivolti ai clienti vengono sospesi.

And yet, many enterprises still rely on manual scriptsead hoc processes to restore identity environments – increasing downtime, operational complexity,erisk.

That’s the gap Commvault is helping to close.

L’introduzione del recupero automatico dell’identità in Okta

Commvault’s expanded della resilienza delle identità capabilities can help provide automated protectionegranular recovery for critical Okta objectseconfigurations.

Rather than rebuilding entire environments after an incident, organizations can precisely restore what was impacted – quicklyeconfidently.

“Identity is the new cyber battleground, with most modern attacks targeting identity systems,” said Pranay Ahlawat, Chief TechnologyeAI Officer at Commvault.“By extending our della resilienza delle identità capabilities to Okta, we’re helping customers protect one of their most critical control planesehelping ensusre they can rapidly recover accessemaintain business continuity even in the face of disruption.”

Competenze chiave

Accelerated recovery from identity disruptions: Automated, policy-driven protection of critical Okta objects – including users, groups, applications,epolicies – can help organizations to restore access quickly following outages, operational mistakes, or cyber incidents.

Granular, point-in-time recovery: Can help precisely restore only deleted, misconfigured, or compromised objectsesettings.No full-environment rebuilds required.

Ransomware-resistant protection: Backup data is stored in Commvault-managed immutable, air-gapped storage isolated from production environments, helping safeguard identity data from ransomwareeunauthorized changes.

Streamlined, integrated recovery: Recover complex, interconnected identity systems through a unified workflow – helping reduce operational overheadesave valuable time during incidents.

Unified della resilienza delle identità platform: Support for Okta extends Commvault’s single-platform approachin contesti caratterizzati da identità ibride, contribuendo a garantire un’applicazione coerente delle politiche,governance,erecovery across providers.

Accesso anticipato in arrivo ad aprile 2026

Commvault’s della resilienza delle identità support for Okta is expected to be available through public Early Access in April 2026, with general availability planned for Summer 2026.

The solution will be offered globally as part of the Commvault Cloud Identity Resilience suiteepriced on a per-user basis.

If identity is now the enterprise control plane, resilience must extend to identity itself.With support for Okta, Commvault continues advancing unified resilience at enterprise scale – helping organizations recover faster, minimize disruption,estay operational in the face of escalating identity-driven cyber risk.

Learn more about della resilienza delle identità qui.Registrati oraper il nostro webinar Identità sotto attacco: riprenditi il controllo con Commvault Identity Resilience, ora compatibile con Okta.

Domande frequenti

Q: Why is della resilienza delle identità becoming a top priority for enterprises?
A: Identity systems now function as the enterprise control plane, governing access for users, applications, APIs,eAI agents.As credential thefteidentity-based attacks increase, disruptions to identity providers can immediately halt business operations.Protectingerecovering identity infrastructure has become mission-critical.

Q: What does Commvault’s support for Okta include?
A: The expanded capabilities help provide automated protectionegranular recovery for essential Okta objects such as users, groups, applications,epolicies.This will help organizations restore specific items impacted by outages, misconfigurations, or cyber incidents without rebuilding entire environments.

Q: How does granular, point-in-time recovery benefit security teams?
A: Instead of performing full-environment restores, teams can precisely recover only deleted or compromised objectsesettings.This approach helps reduce downtime, lower operational risk,eaccelerate restoration of normal access.

Q: How does Commvault protect identity data from ransomware?
A: Backup data is stored in immutable, air-gapped storage managed by Commvaulteisolated from production environments.This architecture helps safeguard identity configurations from ransomwareeunauthorized modifications.

Q: When will Okta support be available?
A: Public Early Access is expected to begin in April 2026, with general availability planned for Summer 2026.The offering will be available globally as part of the Commvault Cloud Identity Resilience suite.

Q: How does this expansion fit into Commvault’s broader resilience strategy?
A: Adding Okta support helps strengthen Commvault’s unified, single-platform approach to della resilienza delle identità across hybrid environments.It enables consistent governance, policy enforcement,erecovery workflows, helping organizations maintain business continuity even during identity-driven disruptions.

Katharine Colucci è Product Marketing Manager presso Commvault.


Blog correlati

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Periods of geopolitical instability, including the current conflict in the Middle East, can lead to an increase in cyber activity from both state‑linked groups and opportunistic threat actors. Government agencies and industry organizations have encouraged businesses to maintain a heightened security posture during this time.
At Commvault, we’re doing exactly that. We’ve elevated our internal awareness, tightened our operational discipline, and reinforced our resilience measures. Commvault also works with a trusted threat intelligence partner, con, per monitorare l’evoluzione dei rischi e definire la nostra strategia di sicurezza. Incoraggiamo i nostri clienti, partner e colleghi del settore ad adottare misure simili per rimanere informati e rafforzare i controlli informatici fondamentali.

Su cosa dovrebbero concentrarsi le organizzazioni in questo momento

1. Know when to shift into “heightened alert” mode

Have clear internal criteria for when to increase monitoring, limit non-essential changes on critical systems, or accelerate incident‑response readiness. These moves don’t need to be dramatic – they just need to be deliberate and well‑coordinated.

2. Rafforzare la disciplina in materia di identità e accesso

During periods of heightened regional tensions, many threat actor campaigns rely on compromising user accounts. Reinforce good hygiene: regular credential rotation, strong authentication, careful review of unusual login behavior, and prompt investigation of anything that looks out of place. For practical steps to reduce identity-related risk, see Commvault’s recent blog on Migliori pratiche in materia di sicurezza.

3. Prestare maggiore attenzione al perimetro esposto a Internet e all’accesso remoto

Threat actors often take advantage of internet‑facing systems or remote access tools during global flare‑ups. Ensure these systems are well‑maintained, updated, and monitored.

4. Prepararsi a possibili interruzioni del servizio

DDoS and hacktivism activity often spikes during regional conflicts. Talk with your service providers, understand your mitigation options, and rehearse your internal escalation and communications plan so you’re ready if availability becomes a target.

5. Dimostra la tua capacità di riprenderti rapidamente

In times of uncertainty, resilience matters as much as prevention. Ensure your critical data is backed up securely, stored in multiple forms and locations, and restorable on short notice. Practicing recovery is just as important as having the backups themselves.

6. Prestare attenzione alla disinformazione, all’ingegneria sociale e alle notizie false

Periods of conflict tend to bring surges in defacements, false breach or shutdown claims, and social‑media‑driven narratives. Treat sensational claims cautiously, verify impacts through trusted channels, report suspicious communications quickly, and maintain steady communication practices.

7. Tenersi aggiornati sulle raccomandazioni di fonti affidabili

Follow alerts and guidance from reputable government and industry bodies. These sources regularly highlight shifts in regional threat activity and recommend practical steps organizations can take to prepare. A few resources include: Avvisi sulla sicurezza informatica della CISA; UK NCSC Reports & Advisories; Avvisi di sicurezza del CERT-EU; and il National Vulnerability Database del NIST.


Stay ready, stay resilient

Cybersecurity during global instability is not about panic, it’s about posture. By staying informed, tightening foundational practices, and strengthening resilience, organizations can navigate turbulent periods with confidence.
If you’d like help reviewing your preparation or refining your approach, our team is here to support you.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza

  • Le strategie tradizionali di resilienza stanno cedendo di fronte alla portata,alla velocità e all’autonomia dei sistemi basati sull’intelligenza artificiale.
  • Gli attacchi ransomware industrializzati e quelli basati sull’IA prendono ora di mira i sistemi di backup,minando le fondamenta del processo di Recovery.
  • Le organizzazioni devono passare da team di sicurezza e Recovery operanti in modo isolato a un modello unificato e continuo denominato “operazioni di resilienza”.
  • La resilienza basata sull’IA richiede visibilità dei dati in tempo reale,rilevamento continuo delle minacce e un Recovery intelligente e pulito su larga scala.
  • Le piattaforme moderne consentono una Recovery rapida e verificata,aiutando le organizzazioni a evitare il compromesso tra Recovery veloce e Recovery sicura.

Mentre le organizzazioni si affrettano ad adottare l’IA,i CISO e i CIO stanno giungendo a una cruda consapevolezza: le strategie di resilienza che funzionavano per le infrastrutture tradizionali stanno fallendo. Sistemi che prima potevano riprendersi dagli attacchi in poche ore ora potrebbero impiegare giorni. Gli approcci di backup progettati per dati centralizzati potrebbero avere difficoltà con carichi di lavoro distribuiti tra cloud e piattaforme di IA. Nel frattempo,le minacce e le potenziali vulnerabilità crescono di giorno in giorno.,David Nowak,responsabile del Cyber Risk Service di Deloitte; Kent Meyer,amministratore delegato di Deloitte; e Shilpi Handa,vicedirettrice della ricerca di IDC per la sicurezza informatica nella regione META,si sono uniti a me per discutere di ciò che la resilienza operativa richiede effettivamente in termini di strategia,architettura e operazioni quotidiane.,Tim Zonca,vicepresidente del marketing di portafoglio presso Commvault,ha affrontato una questione urgente che i responsabili della sicurezza devono affrontare: come mantenere la resilienza quando l’IA cambia radicalmente le regole?

What Industrialized Ransomware and AI Mean for Resilience

CISOs and CIOs are under pressure. In spite of billions spent on cyber defense,nation-states and professional crime rings continue to reap ever larger payoffs from their victims. Ransomware-as-a-service has become widespread,and advanced AI automation is accelerating the industrialization of malware. By including backup systems in their attacks,adversaries are undermining the very foundation of resilience.

As attacks become more sophisticated,targets are becoming more vulnerable. AI is scaling faster than organizations can secure,with exponential data growth,fragmentation across environments,more complex supply chains,and autonomous systems operating with minimal oversight. AI agents and non-human identities now outnumber humans 80 to 1. When these systems make mistakes or expose vulnerabilities,the impact can cascade across interconnected business processes.

Breaches and failures are now almost inevitable; the only question is whether you can recover fast enough to keep your business running. For organizations using legacy systems that assume human-controlled systems,centralized data,and isolated failures,the answer may well be no.

Making Resilience Operational

As AI agents make decisions across the environment,including a significant number of errors,it’s no longer enough to focus on protecting infrastructure. Security leaders must now broaden their operational focus across three critical areas:

  • Garantire continuamente la sicurezza dei dati alla fonte e monitorare le anomalie.
  • Controllare le identità delle persone,delle entità non umane e dei dispositivi che accedono e utilizzano i dati in modo autonomo.
  • Garantire una Recovery prevedibile dei dati su vasta scala senza compromissioni o corruzioni.

Tradizionalmente,la sicurezza dei dati,la resilienza delle identità e il Recovery informatico hanno operato come discipline indipendenti,ciascuna con il proprio team,i propri strumenti,le proprie politiche e i propri requisiti. Questi silos lasciano vulnerabilità che gli aggressori possono sfruttare e rallentano il Recovery in caso di guasto dei sistemi di IA. Per colmare tali lacune,le organizzazioni devono unificare queste capacità in un ciclo continuo e automatizzato. Chiamiamo questo approccio“operazioni di resilienza” (ResOps).

ResOps comprende tre requisiti essenziali per la resilienza dell’IA:

  • Understanding your data landscape: Knowing where data lives,its sensitivity,who’s accessing it (including AI agents and non-human identities),and what policies govern that access in real time. For AI workloads,this extends to protections like LLM prompt governance to control how models access data.
  • Continuous threat detection: Automated systems that constantly monitor for anomalies,compromised identities,and data corruption. When AI systems are making thousands of autonomous decisions,you can’t wait for periodic security reviews.
  • Recovery intelligente: ripristino automatizzato e completo di intere applicazioni cloud-native e delle loro dipendenze. Per prevenire una nuova infezione,i team devono verificare l’integrità dei dati ed effettuare analisi forensi in un ambiente isolato e protetto prima di riportare i dati attendibili in produzione.

Come implementare il ResOps nella pratica

Per aiutare le aziende a passare al ResOps,Commvault ha introdottoCommvault Cloud Unity,la versione della piattaforma più significativa della nostra storia. È progettata per riunire tutte e tre le dimensioni della resilienza:

A next-generation architecture brings AI automation to all facets of data protection,la sicurezza dei dati,della resilienza delle identità,and recovery. For security and IT teams,the platform provides simplicity at scale with one experience,one policy engine,and one interface designed to protect data,predict threats,and accelerate clean recoveries.

As security leaders know all too well,recovering from the most recent backup minimizes data loss but risks restoring compromised data. Rolling back to a verified clean state may eliminate threats but means losing hours or days of business-critical transactions or AI model training.

With Commvault Cloud,il monitoraggio continuo delle minacce and verified clean recovery points help eliminate this forced choice. The platform architecture automatically maps dependencies across distributed systems,helps maintain immutable backups,and helps enable one-click restoration of entire environments. Recovery can be both fast and clean,helping minimize loss as well as risk.

See ResOps in action

Guarda il webinar completo on-demand to learn more about ResOps,explore the architecture and services of Commvault Cloud,and rethink your resilience strategy for the AI age.


FAQs

 Q: What is Resilience Operations (Res Ops)?

A: ResOps is an operating model that unifies la sicurezza dei dati,della resilienza delle identità,and recupero cyber into a continuous,automated discipline rather than treating them as separate IT functions. ResOps transforms resilience from a reactive response to incidents into an active practice that continuously understands data access patterns,helps detect threats and anomalies,and enables fast,intelligent recovery at scale.

Q: Why can’t traditional backup and recovery handle AI workloads?

A: Traditional backup tools were designed for centralized,human-controlled systems with isolated failures. AI workloads involve autonomous agents accessing distributed data across clouds and complex dependencies between microservices and containers,and they operate at a scale that manual processes can’t match.

When AI systems fail or are attacked,you need to recover not just data but entire application infrastructures with all their configurations,policies,and relationships – capabilities traditional backup tools lack.

Q: What does “unified resilience” mean in practice?

A: Unified resilience means bringing la sicurezza dei dati,identity management,and recupero cyber together under a single platform,policy engine,and operational model rather than managing them as separate functions with different teams and tools.

In practice,this provides a consistent approach to protect all workloads and data locations,automatically correlate security events with access patterns,and orchestrate comprehensive recovery that restores both data and the complete application infrastructure needed to use it.

Q: What’s the difference between cyber resilience and AI resilience?

A: Cyber resilience focuses on protecting infrastructure and recovering from security incidents,treating resilience as an operational state for confronting threats. AI resilience expands this to address challenges unique to AI-driven systems: autonomous agents making decisions with minimal oversight,exponential growth of data and non-human identities across environments,and cascading failures where problems in interconnected AI systems impact entire business operations rather than staying isolated.

Q: How does ransomware target backup systems?

A: Ransomware increasingly targets backup systems by exploiting compromised credentials with privileged access,moving laterally from production systems to connected backup repositories,or exploiting vulnerabilities in backup software itself. Modern ransomware families specifically hunt for backup infrastructure to encrypt or delete recovery points,preventing organizations from restoring clean data and maximizing pressure to pay ransom. This makes offline,immutable,or air-gapped backups essential for resilience.

Q: What is the clean vs. complete recovery dilemma?

A: The clean vs. complete recovery dilemma is the forced choice organizations face during incident response. You can recover from the most recent backup to minimize data loss but risk restoring compromised or corrupted data; or you can roll back to a verified clean state before the incident to eliminate threats but lose significant business-critical data. Traditional backup tools make organizations choose between completeness and safety,while modern resilience platforms aim to provide both simultaneously through il monitoraggio continuo delle minacce and verified recovery points.

Q: What is a cleanroom in recupero cyber?

A: A cleanroom in recupero cyber is an isolated,secure environment completely separated from production systems to help organizations safely test,validate,and analyze recovered data before restoring it to active use. Cleanrooms help enable forensic investigation of compromised systems,testing of recovery procedures,and verification that restored data is free from malware or corruption – all without risking reinfection of production environments or exposing sensitive data during analysis.

Sam Curcuruto è direttore del marketing di prodotto presso Commvault.


Blog correlatiRivedere la resilienza nell’era dell’IA

A CIO’s Perspective: Strengthening Business Resilience in the AI Era

Resilienza contro la macchina dell’intelligenza artificiale

Le innovazioni per Cleanroom Recovery consentono una nuova era nella resilienza informatica

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Punti di forza

  • “Instant restore” claims often break down at scale due to real-world I/O operations per second (IOPS), rehydration, and infrastructure constraints.
  • Il montaggio in tempo reale di grandi quantità di dati su uno storage di backup deduplicato può causare un crollo delle prestazioni, costringendo a un lento processo di reidratazione verso lo storage primario.
  • Le camere bianche consentono di svolgere in parallelo le indagini forensi e il ripristino delle attività aziendali, evitando tempi di inattività in sequenza causati da ritardi.
  • La compromissione dell’identità amplia il raggio d’azione dell’attacco, rendendo il Recovery isolato e il Recovery di Active Directory (AD) fondamentali per garantire la sicurezza delle operazioni.
  • I manuali operativi automatizzati per le camere bianche e i test ripetibili aiutano le organizzazioni a convalidare metriche di recupero reali prima che si verifichi una crisi.

Let’s start with a quick story about a “ransomware‑proof” environment that took 72 hours to recover, way beyond the organization’s expectations for recovery time objective. It is exactly the kind of situation where Commvault’s Recupero in Cleanroom could have helped turn a painful, three‑day outage into a faster, more controlled recovery with less risk.

Storia di guerra: Fisica contro Marketing

On Reddit, a user shared how the financial services firm they work for was hit by a breach. They assumed they had a “dream stack” for quick recovery (but can you really have a “dream stack” without Recupero in Cleanroom?): immutable backups, secure storage snapshots, and a modern hypervisor. The datasheets promised “instant mass restore,” yet the business sat offline for three days while everyone tried to drag their environment back to life.

The root cause was not that backups failed, but that the real‑world physics of rehydration, forensics, and identity were never tested at scale. The original poster mentioned that having access to a cleanroom environment would have sped up the process. Let’s dig into this further and address why.

Commvault’s Recupero in Cleanroom is designed to address exactly these weak points: It helps automate clean, isolated recovery into the cloud, validates data, and coordina la fase di Recovery in modo da allinearla all’effettivo svolgimento degli incidenti, not just how diagrams look on slides.

Problem 1: The Rehydration Trap

In the story, “live mounting” a handful of virtual machines (VMs) worked fine, but trying to live mount hundreds crushed the backup appliance. The random I/O running directly on deduplicated, compressed backup storage collapsed the IOPS, forcing the team to rehydrate everything back to primary Non-Volatile Memory Express at about 3 TB/hour for roughly 100 TB of data.

Commvault Recupero in Cleanroom helps recover workloads into an isolated Azure‑based cleanroom built on scalable cloud compute and storage instead of trying to run production at scale off a backup appliance.

This allows you to restore critical VMs into a purpose‑built recovery environment, use cloud elasticity to absorb I/O, and automate the recovery sequence so the right systems (identity, core apps, critical data) come up first without bottlenecking on a single backup target.

Problem 2: The Forensic Drag

In the audit, the tech stack was ready in about four hours, but legal delayed touching anything for 72 hours because they had no pre‑provisioned cleanroom. Without an isolated environment with zero routes back to production, the forensics team could not safely investigate while the business recovered, so everyone waited for the all-clear before starting any real restore.

Recupero in Cleanroom provides an on-demand, isolated recovery environment explicitly built for simultaneous recovery and forensic analysis. È possibile creare una camera bianca isolata su Azure in poche ore, recover systems into it, and let security and legal teams perform read‑only forensics and threat scanning while operations validates applications and prepares for cutover – dramatically shrinking “forensic drag” as a contributor to downtime.

Problem 3: Identity Blast Radius

The environment in the story had a single admin account with access to both the hypervisor and backup console, which meant if attackers pivoted that far, immutability could become just another setting they flipped off. Identity, not just data, was the real blast radius problem.

Recupero in Cleanroom is designed to help reduce dependency on the compromised production identity plane during recovery, allowing isolated access and planned support for AD restoration in the cleanroom.

Trasferendo i servizi di identità in una “cleanroom” isolata and using separate, least‑privilege access paths, you can help validate AD, help enforce proper authorizations, and help protect backup control planes from being trivially compromised by the same credentials that were used in production.

How Recupero in Cleanroom Would Change This Story

If this customer had used Recupero in Cleanroom, their recovery story could have been very different.

For organizations that already invest in “ransomware‑proof” stacks, the missing piece is often not more features but a strategia per le camere bianche that respects physics, identity, and legal reality. Commvault Recupero in Cleanroom is designed to close that gap and help turn recovery from a three‑day war story into a controlled, provable, and much faster operation.

Domande frequenti

Q: Why did the “instant mass restore” approach fail in the ransomware scenario?
A: While live mounting a few VMs worked, scaling to hundreds overwhelmed the backup appliance due to I/O constraints. Deduplicated and compressed backup storage is not designed to handle full production workloads at scale, leading to performance collapse and delayed recovery.

Q: What is the “rehydration trap” in disaster recovery?
A: The rehydration trap occurs when organizations must restore large volumes of compressed backup data back to primary storage before systems can operate normally. This process is limited by throughput rates, which can dramatically extend recovery times when dealing with tens or hundreds of terabytes.

Q: How does a cleanroom help reduce forensic-related downtime?
A: A cleanroom provides an isolated environment where forensic teams can safely investigate while IT simultaneously restores systems. This parallel approach helps eliminate long waiting periods for legal or security approval before beginning recovery efforts.

Q: Why is identity such a critical factor in ransomware recovery?
A: If attackers compromise administrative credentials tied to both production and backup systems, immutability controls may no longer provide protection. Isolated identity recovery and least-privilege access can help limit blast radius and support a safer restoration process.

Q: How does Recupero in Cleanroom help improve recovery orchestration?
A: Recupero in Cleanroom helps automates workload sequencing, cleanpoint validation, and cloud-based recovery infrastructure provisioning. This structured approach aligns recovery with how incidents actually unfold, helping organizations regain control faster and with greater confidence.

Q: What is the strategic lesson for organizations with “ransomware-proof” stacks?
A: Advanced features alone do not guarantee fast recovery. A strategia per le camere bianche that accounts for infrastructure physics, identity isolation, and legal realities helps enable organizations to turn theoretical resilience into measurable, repeatable recovery performance.

Nico Guerrera è Senior Solutions Marketing Manager presso Commvault.

Blog correlati

Recupero della foresta di Active Directory: Perché i metodi manuali non sono più praticabili

Test di recupero: Il pezzo mancante nella maggior parte dei programmi di resilienza informatica

Il vostro manuale moderno per una risposta rapida e un recupero pulito

Sbloccare la resilienza informatica: Il potere delle camere bianche

Why Recupero in Cleanroom and Cyber Testing are Critical for Cyber Resilience

More related posts


Cyber Resilience

Read more about Cyber Resilience