Skip to content

This codification of privacy is transforming how businesses are expected to operate. There is no more question of what happens when a business doesn’t invest in a cyber program and who’s responsible. Let’s take a quick look at what will shape this year.

Regulamentações de privacidade dos EUA entram em vigor: CCPA, NYDFS e SEC atualizam os requisitos

CCPA may be amended. Currently the CCPA has an open request for comment on how audits fit with CCPA. In addition, we will start seeing rulings in cases around CCPA showing what we can expect for the reality of losses from not complying. For those who want to keep track with us, Perkins Coie has a great rastreador.

NYDFS will likely be amended. Industry comments are under review. Once DFS makes its recommendations it will move through the legislation process. Notable takes:

    • “The CISO and the highest-ranking officer of the covered entities are both required to sign a certificate of compliance, and notice of compliance must be delivered annually to the NYDFS.” – Morgan Lewis.
    • Isso vai além de uma lei de privacidade; abrange também a resiliência dos negócios e a segurança das operações

The SEC wants their new rules in place ASAP. This includes provisions for Cyber Security reporting requirements alongside considering rules requiring adoption of standard practices. As with all federal rules, this one may take some time. Other provisions, notably around carbon footprint reporting, seem to be causing friction. We will see if the SEC makes their timeline.

$100 Million penalty for BIPA violations. In 2022, we saw cases relating to the Louisiana BIPA come to a close with significant penalties being doled out. The rubber is meeting the road, and liabilities are a reality. Read more at Data Protection Report.

Por que os líderes executivos devem priorizar a especialização em segurança cibernética

Com esse forte impulso legislativo, as responsabilidades legais já são uma realidade. Os líderes executivos não podem mais ignorar as recomendações das equipes de segurança. A verdade é que a maioria das empresas não está preparada. Um trecho da revista Forbes ilustra isso perfeitamente:

“Our analysis showed that only 51% of Fortune 100 companies have a director on their boards with relevant cybersecurity experience. The situation in the Fortune 200 and 500 is more concerning: only 9% have cyber-savvy directors. Worse still are the companies in the Russell 3000 smaller than those in the Fortune 500: only 8% have cyber directors. There is a total shortage of 2,724 directors with cybersecurity expertise across all Russell 3000 companies.” –Forbes

To be successful in filling these positions, security leaders will need to have an opinion on what’s changing from a legal perspective, how that impacts business strategy, and how the business creates opportunity in markets with changing regulations.

Em resumo, os CISOs precisam fazer parte de todas as discussões estratégicas no nível da diretoria. Um CISO ativo pode, de fato, ser uma vantagem competitiva. Esses líderes ativos compreenderão os dados da empresa, saberão como utilizá-los para obter vantagens no mercado e enfrentarão os novos desafios regulatórios. As empresas que conseguirem se antecipar às mudanças no ambiente regulatório obterão maior retorno. As empresas que encararem a conformidade como apenas mais um item a ser marcado em uma lista ficarão para trás.

Adherence to compliance regulations is critical to your business’s operations, but it doesn’t have to consume an outsized portion of your resources. Let Clumio help automate compliance and simplify management while reducing your data protection costs. Contact us for a customized consultation.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

The past year has been amazing – our data protection portfolio has won many accolades of technology leadership from industry analysts like Gartner, Forrester and GigaOm. These wins are no doubt driven by our relentless passion to protect our customers’ data in a difficult world and our fundamental belief that continuous customer collaboration is key to pragmatic innovation.

The next chapter of our 26-year journey of customer-driven innovation is now here – we are excited to announce the General Availability of Commvault Platform Release 2023! Commvault PR 2023 introduces several new features and additions to strengthen our customers’ security posture, deepen our rich integration with all major hyperscalers and introduce more smart savings through operational efficiencies.
Centenas de clientes já se beneficiaram desses novos recursos durante a fase de pré-visualização tecnológica, que teve início em 15 de dezembro de 2022.

Harnessing the power of multi-cloud

What differentiates our approach to the ecosystem – and yes, we continue to support the broadest ecosystem when it comes to data protection – is how our integrations are seamlessly built-in and not just clumsily bolted on for a quick mention. Deeper the integrations, greater the synergies enjoyed by our customers.

O Commvault PR 2023 traz novas integrações avançadas para facilitar aos nossos clientes a proteção de seus dados no Microsoft Azure, na AWS Cloud, na Google Cloud e na Oracle Cloud Infrastructure.

Take, for instance, our new integration with Microsoft Azure Restore Points. We worked closely with Microsoft to be the first data protection platform to support Azure Restore Points. While Azure has had incremental snapshot capabilities, this new integration allows for application consistency across disks, while reducing costs with the option to use more cost-efficient storage tiers for backups. Commvault PR 2023 also introduces integration with Amazon FSx for NetApp which brings the same on-premises NetApp ONTAP policy-based protection to AWS. The new release also introduces support for Oracle Cloud Infrastructure (OCI) infrequent access & combined storage tiers to help reduce costs for protecting your cloud data.

Enhancing data security

Our trusted approach to data protection is shaped by the fundamental customer direction that data security is an integral and inseparable component of data protection. Building on our robust multi-layered ransomware detection, protection and recovery framework, Commvault PR 2023 introduces new integrations to drive data protection insights into the broader security ecosystem.

An important aspect of data protection is to leverage data awareness to proactively alert IT teams when threats arise. Commvault PR 2023 introduces a new Security Information and Event Management (SIEM) connector that makes it easy to feed alerts, events, and audit data to other platforms through webhooks APIs or even Syslog. Leveraging standard protocols ensures we can work with virtually any SIEM or event management system giving security teams better visibility to anomalies and threats in their data. 

Driving smart savings

With the uncertainty of a global recession looming, customers in every industry are looking to optimize costs in their budgets to make up for the increased spending for security and mission-critical areas. We are continuing to help provide options to lower the cost for data

Novos recursos que permitem utilizar snapshots de região única em vez de snapshots multirregionais no GCP podem reduzir em 30% o custo dos recursos de backup. Às vezes, otimizar custos é tão simples quanto reduzir o tempo necessário para proteger os aplicativos.

Nossas otimizações para o Hadoop, que utilizam o snapdiff, podem reduzir o tempo de varreduras de backup — que antes levavam horas — para apenas alguns minutos, graças às melhorias na forma como verificamos os blocos alterados.

These are just a few of the amazing features we have in Platform Release 2023. You can learn about more of the latest features in our What’s New page for Platform Releases. Conecte-se with our product management team and others in our comunidades for all the latest news and release information. 

Join us live on March 8th, 2023 at our Platform Release 2023 customer webinar.  Register here

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

O Dia Internacional das Mulheres e Meninas na Ciência de 2023 será comemorado no sábado, 11 de fevereiro, e representa uma oportunidade para promover o acesso e a participação plenos e em igualdade das mulheres nas áreas de Ciência, Tecnologia, Engenharia e Matemática (STEM).

Conversamos com duas líderes incríveis e inspiradoras da Commvault, a diretora de tecnologia de campo (CTO) Vidya Shankaran e a diretora de experiência do usuário Parisa Bazl, para conhecer suas opiniões sobre diversos temas, incluindo:

  • Por que uma minoria de mulheres segue carreira nas áreas de Ciência, Tecnologia, Engenharia e Matemática (STEM),
  • Como a diversidade de perspectivas pode ser um grande trunfo em suas funções e
  • Que conselho elas dariam às versões de si mesmas aos 18 anos.
  • Heróis pessoais

Why is marking the International Day of Women and Girls in Science important?

Vidya

Como mãe de uma filha que estuda em uma escola de ensino médio com foco em ciências e engenharia, sei o quanto é importante conscientizar sobre a necessidade da igualdade de gênero e promover o empoderamento e o avanço de mulheres e meninas nas áreas de ciência, tecnologia, engenharia e matemática (STEM).

By celebrating this day, it serves as a constant reminder for all to work towards removing the barriers that prevent women and girls from participating – this helps foster a more inclusive and innovative scientific community and a better future for all.

O dia reconhece as importantes contribuições das mulheres e meninas nessas áreas e incentiva mais meninas e mulheres a seguirem carreiras nas áreas de Ciência, Tecnologia, Engenharia e Matemática (STEM).

Parisa

Celebrating this day is a way to remind ourselves of how far we’ve come and the distance we still need to go. While achieving gender equality in the STEM field is an uphill battle, our progress is evidence that it is possible and we will get there. This day is also a reminder of the benefits of having diversity in technology since so many critical, fun, and interesting things — from WiFi to dating apps – had their groundwork laid by women.

Why do you think women earn STEM degrees at half the rate of men – how can we help address this?

Vidya

Despite the fact that women have had a significant role to play in the progress of science and technology, they have not received the same levels of recognition as their male colleagues is an issue that transcends centuries. 

I would not necessarily to ascribe it to lack of female role models in STEM – there are many unsung “heroes” – but rather to the gender stereotypes and societal expectations that science is a “male” field. This manifests in the form of insufficient support for work-life balance that women and girls encounter compared to their male counterparts.

Thankfully, it is not irreparable or beyond redemption yet – there are many things we are already doing today and should continue doing and maybe even accelerate.

Promover modelos femininos nas áreas de Ciência, Tecnologia, Engenharia e Matemática (STEM) por meio da cobertura da mídia e destacar as conquistas de mulheres bem-sucedidas na ciência é fundamental, pois isso tem o poder de incentivar as meninas a se interessarem pela ciência desde cedo.

Acima de tudo, é fundamental que continuemos a oferecer ambientes favoráveis na educação e no local de trabalho, como programas de mentoria e atividades de divulgação. Oferecer condições flexíveis de trabalho garante que as mulheres continuem motivadas a seguir suas carreiras nas áreas de Ciência, Tecnologia, Engenharia e Matemática (STEM). Por fim, fomentar uma cultura de diversidade e inclusão nas áreas STEM e promover a equidade e a igualdade de oportunidades na contratação, na promoção e na remuneração são aspectos essenciais para melhorar a integração e a retenção de mulheres e meninas nas carreiras STEM.

Parisa

Muitas mulheres crescem com a percepção equivocada de que as áreas de Ciência, Tecnologia, Engenharia e Matemática (STEM) são um campo que valoriza os pontos fortes estereotipicamente masculinos, e nem sempre contamos com os sistemas de apoio social adequados para lidar com esses sentimentos de inadequação e falta de confiança. A tecnologia é frequentemente associada a software, mas, na verdade, trata-se muito mais de pessoas. Ao destacar os aspectos humanos dessa disciplina, podemos incentivar mais mulheres a perceberem como suas origens, perspectivas e habilidades únicas servirão como um ponto forte ao buscarem formação e carreiras nas áreas de STEM.

What can being a woman bring to your roles of field Chief Technology Officer (Vidya) and Director of User Experience (Parisa)

Vidya

In my role, which is technology evangelism with our customers and partners, in order deliver this role successfully, it requires empathy, emotional intelligence, respect for all cultures and obviously, understanding of technology. As a woman it does require a lot more effort and perseverance to get to and keep my “seat at the table”, but it is not without the support of all men and women around me.

Também tenho observado um aumento no número de homens que são aliados, os quais têm sido fundamentais para promover a aceitação, o incentivo e o apoio às mulheres na área de tecnologia. Esses homens são, invariavelmente, pais ou irmãos de mulheres e meninas que atuam nas áreas de Ciência, Tecnologia, Engenharia e Matemática (STEM) e estão cientes dos desafios que as mulheres e meninas enfrentam, além de se sentirem felizes em contribuir para a remoção desses obstáculos. Essa é, sem dúvida, uma mudança na direção certa.

Parisa

Working in a field where I’ve historically been at a disadvantage means that I’ve cultivated skills which not only help me navigate the field, but also do my job very well. I have had to pay attention to the smallest details, ask incisive questions, and listen extremely closely in order to best position myself for success. These are skills that make me a better advocate for users, since great UX is built on our ability to pay attention to what their users are saying in order to piece together the optimal solutions. In addition, being an outsider within the field of technology also makes me much more conscientious of inclusivity, and how everything from the way in which my team operates down to the interface that is designed needs to be intentional about creating equitable access and success.

What advice would you give to your 18-year-old self, moving into technology?

Vidya

Eu diria: não desista, porque as coisas vão melhorar .

But again, the kind of pressure we put on ourselves to deliver our best day after day, I would only say to take slow down and “smell the roses” – that we are not expected to know everything or have all the answers and it is okay to say, “I don’t know”.  After graduating with a degree in Chemical Engineering when I moved into Information technology, it felt like a personal failure, but I would tell me 18-yo self that it is okay to fail – “Failure” is a verb not a noun.

Parisa

Eu aconselharia meu eu de 18 anos, que nunca planejou seguir a carreira de tecnologia, a pensar nisso além da simples engenharia. Como mencionei anteriormente, a tecnologia tem muito mais a ver com pessoas do que com software. Se nos concentrarmos em nossa capacidade de nos conectar com as pessoas e cultivar a compreensão, isso nos torna muito mais valiosos e nosso impacto, muito mais positivo.

Personal Heroes – Who do you admire?

Vidya

Tenho muito respeito por Indra Nooyi, ex-CEO da PepsiCo, e procuro todas as oportunidades para aprender com suas experiências.

Parisa

I’m a big fan of Barack Obama. He is someone who also had to navigate a system that was not predisposed to his success, and he leveraged his unique skillset, background, and point of view to inspire and connect with millions of people.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

It sometimes feels like we are living in the age of the reboot.  If you’re a fan of the hit TV show “That 70’s Show,” you know that it’s all about a group of friends navigating the challenges of adolescence in the 1970s and that it’s been rebooted (and updated to the 90s) on a popular streaming service. 

And it’s not alone.  From the good (Cobra Kai anyone?) to the not so popular (did anyone actually see the Knight Rider remake??) there is always an appetite for an update which reflects the current environment and challenges.

That sentiment can also be applied to your organization’s data management and protection strategy – to ensure it stays current and effective in an ever-changing world of emerging technologies and cyber threats.

Com um novo ano e uma nova perspectiva, veja se algum dos sinais abaixo faz sentido para você. Se for o caso, talvez este seja o momento ideal para elaborar um plano para renovar sua abordagem em relação aos dados na Era da Nuvem Moderna:

  • Outdated & mismatched technologies: Just like the characters on the show were stuck in the 1970s, your data management and protection strategy may be relying on a “frakenstack” of mismatched and outdated technologies that sprawled organically but are now stuck in time and are no longer effective in today’s modern multi-cloud world. It’s important to regularly review and update your technology strategy to ensure that your approach to data growth and retention is not only purposeful and effective, but also provides you powerful protection and controls from the best tools available.
  • Uncertainty around shared responsibility obligations with Cloud Providers and SaaS Applications: If you don’t have a solid understanding of what your obligations are to protect your data under the shared responsibility model, you could end up losing days, weeks, or even months of valuable insights in the event of a disaster situation. In the show, the characters often found themselves in sticky situations that could have been avoided with proper situational awareness & planning. The same is true for your organization’s off-prem data.
  • Insufficient access controls: Whether resulting from innocent human error, or malicious bad actors, your data management and protection measures can often be wide open to catastrophic incident if users have too large a sandbox to play in. Our crew of misfits in “That 70’s Show” often found themselves in trouble due to a lack of boundaries and rules. The same is true for your organization’s data. With proper access controls in place, your data is more protected, your risk profiler is smaller, and you can rest easy knowing that it’s that much harder to have a major incident due to unauthorized individual actions.
  • Lack of employee & org leader education: Just like the characters on the show needed guidance and direction, your employees and cross-functional partners need to be educated on best practices for data protection. Without proper education, your organization is at risk of data breaches and other cybersecurity threats. Do all of your cross-functional partners (HR, Sales, Operations, Dev Ops, etc.) understand the implications and limitations of native SaaS applications and cloud services? Do they have a trusted partner in the IT function to ensure that their workloads are secure and backed up to cover any gaps in the service provider’s shared responsibility model while simultaneously providing upline leadership a single view of all of their distributed corporate data across all platforms and form-factors?

Se algum desses sinais se aplicar à sua organização, é hora de pensar em atualizar sua estratégia de proteção de dados.

Just like “That 70’s Show” has stood the test of time, a solid data protection strategy can help your organization stay current and protect its sensitive information. Don’t get stuck in the past – take action to ensure your data is safe and secure.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Zero trust architecture is central to an organization’s security posture to mitigate cyberattacks, and the Defense Department recently released its Zero Trust Strategy and Roadmap1 on its plan to get the DOD to a Zero Trust architecture by 2027.2

A zero trust architecture provides the foundations for micro-segmentation of the IT landscape, access limited with the Least Privilege principle, and all communication to and between the micro-segments being authenticated, audited, and verified3. The underlying philosophy for zero trust is never assume trust, but continuously validate trust, so bad actors don’t get in. Companies, organizations and government agencies need to make sure that even users inside a network can’t do serious damage.

Flag Unusual Behavior

Os princípios do modelo “zero trust” garantem que o acesso do usuário seja continuamente validado e monitorado em termos de autenticação e autorização, ao mesmo tempo em que é constantemente auditado. A Commvault utiliza controles de segurança, como autenticação multifatorial para tarefas administrativas diárias, bloqueios de privacidade e criptografia de dados. O acesso do usuário pode ser compartimentado, negando explicitamente o acesso ao nível do CommCell, ao mesmo tempo em que se aplicam funções a grupos microsegmentados de recursos por meio de configurações multilocatárias. Os controles do modelo “zero trust” ajudam a limitar a movimentação lateral interna para evitar a perda de dados e o acesso não autorizado aos mesmos.

Apply Zero Trust Controls

A Commvault simplifica a aplicação de controles AAA do modelo “zero trust” por meio doPainel de Avaliação da Integridade da Segurança. O painel oferece uma visão unificada para identificar controles, destacar riscos potenciais no ambiente de backup e recomendar ações interativas para aplicar esses controles.

Add Layers of Security

Para ajudar a fortalecer a resiliência da sua infraestrutura de dados, aEstrutura de Cibersegurança do NISTse concentra em cinco pilares principais para um programa de cibersegurança bem-sucedido e holístico. A atenção a esses pilares pode ajudar sua organização a desenvolver uma estratégia abrangente de gestão de riscos. A Commvault incorporou esses pilares de segurança ao nosso software e às nossas políticas de proteção de dados, sem onerar a gestão com custos adicionais. A plataforma de proteção e gestão de dados da Commvault inclui cinco camadas de segurança:

Identificar 

Proteção

Monitorar

Responder

Recuperar

Nossa segurança em várias camadas consiste em conjuntos de recursos, diretrizes e práticas recomendadas para gerenciar os riscos de segurança cibernética e garantir que os dados estejam prontamente disponíveis. Ajudamos a proteger e isolar seus dados, oferecemos monitoramento proativo e alertas, além de possibilitar restaurações rápidas. Tecnologias avançadas baseadas em inteligência artificial e aprendizado de máquina, incluindo honeypots, permitem detectar e emitir alertas sobre possíveis ataques no momento em que eles ocorrem, para que você possa responder rapidamente. Ao manter seus backups protegidos e possibilitar a restauração dentro dos prazos estabelecidos nos seus Acordos de Nível de Serviço, você pode minimizar o impacto de um ataque de ransomware e retomar suas atividades imediatamente (além de evitar o pagamento de resgates caros).

Immutability

Protecting and isolating your backup copies is critical for data integrity and security. Therefore, we have taken an agnostic approach to immutability. With Commvault, you do not need special hardware or cloud storage accounts to lock backup data against ransomware threats. If you happen to have Write-Once, Read Many (WORM)-, object lock- or snapshot-supported hardware (which Commvault fully supports), you can still use Commvault’s built-in locking capabilities to complement and layer on top of existing security controls. Commvault’s ability to support layered defenses for securing data sets against ransomware ensures that your organization benefits from a sound cyber recovery-ready architecture. Here are some elements to include in your immutability architecture:

  •  Access locks to isolate copy store against ransomware
  • Imutabilidade com bloqueios de ciclo de vida para reduzir riscos, em equilíbrio com o impacto no consumo
  • Rede de isolamento por entrelaço de ar e controles
  • Governança de configuração para proteção contra alterações intencionais ou acidentais
  • Concurrent Recovery performance – reduce latency with due importance to speed and cost impact
  • Aplicação automática de patches para manter a infraestrutura atualizada, simplificando o gerenciamento e a manutenção da infraestrutura de proteção de dados
  • Alignment with the 3-2-1 data protection philosophy  (3 copies of data, 2 different media, 1 vaulted copy)

Learn more about Commvault’s immutable infrastructure architecture Saiba mais no SHIFT 2025.

Cyber Deception Technology

Embora garantir a continuidade dos negócios seja um elemento essencial de qualquer estratégia em várias camadas, uma postura de segurança robusta também inclui tecnologia de defesa proativa que identifica e combate ativamente ameaças desconhecidas e de dia zero.Metallic® ThreatWiseTMrevoluciona a proteção contra ransomware, combinando alertas e ações antecipadas sofisticadas com proteção abrangente de dados. Ele permite que empresas de todos os tamanhos neutralizem ataques silenciosos antes que causem danos, detectando e desviando os ataques de dia zero mais furtivos, que escapam à tecnologia de detecção convencional e contornam os controles de segurança.

A Ransomware Strategy

You need a plan to remain steadfast against ransomware. Beyond simply adhering to zero trust principles and hoping for the best, the ultimate solution can manage and substantially reduce the impact of a ransomware attack. It can reduce costs for your organization by utilizing one centralized management platform, so security teams don’t have multiple product points to log in and out of. It can increase the visibility of your data through a single landscape to minimize complexity for your teams. And finally, it can protect what matters most by providing the broadest workload coverage and rapid recovery capabilities through a unified approach. For all of this to happen, a solution must embrace Zero Loss Strategy.

Become Less Vulnerable

A realidade é que sua organização precisa estar preparada e tomar medidas proativas para proteger seus dados, além de trabalhar com um provedor que ofereça soluções de proteção e Recovery contra ransomware. Qual é o seu nível de preparação? Faça nossaavaliação de risco gratuitapara descobrir. Além disso, leia nossoeBooksobre “Compreensão das funções e responsabilidades da equipe no combate ao ransomware”.

References
1. Departamento de Defesa dos EUA (DOD), “Departamento de Defesa divulga estratégia e roteiro para o Zero Trust”, novembro de 2022
2. C. Todd Lopez, DOD News, “DOD divulga caminho para a segurança cibernética por meio da arquitetura Zero Trust”, novembro de 2022
3.Commvault, Vidya Shankaran, Ransomware Defense in Depth – Best Practices for Security and Backup Data Immutability, October 2021

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

I’m so proud to announce the inspiring Vaulters who just won our FY’23 Q3 CEO Living Our Values Awards. 

Here at Commvault, our four values – we connect, we inspire, we care, we deliver – are always top of mind! 

This week we hosted our quarterly internal Global Town Hall meeting and presented our CEO Living Our Values Awards. This quarterly awards program helps us globally recognize and celebrate our Vaulters for their incredible work as they live our values every day. 

I’m so proud to announce our FY’23 Q3 CEO Living Our Values Award winners:

Christina Manning
, Diretora de Operações Financeiras

Mathew Ericson
Gerente Sênior de Produto

Jason Gerrard
, Diretor de Engenharia de Vendas

Parisa Bazl
, Diretora de Desenvolvimento de Experiência do Usuário (UX)

Sam Hernandez
, Diretor de Gestão de Instalações


Todos esses vencedores são um exemplo inspirador e representam o que realmente significa ser um Vaulter!

To learn more about what it’s like to work at Commvault, check out our site de carreiras.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

O desafio atual dos registros de auditoria

One major challenge customers face with audit logs is that they’re not aggregated in a central location that is fully immutable. SaaS applications specifically tend to have their audit logs kept within the SaaS application itself, oftentimes with only a 90-day history.

Isso leva à criação de scripts complexos ou à exportação periódica de logs de cada aplicativo para um local centralizado, a fim de atender às metas corporativas de conformidade e segurança.

This is a heavy lift on IT departments, and with hundreds of applications under management in any environment, it’s oftentimes not feasible to accomplish this completely. 

Consolidando registros de auditoria com o AWS CloudTrail Lake

Com o lançamento do CloudTrail Lake, a AWS simplificou o gerenciamento de registros de auditoria provenientes de fontes diversas. O CloudTrail Lake é um data lake gerenciado de segurança e auditoria que permite que as organizações agreguem, armazenem de forma imutável e consultem eventos registrados pelo AWS CloudTrail.

This can be done across different regions and accounts – and is backed by a 7-year default retention policy to help you meet compliance requirements.

Os clientes podem importar e analisar eventos em um esquema compatível com o AWS CloudTraila partir do Clumio, bem como de outras fontes de terceiros e não pertencentes à AWS, para otimizar auditorias, investigações de segurança e resolução de problemas operacionais.

Segurança de dados mais simples com o Clumio e o AWS CloudTrail Lake

A AWS e a Clumio uniram forças para oferecer essa integração para o CloudTrail Lake, que permite simplificar e agilizar o processo de consolidação de dados de atividades.

Through the newly launchedPutAuditEvents API for AWS CloudTrail Lake, Clumio has created a simple integration to capture user activity information and events from your Clumio environment alongside the AWS systems you are protecting with Clumio.

Once the integration is enabled, you’ll be able to capture and store audit activity across various categories. This will allow you to easily answer many security and compliance-related questions across various categories such as:

  • Authentication– Was there a high volume of unsuccessful logins to the Clumio console, indicating a brute force entry attempt or an issue with your Single Sign On provider? 
  • User Management– When was a user added to the Development Organization in Clumio, and when were they given the backup Admin role?
  • Backups– When was a backup policy accidentally changed? This will help you quickly determine when a backup policy was changed or created to ensure you’re always meeting both long-term compliance requirements and maintaining any minimum required RPO’s (recovery point objectives).
  • Restores– Is someone browsing the CEO’s email history, or trying to recover Payroll information from a system backup? This activity is tracked even if a restore hasn’t been initiated.
  • S3 Protection Groups– When was a new S3 production bucket added to a protection group? Why was a bucket removed? 

Configuração e arquitetura dos logs do Clumio no AWS CloudTrail Lake

First, in Clumio, navigate directly to the Audit Report page. You’ll see a link to set up the integration in the upper right corner. You must have the Super Admin role to set up the integration.

Integração com o AWS CloudTrail

Na próxima tela, você verá um ID externo exclusivo para a sua integração com o CloudTrail. Copie esse valor e, em seguida, configuraremos a próxima etapa da integração diretamente na AWS.

After logging into the AWS Console, navigate to CloudTrail, where you will find a new Integrations section under Lake.Click on the Add Integration button to configure the Clumio integration.

You’ll first need to give a name to channel that Clumio will use to send the audit logs data through, and then selectClumioas the source.

Next, we will need a place to deliver the Clumio audit logs and determine how long you would like to get the logs. You can either use an existing event data store or create a new one for this integration.

Next, we’ll configure the resource policy which is what will provide Clumio with a secure way to send the audit log data across the channel. This is where we will paste in the external ID we copied from the Clumio interface.

Lastly, apply any tags you may want to add to the resource and select Add Integration.

The integration is now set up; however, we have one final step. We need to copy the Channel ARN value and bring it back to Clumio, so we can complete the setup.

Once you add the Channel ARN value, click on Connect to CloudTrail

Um evento inicial será enviado ao repositório de dados do CloudTrail Lake, permitindo que você verifique a conectividade. A partir daí, seus eventos de auditoria do Clumio serão enviados regularmente ao repositório de dados do CloudTrail Lake.

Additionally, you’ll be able to monitor the health of the integration at any time through the Audit Log report.

A seguir, está uma lista de todas as categorias de eventos de auditoria enviadas ao CloudTrail como parte dessa integração:

  • Autenticação
  • Fonte de dados
  • Integração automatizada de cargas de trabalho orientada por
  • Proteção S3
  • Restaurar
  • Backup
  • Usuários
  • Unidade Organizacional
  • Configuração do KMS
  • SSO/MFA
  • Modelo do CloudFormation

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

In the handful of months since I became Commvault’s first Chief Partner Officer, I’ve been reading the terrain, talking with our partners, and figuring out how we can better help them in the year to come. I’ve analyzed everything from program incentives to partner enablement and everything in between to plot our course. There is, however, one thing I didn’t consider. The intangible effect of being one of the coolest kids on the block.

For the 7th year in a row, Commvault has been named to CRN’s annual Cloud 100 list! Honoring the 100 Coolest Cloud Companies for 2023 across five key categories: infrastructure, monitoring and management, storage, software, and security, we rated among the Top 20 in the storage category based on CRN’s analysis.

To make the list, which is considered by most in the partner world as the trusted resource for solution providers looking for technology vendors best positioned to support their cloud product and services needs, Commvault had to prove its commitment to channel partners as well as demonstrate our innovation in the development of cloud-based technologies.

This wasn’t difficult for Commvault, as we’re a leader in data management, protecting data wherever it lives – whether on-prem, in the cloud, or in a hybrid cloud environment. We support the broadest range of workloads in the industry and most recently expandimos nossa proteção em nuvem para o Kubernetes, o que nos posicionou como “Outperformer” e “Líder” noGigaOm’s Radar for Kubernetes Data Protection.

“In today’s remote-facing enterprise environment, cloud services have become the critical component needed to build comprehensive and secure IT solutions,” said Blaine Raddon, CEO, The Channel Company. “The companies selected for this year’s Cloud 100 list have shown time and again that they support partners in the ever-evolving cloud computing business with state-of-the-art products and services. Our team commends those on this year’s list and looks forward to watching them drive positive change in the cloud domain throughout the year.”

CRN’s Cloud 100 list will be featured in the February 2023 issue of CRN magazine and online at www.crn.com/cloud100.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

A Semana da Privacidade de Dados é um evento anual que visa conscientizar sobre a importância da privacidade e da segurança dos dados. O objetivo da Semana da Privacidade de Dados é educar pessoas e organizações sobre a importância de proteger os dados pessoais e fornecer-lhes as ferramentas e os recursos necessários para que possam fazê-lo de forma eficaz.

We’ve brought together three opinion leaders to discuss the key data privacy challenges that face businesses around the world and how to overcome them.

Bill Mew, Data Privacy Champion and CEO of the Crisis Team is joined by Jakub Lewandowski – Global Data Governance Officer, Commvault and Thomas Bryant – Product Marketing Director, Commvault as they discuss;

  • Tendências e desafios atuais em privacidade e segurança de dados
  • Leis e regulamentações relacionadas à privacidade de dados, como o Regulamento Geral sobre a Proteção de Dados (RGPD) na União Europeia e a Lei de Privacidade do Consumidor da Califórnia (CCPA) nos Estados Unidos, bem como a DORA e a NIS2
  • Best Practices for protecting data – including a modern (and tested) data protection strategy and conducting regular risk assessments
  • The current state of Data Privacy policy and legislation compliance/ enforcement  

Saiba mais sobre esses temas em nossa série de posts do blog sobre a Semana da Privacidade de Dados, já disponível

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

O Dia Mundial da Privacidade, comemorado anualmente em 28 de janeiro, serve como um lembrete da importância de proteger os dados pessoais na era digital atual. À medida que a tecnologia avança e mais informações pessoais são compartilhadas online, indivíduos e organizações devem tomar medidas para proteger seus dados.

New regulations, such as DORA (Digital Operational Resiliency ACT), mandate that organizations create plans for risk management, incident reporting, and resilience testing. These regulations outline policies for data management, including encryption, data locality, and data lifecycles. A Gartner projeta, “by 2023, 65% of the world’s population will have its personal data covered under various privacy regulations, and companies need flexible solutions that can adapt to the multitude of legislation.” Navigating this complex environment can be challenging for both individuals and companies.

Data Privacy is protecting personal information and giving individuals control over how their data is collected, used, and stored.  On the other hand, data protection refers to the technical and organizational measures put in place to protect data (including personal data) from unauthorized access, use, alteration, or destruction. Data protection encompasses Data Privacy and other areas, including backup & recovery, disaster recovery, data security, and a host of other areas.

To help address that complexity, let’s spend some time reviewing the Top 10 topics to consider when managing Data Privacy and Data Protection.


1.Data Protection Strategy
2.Criptografia
3.Multi-Person Authentication
4.Armazenamento Imutável
5.Soberania de dados
6.Data Governance & Discovery
7.Classification of data
8.Retenção de dados
9. TrilhaResilience plan testing & incident response
10.Risk Assessment

1. Data Protection Strategy

Organizations should start by creating or updating a Data Privacy, Backup & Recovery, and Disaster Recovery plan as part of an overall data protection strategy. There are many facets to a reliable data protection plan and how it specifically relates to protecting the private data your customers have shared with your organization.

2. Encryption

A criptografia é um recurso essencial para a proteção de dados e de informações privadas. Permitir a criptografia de dados em repouso e em trânsito ajuda a impedir o acesso não autorizado a informações pessoais. Isso é especialmente importante para organizações que lidam com grandes volumes de dados privados, como prestadores de serviços de saúde e instituições financeiras. Os dados não residem mais apenas em nossos data centers corporativos, já que a maioria das organizações possui uma ou várias nuvens públicas com cargas de trabalho e dados armazenados nelas. Proteger os dados com criptografia durante todo o seu ciclo de vida ajuda a mitigar ameaças de possíveis invasores.

3. Multi-person authentication

Além de proteger os dados por meio de criptografia, as organizações devem proteger seus sistemas contra ataques maliciosos. O uso da autenticação por múltiplas pessoas (MPA) em seus sistemas de proteção de dados garante que tarefas críticas exijam várias aprovações de usuários pré-aprovados. Muitas vezes negligenciada, essa é uma das maneiras mais simples de impedir tarefas como a exfiltração ou a exclusão de dados.

4. Immutable Storage

O armazenamento imutável permite que os dados, sejam eles privados ou não, sejam gravados sem que possam ser modificados ou excluídos posteriormente. O fato de os dados não poderem ser adulterados ou alterados garante a manutenção da integridade dos dados. Os requisitos de armazenamento imutável estão se tornando rapidamente um elemento padrão das regulamentações de governança de dados, como o GDPR, a HIPAA e outras. Quando combinado com a MPA, é possível criar camadas de armazenamento de dados altamente seguras, ideais para o armazenamento de dados confidenciais e privados.

5. Data Sovereignty

Organizations should consider regulations surrounding private data storage when developing a data protection strategy. This includes the location of data storage and compliance with regulations regarding data sovereignty. For example, a cloud-based workload on GCP in Europe or containing EU citizens’ data must comply with EU regulations. Anywhere that private data may reside, even if temporary, may be required to be in a specific region under regulatory requirements. Commvault helps to address this concern in its latest release, allowing customers to select which specific region they will leverage for snapshot & data protection storage vs. multiple regions that cost more and may have different regulatory requirements.

6. Data Governance & Discovery

In a recent survey, 57% dos CISOs admit they don’t know where some or all their data is or how it is protected! As this amount of private data continues to grow, the sheer number of regulations expands exponentially, and we are confused about what and how we should protect our data.  As a result, organizations need to understand their data, where it is, and what is at risk.  Being able to prioritize data based on your organization’s policies, priorities, and applicable regulations is critical to protecting the data. You cannot protect what you don’t know about!

7. Classification of data

Saber quais dados existem e onde estão armazenados é apenas parte da solução. As organizações devem considerar quais dados são dados privados de clientes, essenciais para os negócios etc., em termos de sua importância para a sua empresa e para seus clientes. Proteger apenas os dados locais pode deixar de lado alguns dados críticos de clientes que estão armazenados em sua solução de CRM baseada em SaaS. Por falar nisso, você deve contar com algo além do seu fornecedor de SaaS ou mesmo dos seus provedores de nuvem IaaS para garantir a proteção dos seus dados. Eles podem oferecer alguns SLAs e um certo nível de redundância, mas isso não substitui um plano sólido de proteção de dados. Gerenciar a classificação de dados não é uma operação pontual, já que os dados crescem exponencialmente a cada ano.

8. Retention

It is paramount to know what data exists and how important it is, but how long does it stay relevant? This is a hard question to answer for most organizations and one that can be seen every year when buying ever-increasing storage systems to house corporate data. The ability to assign an expected lifespan to data can significantly impact your organization’s bottom line AND protect your customers’ private data. Having systems in place to automatically find, classify, and set retention will reduce the likelihood of data sprawl, reduce the amount of time to recover unused data, and reduce costs. If you are looking for a great place to start efficiently managing your governance, risk, and compliance, read through Commvault’s unique approach to o Gerenciamento Unificado de Dados.

9. Resilience plan testing & incident response

Resilience plan testing often referred to as a runbook, is an often-overlooked area of a data protection strategy. Creating or updating an outdated plan can take time and effort. Partnering with solution providers or strategic data protection companies with experience in creating a plan can significantly reduce the time it takes to get current. While it may be trivial to think runbooks are passe, I’ve found that when an actual DR event or ransomware attack hits, they are the GO-TO asset you want in your arsenal of tools. A regular cadence of updates creates an organizational posture that is ready to face data security threats head-on.

10.  Risk Assessment

As mentioned with runbook, consider working with strategic vendors to perform a risk assessment semi-annually or annually. Scheduled reviews can help build the muscle memory for a solid data protection and data privacy mindset. The benefit of working with well establish data protection & data privacy vendors is they are up to date on the latest security threats and mitigation strategies.

By implementing this list of considerations and routinely refreshing your resilience plan, you can be confident that personal information is secure and compliant with the latest privacy regulations. If you aren’t sure where to start but need help from a company that can answer all these questions.

A Commvault está aqui para ajudar! Estamos sempre adicionando novos recursos, incluindo nossas mais recentes melhorias em soberania regional de dados para instantâneos de backup, certificações do setor, recursos de armazenamento imutável e muito mais.

Head over to our community to saber mais or take a test drive today https://www.commvault.com/request-demo

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Happy 2023 Data Privacy Week!

Just as everyone started to get more or less cozy with the regulatory landscape in data privacy/protection and individuals and businesses learned to navigate the shallow waters of data subject requests, risk management, and impact assessments – BOOM – another tidal wave of regulatory requirements and new challenges rushed in!

2023 is the perfect moment to start internalizing new acronyms (get ready for #NIS2, #DORA, #DPDPB, #CPRA, #CCPA, #CPA, #CDPA, #UCPA, #VCDPA, #ADPPA, #PrivacyPenaltyBill) and legislative acts they stand for.

O objetivo principal das mudanças que estão por vir é fortalecer e aprimorar as medidas de segurança cibernética de diversas organizações e gerenciar os riscos cibernéticos em constante evolução de maneira mais eficaz.

Aqui está uma visão geral de alguns acontecimentos jurídicos em todo o mundo:

  • EU – Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2)
  • EU – Regulation on digital operational resilience for the financial sector (DORA)
  • US – State & Federal privacy laws
  • India – Digital Personal Data Protection Bill (DPDPB)
  • Australia – Privacy Penalty Bill & overhaul of the Privacy Act 1988

NIS2

According to ENISA, the general spending on cybersecurity is 41 % lower by organisations in the EU than by their US counterparts. With the arrival of NIS2, this ratio is expected to shift to cover this enormous gap at least partially. Conservative estimates are that NIS2 entry in force will translate into a ~22% increase in ICT spending over a 3–4-year period.

A NIS2 foi publicada pouco antes do fim do ano, e os Estados-Membros da UE têm agora 21 meses para transpor os requisitos e mecanismos descritos para a legislação nacional. A Diretiva NIS de 2016 — apesar de suas deficiências — serviu como base para o aumento das capacidades de segurança cibernética dos Estados-Membros. Agora, a NIS2 ampliará o escopo e a lista de organizações afetadas. Estima-se que até 160 mil organizações estarão sujeitas a essa nova legislação, incluindo prestadores de serviços digitais (plataformas e serviços de centros de dados), prestadores de redes e serviços de comunicações eletrônicas, os setores de manufatura e alimentício, além do setor público.


NIS2 aims to strengthen cybersecurity postures by, amongst other: improving cybersecurity governance, addressing the security of supply chains, streamlining reporting obligations (early warnings/shortened notification periods), and introducing more stringent supervisory measures and stricter enforcement requirements.

O que você pode fazer agora mesmo?

  • First, try to understand which obligations will apply to your organization and in which compliance bucket your organization will fall into: “Essential Entity,” “Important Entity,” or maybe “other.”
  • Em seguida, veja se é possível criar sinergias e aproveitar as medidas técnicas e organizacionais já implementadas durante esforços de conformidade anteriores (por exemplo, GDPR, NIS1 etc.)
  • Comece a procurar os parceiros certos que possam apoiar adequadamente seus esforços de conformidade. Envolva seus fornecedores na discussão da abordagem que melhor se adapte à sua organização.
  • Por último, mas não menos importante, inicie o planejamento para um aumento nos gastos a fim de sanar quaisquer lacunas remanescentes. O descumprimento pode resultar em multas administrativas de até 10 milhões de euros ou até 2% do faturamento anual total mundial da organização.


DORA

DORA aims to achieve “a high common level of digital operational resilience,” mitigating cyber threats and ensuring resilient operations across the EU financial sector. It will become directly applicable from Jan 17th, 2025. It will impact the financial sector (banks, insurance companies, investment firms) and its ICT providers (i.e., cloud platforms) – roughly around 22 000 organizations.

Os novos requisitos impostos pela DORA se resumirão, na prática, à revisão e atualização das práticas de gestão de riscos. Os clientes do setor financeiro precisarão transferir o máximo possível de riscos regulatórios para os provedores de TIC ou adotar diferentes estratégias de mitigação de riscos. De qualquer forma, os provedores de TIC precisarão garantir o cumprimento dos requisitos da DORA. Todo o setor também precisará reavaliar as relações contratuais com os fornecedores. A DORA incorporará requisitos para contratos entre empresas financeiras e seus principais provedores de TIC, incluindo o local onde os dados são processados, descrições dos acordos de nível de serviço, requisitos de relatórios, direitos de acesso e circunstâncias que levariam à rescisão do contrato.

In a separate post – Commvault’s Product Team will perform a more technical deep-dive into DORA’s requirements related to detection (art. 10), response and recovery (art. 11), and backup (art. 12).


US data privacy laws – CPRA/CCPA, CPA, CDPA, UCPA, VCDPA, ADPPA

As of January 1st, 2023, California Privacy Rights Act (CPRA) amendments to the California Consumer Privacy Act 2018 went into effect. Many temporary exemptions in place expire, imposing additional obligations on companies dealing with California residents’ personal information, e.g., regarding employment-related personal data, opt-out from selling personal information.

2023 is also the year when the Colorado Privacy Act (CPA), The Connecticut Data Privacy Act (CDPA), The Utah Consumer Privacy Act (UCPA), and The Virginia Consumer Data Privacy Act (VCDPA) will become effective. Legislative fragmentation risk is imminent and substantial, and this is the kind of risk that caused the European Union to harmonize the regulatory approach. Let us see whether the same will be true in 2023 in the case of the American Data Privacy and Protection Act (‘ADPPA’) – a proposal for a federal and general data privacy law.

India – DPDPB

Indian legislators plan to introduce a very ambitious Digital Personal Data Protection Bill (DPDPB) this year. When enacted, long-awaited legislation will undoubtedly impact all kinds of organizations due to India’s role as a tech powerhouse and a global outsourcing hub.

Australia – Privacy Penalty Bill & overhaul of the Privacy Act

Australian authorities announced yet another complete overhaul of the Privacy Act dated 1988. The current legislation was summarized as “out of date and not fit for purpose in the digital age.”

Enquanto isso, ainda em 2022, a Austrália aprovou o Projeto de Lei sobre Multas de Privacidade, que aumentou as sanções relacionadas à privacidade para níveis comparáveis às tendências introduzidas pelo GDPR (até 50 milhões de AUD) e ampliou os poderes regulatórios do Gabinete do Comissário de Informação da Austrália (OAIC) e da Autoridade Australiana de Comunicações e Mídia (ACMA).

Summary

O relógio implacável da conformidade acaba de recomeçar a correr. Equipes multifuncionais compostas por profissionais de TI, conformidade, privacidade, área jurídica e analistas de negócios dedicarão uma quantidade considerável de tempo à análise do impacto da enxurrada de mudanças legislativas que surgiram no final do ano passado e que se concretizarão ao longo de 2023.

Esteja ciente de que as novidades legislativas aqui apresentadas poderiam ser mais abrangentes. Você pode ter certeza, no entanto, de que elas se tornarão temas recorrentes de discussão não apenas em 2023, mas também nos próximos anos.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Como parte de uma série de três artigos para marcar o Dia da Privacidade de Dados de 2023 (veja os artigos complementares deJakub LewandowskieThomas Bryant ), Bill Mew argues that there is a real enforcement problem – it’s like the ‘Wild West’ out there.

Políticas, diretrizes e regras só são úteis se forem cumpridas, assim como regulamentos e leis não têm sentido sem fiscalização. O problema no âmbito da privacidade de dados e da segurança cibernética é que, nos casos em que as regras deveriam ser aplicadas, elas são frequentemente ignoradas; e, nos casos em que as leis foram aprovadas, é necessário haver mais fiscalização.

Os CISOs (Diretores de Segurança da Informação) têm uma tarefa ingrata. Os funcionários geralmente relutam em cumprir as medidas de higiene cibernética que um CISO busca impor, mas quando sua falta de disciplina resulta em uma violação, esses colegas são rápidos demais em atribuir a culpa ao CISO. Além disso, embora existam regulamentações caras e complexas a serem cumpridas e regras rígidas sobre o relato de violações, as autoridades, longe de ajudar a lidar com qualquer incidente ou capturar os verdadeiros criminosos, simplesmente utilizam os relatórios para avaliar a aplicação de multas.

Functional, Cultural Mismatch

Se questionados, a maioria dos funcionários concordaria que as ameaças cibernéticas são uma questão significativa, mas, em seu dia a dia, eles se concentram em métricas de ROI (retorno sobre o investimento) voltadas para a receita ou o lucro. Essas são as métricas com base nas quais o desempenho individual e da unidade é avaliado e que servem de base para as políticas de incentivo em toda a empresa.

The CISO is instead focused on return on risk (ROR). Based on the allocated budget and the organisation’s risk appetite, the CISO focuses on maximising security and minimising risk.

The mismatch between the CISO’s ROR orientation and just about everyone else’s ROI orientation can put the CISO at odds with the rest of the management team. They may not only become isolated (what I term CISOlation) but can also be a scapegoat when things go wrong – even when warnings are ignored.

Perverse regulatory incentives

In an accompanying article, Jakub Lewandowski [LINK] has explored the raft of new privacy and cybersecurity laws expected to add to a considerable regulatory burden. The problem is that regulation without enforcement is not just pointless but counter-productive. After all, only responsible companies will comply with these regulations, and for them, it represents a cost or compliance tax. Meanwhile, irresponsible ones often choose not to abide by the rules. If they believe that there is little or no risk of enforcement, then this is a cost-saving and risk-free source of competitive advantage.

A falta de conformidade é generalizada e tem origem nas altas esferas, com notícias frequentes sobre as BigTech sofrendo incidentes envolvendo dados ou sendo multadas. Essas multas parecem não estar surtindo efeito dissuasório, mas, ao contrário, estão sendo vistas como um custo adicional dos negócios pelas empresas BigTech e por muitas outras que tiveram a infelicidade de sofrer um incidente envolvendo dados.

Again, responsible firms that did their best to take reasonable measures but were unfortunately unable to prevent mistakes or attacks run the risk of being fined once they notify the local regulator. Meanwhile, irresponsible ones who choose not to comply will simply avoid reporting incidents and attempt to cover them up instead to avoid fines. Fines have, therefore, become more of a lagging indicator of misfortune for responsible firms rather than of misbehaviour by irresponsible ones.

Record of Regulatory Inaction

Most BigTech firms, attracted by a favourable tax regime, have opted to base their European headquarters in Ireland. The local regulator, DPC Ireland, is therefore responsible for ensuring that they comply with GDPR and other such regulations. Whether down to inadequate funding, reluctance to rock the boat, or simply out-gunned and out-lobbied by the BigTech firms, DPC Ireland has been seen as ineffective in holding them to account.

In one notable case, measures it failed to take against Facebook were eventually resolved in the European High Court under the Schrems I and Schrems II rulings. When it still failed to take action and apply these rulings, DPC Ireland was sanctioned by the European Parliament in a votação de 451 a 1. Quando novas pressões por parte de órgãos reguladores de toda a Europa a forçaram a agir, após um atraso de dois anos, a multa que aplicou ao Facebook foi tão baixa que teve de ser aumentada (dez vezes) por insistência dos demais órgãos reguladores.

The EU Ombudsman Emily O’Reilly eventually abrir uma investigação into the European Commission’s monitoring of how data protection rules are applied in Ireland. Eight months later, the Conselho Irlandês de Liberdades Civis (ICCL) criticou a UE for its continued failure to properly monitor Ireland’s GDPR enforcement while “the fundamental rights of all Europeans hang in the balance.” There are now moves afoot to strip Ireland of its responsibility for regulating the BigTech firms and centralise such enforcement instead.

Ineffective Global Policing

Meanwhile, the number and sophistication of cyber-attacks are increasing exponentially, as is the cost of remediation. The World Economic Forum (WEF) has recently not only called for more widespread use of “simulados de segurança cibernética” to test cybersecurity and incident response capabilities but is also championing the necessidade de regras globais to crack down on cybercrime.

Estima-se que os prejuízos causados por todas as formas de crime cibernético, incluindo os custos de Recovery e reparação, tenham totalizado US$ 3 trilhões em 2015 e US$ 6 trilhões em 2021, podendo chegar a US$ 10,5 trilhões por ano até 2025.

Cyber insurance isn’t the answer. Rapidly increasing premiums mean that it is out of reach to most buyers, but even those who can afford it often find it’s not worth it. At the same time, cyber insurance cannot be expected to cover systemic problems, and in any case, it has the perverse effect of potentially making bad problems even worse.

While almost all nations have signed up for United Nations agreements on combatting crime, including o crime cibernético, some nations turn a blind eye and instead provide safe havens for cybercriminals to operate from. While most o crime cibernético originates from countries like Russia, Iran, or North Korea, such activities are not confined to these rogue nations and continue closer to home. In addition, countries like China have significant espionage operations, and the United States is responsible for a great deal of global mass surveillance – all of which contravenes GDPR and a host of other laws.

We need to start with mandatory data breaches and cyber theft reporting. This has begun in the US with 2022’s a Lei de Notificação de Incidentes Cibernéticos para Infraestruturas Críticas, and in the EU with 2018’s a Diretiva sobre a Segurança das Redes e dos Sistemas de Informação. Still, there are also a série de outras regulamentações that mandate telecom payment services, medical device manufacturers, and critical infrastructure providers to report breaches.

Once we have better data on the problem, we can focus on improving international investigation, prosecution, and adjudication efficiency and effectiveness. The Escritório das Nações Unidas sobre Drogas e Crime is promoting a Cybercrime Programme which has the following aims:

  • Maior eficiência e eficácia na investigação, no julgamento e na resolução de casos de crimes cibernéticos, especialmente a exploração sexual infantil e o abuso infantil online, dentro de um sólido quadro de direitos humanos.
  • Resposta eficiente e eficaz a longo prazo de todo o governo ao crime cibernético, incluindo coordenação nacional, coleta de dados e marcos jurídicos eficazes, levando a uma resposta sustentável e a maior dissuasão.
  • Fortalecimento da comunicação nacional e internacional entre o governo, as autoridades de segurança pública e o setor privado, acompanhado de uma maior conscientização do público sobre os riscos do crime cibernético.

These are laudable goals. However, we are a long way from victims of crime being able to pick up the phone to police at the local, national, or international level with any expectation of getting either practical assistance or justice. The reality is that when it comes to cybercrime, aside from private sector incident response specialists, you’re on your own.

  • Os funcionários raramente seguem as normas de higiene cibernética de maneira adequada
  • Os órgãos reguladores não agem de forma proativa na identificação e no combate às infrações
  • Os criminosos estão se tornando cada vez mais ousados, agressivos e sofisticados
  • A polícia não consegue agir contra criminosos que operam a partir de refúgios
  • E os CISOs são sempre os bodes expiatórios quando as coisas dão errado

In this ‘Wild West’ environment, there isn’t any cavalry going to the rescue, so you are expected to be adequately armed and ready to defend yourself. Take hints from Thomas Bryant’s article and learn how to deal with it best. There is no substitute for getting your cybersecurity and incident response right.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

As part of our “Get to know your customers day” series, we’re taking a deeper look at Swinerton Inc, a large national construction company who is pursuing a cloud data management program to drive versatility, sustainability and to free up company resources.

IT Manager, Brandon Marrott gives an insight into Swinerton’s data modernization journey which includes cloud transformation and embracing SaaS flexibility.  He also describes operating a hybrid cloud environment through the need to retain a number of company data assets on prem and how Swinerton manages their entire data estate, including SaaS, with Commvault.

https://play.vidyard.com/U5fZTkcgxdb7v9we3WJghp

What does it mean to go to the cloud?

Selecting the right cloud transformation partner

https://play.vidyard.com/oUYbtkBhyzYRoVibhsaWGm
https://play.vidyard.com/zwLtwiwBcsPG15DN2u5L8L

Superando desafios e gerenciando com flexibilidade um conjunto crescente de dados SaaS


Faced with increased pressures, including an uncertain economic environment, IT teams are constantly finding ways to reduce costs or increase overall efficiency – all while supporting an evolving data environment.

Conheça mais exemplos de como os clientes da Commvault utilizam serviços modernos e inovadores de proteção de dados, incluindo nosso portfólio de DPaaS, o Metallic, para alcançar suas metas de transformação digitalhttps://www.commvault.com/digital-transformation-changes-everything-when-it-comes-to-data.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Desde o cumprimento de metas de sustentabilidade até a busca por eficiências, tudo isso enquanto apoiam a inovação, as equipes de TI têm muito a contribuir em 2023.

Confira nossa coleção das Prioridades de TI para Parceiros e Clientes em 2023 e compartilhe sua opinião conosco nas redes sociais.

Alan Atkinson, Chief Partner Officer – Concentration on highest value projects


2023 will continue to be challenging for companies from an economic perspective, especially those that are neither profitable nor public – leading many organizations to seek opportunities for cost reductions.

Inevitavelmente, haverá cortes e, em última instância, alguns fracassos, e os parceiros e clientes se mostrarão relutantes em adotar soluções de fornecedores que não tenham um caminho claro a seguir. Isso, combinado com diversas pressões inflacionárias, exigirá que os parceiros se concentrem em viabilizar os projetos de maior valor. Ransomware, migração para a nuvem e transformação digital continuarão sendo prioridades que receberão financiamento, enquanto outras áreas de negócios provavelmente perderão prioridade. A consolidação será fundamental para atender a essas necessidades. Parceiros e clientes não estarão buscando mais fornecedores, mas sim fornecedores que ofereçam mais soluções. Eles farão apostas maiores e mais concentradas, alinhando-se a fornecedores que ofereçam uma cobertura mais ampla e suporte em modelos de entrega com boa relação custo-benefício.

Darren Yablonski, Sr. Director, Sales Engineering, Canada, U.S. SLED, LATAM – Cyber Security, AI and Regulation


A top, if not the top IT priority for organizations in 2023 will most certainly be cybersecurity. Significant amounts of IT budget spend will be allocated and invested in technologies to prevent, detect and recover from inevitable cyberattacks not if, but when they occur. As cloud adoption in a SaaS (Software as a Service) model continues to proliferate the market, organizations will leverage solutions that provide proven piece of mind knowing their data is safe and recoverable in a timely fashion. Trust will be given to organizations that can clearly articulate cybersecurity best practices that align to a customer specific use case and objectives.

Continuing on the theme of cybersecurity, emerging technologies and trends will be inclusive of both AI (artificial intelligence) and automation. Organizations typically have predictable network and data usage patterns. As data continues to grow exponentially within the realm of the “internet of things” and those patterns deviate within a network or data repository, humans simply cannot keep track of anomalies in real time. As such, Security Information and Event Management (SIEM) solutions that collect, process, analyze and report threats in an expedited and accurate manner will continue to become more ubiquitous. Integration and adoption of such technologies within a zero-trust architecture will be of greater top of mind for CISO’s and security specialists as the years progress.

Conforme mencionado anteriormente, o consumo de dados continuará fluindo de aplicativos locais para aplicativos em nuvem, utilizando um modelo SaaS, dependendo do caso de uso. Soluções híbridas, tanto locais quanto baseadas em nuvem, continuarão a existir por vários anos, à medida que as empresas buscam equilibrar e garantir a imutabilidade dos dados e a velocidade de Recovery da maneira mais econômica possível. À medida que novas regulamentações específicas para práticas de segurança de dados continuam a evoluir, as soluções de gerenciamento de dados que oferecem um conjunto completo e abrangente de ferramentas para lidar com essas práticas também evoluirão. Em resumo, à medida que o cenário de ameaças em TI continua a crescer e a se tornar mais complexo, as organizações que buscam lidar com essa complexidade para os clientes se concentrarão no desenvolvimento de soluções de software mais diversificadas e abrangentes que simplifiquem a capacidade de recuperação e a geração de relatórios precisos, independentemente de onde os dados estejam armazenados.

Katharine Colucci, Associate Solutions Marketing Manager – Corporate Sustainability


The IT organization will take steps to lower the carbon footprint of its data to support corporate sustainability goals. Adopting more sustainable business practices has become a strategic priority of organizations worldwide as they become increasingly aware of how important sustainability efforts are to the success of the business. In fact, Gartner predicts that by 2025, 50% of CIOs will have performance metrics tied to the sustainability of the IT organization. IT teams will need to take steps to reduce the carbon footprint of their data through responsible data management practices, to support overall corporate sustainability goals. Responsible data management practices make it possible to control the total amount of data produced, thereby reducing the energy needed to create, store, manage and protect it.

Commvault supports our customers wherever they are on their sustainability journey, providing opportunities to mitigate their carbon footprint while reducing costs and maximizing the efficiency and security of their data management practices. To learn more about how Commvault is helping customers take a sustainable approach to intelligently manage data, visit Commvault.com/corporate-sustainability.

Gartner, você está pensando em termos muito limitados sobre tecnologia sustentável?, setembro de 2022

Jason Gerrard, Director, International Sales Engineering – AI/ML and Automation


À medida que a população envelhece progressivamente, torna-se cada vez mais difícil para as empresas recrutar novos talentos para o setor de TI. Como resultado, a lacuna de competências está se ampliando e as empresas estão tendo que depender menos de pessoas para impulsionar a inovação, o crescimento e a estabilidade, avançando em direção a um mundo mais automatizado, onde a tecnologia pode preencher essa lacuna.

Essa transformação já está bem avançada, e muitas organizações estão aproveitando ambientes, como a nuvem pública, para ajudá-las a automatizar muitos dos processos que, historicamente, exigiam a intervenção humana. As tecnologias de orquestração e automação podem contribuir significativamente para essa transição ao integrar inteligência artificial e aprendizado de máquina em suas soluções. Essas tecnologias foram amplamente adotadas ao longo do último ano para ajudar a preencher a lacuna de competências, mas, com os custos prestes a atingir níveis sem precedentes, elas continuarão a crescer em 2023 como uma solução para reduzir custos e, ao mesmo tempo, manter os sistemas em funcionamento.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

As the world enters the post pandemic period of heightened digital transformation, new challenges have emerged which businesses (and their data) will have to navigate.  In the face of increased economic pressure, digital transformation and cloud initiatives are set to focus on creating efficiencies through costs and resources.

To help organizations steer through these (potentially) choppy waters, we’ve gathered thoughts from some Commvault key opinion leaders.  

Param Kumarasamy, VP, Product Management
– Resilience and Cloud Native Technologies

Em 2023, a incerteza econômica continuará a crescer em meio a um aumento massivo de dados e a recursos de TI cada vez mais limitados. Isso fará com que as empresas deixem de lado as iniciativas de transformação e se concentrem na resiliência. Esperamos que os executivos adotem uma postura defensiva para lidar com problemas conhecidos e fazer mais com recursos limitados. As iniciativas de resiliência de TI aumentarão a adoção de tecnologias de IA/ML, como o automonitoramento e o gerenciamento de ativos de TI, bem como a automação e a orquestração de atividades de TI tanto no ambiente local quanto na nuvem.

Nos últimos anos, observamos um enorme crescimento nas iniciativas de nuvem híbrida e multinuvem nas empresas. Em 2023, esperamos que as organizações intensifiquem o uso de tecnologias nativas da nuvem. Da mesma forma que ocorreu com a transição do ambiente físico para a virtualização, veremos as empresas migrando das tecnologias de virtualização para adotar cada vez mais o Kubernetes, contêineres e DevOps em implantações locais e na nuvem.

Reza Morakabati, Chief Information Officer –
CIOs need a holistic approach to data protection

À medida que entramos em 2023, os CIOs precisarão adotar uma abordagem holística e contextual ao avaliar seu mapa de destinos de armazenamento de dados. As empresas podem adotar cegamente a nuvem ou o ambiente local com base em recomendações gerais, mas a decisão deve depender fortemente da forma como os dados serão utilizados.

CIOs need to focus on five main areas – scalability, flexibility, agility, security, and cost. Cloud for instance checks off many of these boxes, but could account for a significant portion of a CIO’s operating budget, whereas data center investments are mostly allocated to capital budgets. It is critical for CIOs to look at the full picture.

Matt Tyrer, Senior Solutions Marketing Manager
and Head of Competitive Intelligence – Data Diversification and Mobility 

The number of applications, clouds, platforms, utilities, tools, and various other data workloads and locations to run them is multiplying. Just to frame this a little let’s just look at one of the bigger providers out there, AWS.  Prior to AWS reInvent in late November 2022, they had over 200 applications and services within their catalog for customers to leverage and build on. They then introduced at their annual event another 50+ including many highly specialized databases and tools.

That’s a lot, and that’s just one vendor. With this growing diversification is my prediction, and one seconded by Gartner at their recent IT Infrastructure, Operations, and Cloud Strategies Conference in Las Vegas just a few weeks ago: 

The applications and workloads you are running today, and where you are running them, will not be the applications and workloads or places where you will be running them in tomorrow. 

The impact here is equally diverse.  

  • Skills Shortages: The constant shifting of data workloads will mean that most organizations will not have the in-house skills to keep up with the changing platforms and services they are depending on to drive their business forward and remain competitive. 
  • Data Protection/Management Challenges: It is already a daunting task ensuring that all of your data sources are not only protected but secured from the growing threats to them. Many businesses are stuck relying on multiple niche or point product solutions in order to tackle this challenge because there simply are not many options out there that can cover it ALL. Now imagine all of those data sources and applications moving and changing on a regular basis, most tools today just can’t keep up and this will lead to overlapping siloes adding complexity, cost, and overall risk to the business. 

To address this, businesses will be turning more and more to partners who provide the broadest possible spectrum of support for data protection and data management to ensure that as their data platforms change, their solutions not only can keep pace, but already provide the needed coverage. This will enable organizations to adapt and transform with significantly less friction as they don’t need to revisit data protection and management with each step. This also supports a number of other initiatives such as sustainability and ESG as it enables the consolidation of tools and reduction of infrastructure and consumption of other resources such as the power and water that fuel that infrastructure. 

Hope D’Amore, Solutions Marketing Manager
– Cloud-Native will become the norm

A transformação digital é necessária para manter um nível de inovação e competitividade no mercado. Somando-se a isso um cenário econômico turbulento e incerto, as empresas precisarão se concentrar na gestão de custos da nuvem para encontrar um equilíbrio entre os dois aspectos. Alguns podem pensar que a adoção de soluções nativas da nuvem ficaria em segundo plano durante esses tempos de incerteza, mas uma pesquisa recente da Forrester revela que 40% das empresas adotarão uma estratégia que prioriza as soluções nativas da nuvem em 2023. As organizações investirão mais em tecnologias nativas da nuvem, como o Kubernetes, para obter maior eficiência, em vez de continuar investindo em infraestrutura legada.

As the shift to cloud-native environments becomes the norm, security will continue to be top of mind and Commvault is here to help. We provide the most comprehensive and flexible portfolio of solutions for containers. Store, protect, and migrate your Kubernetes applications wherever they live across hybrid multi-cloud environments. To learn more about how Commvault data protection can increase efficiencies within your cloud-native environment, visit Commvault.com/containers.

Forrester, Previsões para 2023: Computação em nuvem, 27 de outubro de 2022

O que você acha? Quais são os planos da sua empresa nas áreas de transformação digital e nuvem? Você pretende investir mais em containerização este ano?

Compartilhe conosco nas redes sociais.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

Ao celebrarmos o Dr. Martin Luther King Jr. no dia 16 de janeiro, é fundamental destacar sua vida e seu legado como líder dos direitos civis neste início de 2023. Apesar de tantas conquistas alcançadas nos movimentos pela justiça racial e social, ainda temos um longo caminho a percorrer em direção à igualdade para todos.

This day is a meaningful opportunity to reflect on what it means to drive positive change through the power of connection – whether it’s in our local communities, with family and friends or in our workplaces. For Dr. King, and all those who worked alongside him, their commitment to equality and human rights became another moment in the world in how individuals can empower the collective.

At Commvault, we’re striving for a balance in what it means to connect meaningfully whether it is in person or remotely. The global pandemic helped us navigate how to extend those connections around the world in virtual spaces and do it successfully to have “courageous conversations” around various topics.

In my role, my goal is focused on empowering everyone to be a change agent towards moving the Commvault community forward– especially driving lasting and impactful change for all dimensions of diversity. In various workplaces, there are diversity, equity and inclusion (DE&I) efforts focused on improving the recruitment, retention, advancement and sense of belonging for those from diverse, unique backgrounds and cultures. Within Commvault, we have the Multi-Culture Employee Resource Group (ERG) focused on helping to create connections, education and awareness of our global cultures.

O Grupo de Representação de Diversidade Cultural (ERG) da Commvault está comprometido em oferecer um espaço de acolhimento, celebração e reflexão para os funcionários da Commvault que pertencem a grupos raciais sub-representados e para seus aliados na empresa. Buscamos conscientizar sobre a beleza, o valor e as contribuições de todas as origens raciais e étnicas.

As a company, we’re working towards that meaningful change and creating a sustainable foundation to support future efforts where all feel like they belong and can thrive. In honor of Dr. Martin Luther King, Jr., let’s continue to make a commitment to ourselves, others, and our broader global community that we will create space for positive change, more connections, and making our places in the world a more welcoming environment -– we’re in this together!

Clique aqui to learn more about our DE&I efforts at Commvault.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

To be successful in our roles as IT professionals, we frequently need to juggle a variety of responsibilities or “wear a lot of hats” – especially when it comes to the important matter of protecting a company’s great asset, its data. 

Vamos fazer uma pausa para explorar as características de cada função e como elas se relacionam com as responsabilidades de proteção de dados de um profissional de TI:

The baseball cap – Readiness

Antecipar e neutralizar possíveis ameaças à segurança da informação. Como líderes de TI, é nossa responsabilidade proteger os dados e antecipar quaisquer pontos fracos. Isso implica monitorar continuamente em busca de possíveis ameaças e preveni-las antes que se tornem um problema. A utilização de soluções como o cyber-deception permite um sistema de alerta precoce e oferece aquela proteção necessária antes que você seja pego de surpresa por um ataque.

The fedora – Flexibility

Modifying data protection tactics to fit the organization’s evolving needs. As IT executives, we must be ready to modify our approach to data protection to match the shifting requirements of our organization. The digital landscape is always changing. To remain ahead of potential dangers, this can entail putting new security processes into place or modifying current ones. Additionally, an IT leader must consider the latest technologies from cloud to containers and even possibly consider older tech when involved in mergers and acquisitions.  These scenarios all require a robust data protection solution that is scalable and flexible.  

The beret – Creativity

Inventing innovative ways to safeguard data in an increasingly complex digital environment. As IT executives, we must be able to think creatively and develop novel ways to safeguard data in a complicated digital environment. The cybercriminals are often a few steps ahead and might have more resources than your internal IT staff, the only way to combat this is to have elegant solutions to complex problems.  Nothing is more elegant than a beret…

The top hat – Decision Making

Making decisions that secure data and shield the organization from potential dangers while also ensuring that data protection and security are top organizational priorities. As the “top hat” of the company, it is our duty to make sure that data security and protection come first, to make choices that secure data, and to defend the company against any dangers. Our customers, employees, shareholders and even our peace of mind rely on knowing that IT leaders are securing the data and information of our company.  

Em conclusão, os líderes de TI têm muitas responsabilidades e precisam ter conhecimento em diversas áreas.

No Dia Nacional do Chapéu, vamos reservar um momento para reconhecer as diversas funções que eles desempenham e o papel fundamental que cumprem para garantir o funcionamento harmonioso e eficaz de nossas empresas.

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements

2022 was a BIG year for Cyber Security.  According to Cyber Security Hub, more than 4100 data breaches were publicly exposed with a number of high-profile attacks including Twitter, Optus and WhatsApp.

In today’s world, bad actors are well organized, informed and also persistent with the volume and speed of attacks increasing.  Their motives are changing, with data leakage, exfiltration, theft and restructure being top objectives causing data damage to now be the top concern of IT decision makers.

So what does 2023 hold? We’ve gathered thoughts from experts across Commvault to answer that very question. 

Industry-Wide Shift to Proactive, Early Threat Prevention 
– Matt Tyrer

In short, businesses will need and begin to implement proactive solutions to constantly monitor their environment to catch threats and enable early warning/response.  Bad guys are getting in, and we aren’t knowing about it early enough. 

From a cyber security and threat defence perspective, the industry today could be essentially divided in two approaches: 

  1. Preventative Measures: These vendors are your perimeter defence vendors like firewalls, anti-virus, SIEM/SOAR tools, along with other data loss prevention (DLP) and intrusion detection/prevention solutions. Even the newer identity access management (IAM) security vendors, who are adding key security functionality to control who can see what in your environment, can be grouped in here. They are all the locks on your doors and windows actively working to keep the bad guys out of the house so that they can’t even start the fire. 
  2. Reactive Measures: These tend to be the storage and most conventional backup vendors who are focused on protecting the data itself. Aiming to ensure it is available for recovery via table stakes features like immutability and anomaly detection (threat hunting) in the backups. These solutions are the sprinkler system and fire alarm – by the time they are triggered your house is already on fire and your only response is triage and disaster recovery. 

Don’t get me wrong, both of these are critical parts of a layered security posture and strategy but there is a gap which where early warning lives.  It’s the abilities to better respond when a breach occurs, while not waiting for data damage to be done before recovery is kickstarted.

This is why my prediction is an industry wide shift to more PROACTIVE warning systems, helping companies fill gaps between their preventive and reactionary toolsets.    

Thankfully, Commvault is ahead of this game with our ThreatWise cyber deception technology. Get started NOW on proactively defending your data. 

Rise in Managed Services Provider Spending
– Donna Namorato

The Institute of International Finance is predicting a global economic growth rate of just 1.2% in 2023, a level on par with 2009 when the world was only beginning its emergence from the from the financial crisis.1 Even with economic uncertainty looming, expect that cybersecurity spending will continue to rise but don’t be surprised if there is a decline in product and service spending.

E, mesmo com o aumento dos gastos com segurança cibernética, de acordo com uma pesquisa da Jefferies com diretores de TI (CIOs), 53% afirmaram que cortariam os gastos com ITSM. Se isso acontecer, eu esperaria ver um aumento nos gastos com Provedores de Serviços Gerenciados (MSPs). Os MSPs são especializados em segmentos específicos de TI e podem oferecer experiência especializada na área, já que atraem e retêm talentos, ao passo que as organizações têm dificuldade em fazer isso.

To remain vigilant against ransomware and data security, organizations must adopt a ransomware strategy and develop an plano de resposta a incidentes against bad actors. Incorporating a multilayered security framework is also vital to safeguard your data and reduce cybersecurity risk. And, when you need help, as Soluções de Readiness contra Ransomware da Commvault is available to assist you.

Industry and Platform Consolidation
– Brian Brockway, Global Chief Technology Officer


Atualmente, o cenário de segurança é bastante complexo. Existem inúmeras ferramentas disponíveis no mercado, e muitas empresas utilizam várias soluções para garantir proteção total. No entanto, temos observado que o setor começou a se consolidar, e essa tendência deve se manter até 2023. Todos os componentes precisam funcionar em conjunto para operar com máxima eficiência e oferecer as melhores chances de proteção. Consolidá-los em uma única plataforma será essencial para garantir que você aproveite ao máximo suas soluções, e ter um painel único de gerenciamento é fundamental para administrá-las. Especialmente à medida que os custos continuam a subir, as organizações devem garantir que estejam gastando cada centavo com sabedoria e obtendo o melhor retorno de cada aquisição.

No entanto, devido à enorme quantidade de ameaças que as empresas enfrentam, há também uma compreensão crescente de que nem tudo pode ser evitado, por mais excelentes que sejam suas soluções ou por mais eficaz que seja o gerenciamento delas. As organizações devem voltar seu foco para a resiliência. É quase inevitável agora que as empresas sejam atacadas em algum momento, mas o que realmente importa é a rapidez com que você consegue se recuperar disso. Backups regulares devem ser realizados para que, mesmo que o pior aconteça, o tempo de inatividade seja reduzido ao mínimo e as operações normais de negócios possam ser restauradas o mais rápido possível, com poucos danos duradouros.

“Inside-out” CyberSecurity, Tiger Teams and Managed Services
– Zack Brigman, Sr Product Marketing Manager

As ameaças cibernéticas continuam atingindo níveis recordes, tanto no número de invasões bem-sucedidas quanto nos danos causados por esses ataques. Olhando para 2023, os especialistas projetam que essas tendências continuarão a evoluir na direção errada, à medida que os adversários empregam novas táticas sofisticadas, as redes de hackers contratados continuam a se expandir e a lacuna de competências em segurança e TI se amplia. E, embora essas forças negativas apresentem desafios difíceis de superar, as organizações darão um grande salto no próximo ano para planejar, investir e amadurecer melhor suas disciplinas de segurança cibernética.

Prioritization

Breaches happen. But not all assets, systems, and data are created equal. Given that a small percentage of information assets carry the majority of business risk, progressive companies will begin employing an “inside-out” cybersecurity strategy. One that starts with hardening and securing their most critical assets first – then working toward the perimeter. While perimeter defences and preventing intrusion will (and should) remain a paramount focus, this risk-aligned approach enables the prioritization of defence strategies to mitigate risk for high-value assets and functions. This reshapes conventional “outside-in” approaches, making security investments more accessible and operational.

Tiger Teams

To better manage emerging threats and respond to risk, we will continue to see a rise in fusion teams (thanks Gartner for the term!) – merging IT, security, and operational stakeholders together to drive change. These blended teams help create new synergies by pairing complementary (but often siloed) groups and capacities to achieve common goals. These cross-functional teams increase visibility across the organization, discover and eliminate blind spots, and optimize investments in existing and new tools. While many mature organizations already leverage fusion teams today, 2023 will see a more widespread adoption of these functions to better identify risks, implement cyber response strategies, and manage threats.

Managed Services

As threats mount, businesses will continue to adopt managed service (MSP) and managed security service (MSSP) offerings to augment existing tools and tactics. This is particularly true of lean IT departments and those looking to enhance their security operations centers. Leveraging these managed providers will enable organizations to close the cyber security skills gap, tap into a consortium of specialized solutions, and scale their cyber practice without managing additional headcount or disparate solutions. 

Thanks to all our contributors! Stay tuned to see if their predictions come true by following Commvault and our DPaaS portfolio Metallic on Social Media. 

More related posts


Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era
Thumbnail_Blog-Bringing-Trust-to-CVE-2026

Demystifying SOC 2 Data Protection Requirements

Read more about Demystifying SOC 2 Data Protection Requirements