Skip to content

Note: This blog was originally published in October 2025 when Data Rooms was introduced. It has been updated to reflect the next evolution, Data Activate.

Pontos principais

  • Data Activate is part of Commvault’s next-generation AI capabilities – alongside O AI Protecteo AI Studio – anunciamos to help organizations activate AI safely, govern AI agents,ebuild agentic workflows from Commvault Cloud.
  • O Data Activate foi desenvolvido para que você possa transformar dados de backup em ativos confiáveis e prontos para IA, ao mesmo tempo em que ajuda a manter a governança e a conformidade.
  • A oferta une a proteção de dados e a ativação da IA sem criar novos riscos de segurança ou exigir outra platform.
  • Ele se integra a ecossistemas de IA existentes, como Microsoft Azure e Snowflake, usando padrões abertos, como Apache Parquet e Iceberg.
  • A governança integrada ajuda a viabilizar a curadoria, a classificação e o compartilhamento de dados protegidos dentro de uma arquitetura de confiança zero.
  • Ao ativar dados históricos, as organizações podem ajudar a acelerar a inovação em IA, análises e fluxos de trabalho de conformidade com segurança.

AI innovation depends on data – but not just any data. It depends on trusted, governed,eaccessible data. Yet for most enterprises, the data that could fuel AI lives deep within backups, scattered across environments,ewrapped in compliance constraints. That’s where Commvault’s Data Activate offering, previously known as Data Rooms, comes in.

Acelerando a IA com segurança

O Data Activate é um dos três recursos de IAanunciamos as part of its next-generation AI platform – alongside O AI Protecteo AI Studio. As organizations race to adopt AI, many are running into a fundamental challenge: their data is fragmentededifficult to use. According to a recent survey, 68% das organizações cite data silos as their top concern.

Commvault’s Data Activate offering helps transform backup data – one of the most completeetrusted datasets an organization owns – into AI-ready assets. Data Activate helps enterprises safely connect their data to AIeanalytics platforms, without creating new risks or complexity.

Unlike earlier bulk export approaches, Data Activate can regularly publish updated datasets, making it easier to keep AI pipelines in sync with the most current trusted data. Teams also can identifyeexclude sensitive data – such as personally identifiable information – before activating datasets for analytics or model development.

The Data Activate offering is not another AI platform. It’s the bridge between data protectionedata activation, designed to make your existing AI investments work fasteresafer. It does this by creating governed, policy-controlled “rooms” inside Commvault Cloud – spaces where data can be classified, curated,eshared with AIeanalytics tools without leaving the protection boundary.

Ouvindo os clientes: chega de Platform

We heard customers loudeclear: You don’t need another AI platform. You need a protected, simple way to use the data you already maintain – across the AI toolseecosystems you’ve already chosen.

That’s why Commvault built Data Activate to integrate with partners like Microsoft AzureeSnowflake using open-standard formats such as Apache ParqueteIceberg. This helps you keep your data portable, policy-compliant,eready for activation – wherever your AI strategy takes you.

Transformando a proteção de dados em ativação de dados

With Data Activate, authorized users can discover, classify,eprepare data directly from backup repositories – across on-premisesecloud environments. Built-in governance helps maintain control, allowing only approved datasets to be shared, with automated classification, sensitivity tagging, redaction,eaudit trails applied every step of the way.

Data Activate acts as a governed, policy-controlled workspace inside Commvault Cloud – where data can be curatedemade available to AI or analytics tools without leaving the protection boundary. This governed design provides a protected bridge between backup dataeactivation workflows, helping organizations unlock their information for innovation while being able to maintain complianceecontrol.

O Data Activate pode ajudar você a:

  • Accelerate insights: Quickly findeexport historical data in AI-friendly formats to train models or power analytics.
  • Simplify operations: Eliminate brittle ETL pipelines with automated data discoveryecuration.
  • Maintain compliance: Keep governance intact with policy-based controlsetraceability from backup to activation.

A confiança como base para uma IA responsável

Na pressa por adotar a IA, a confiança muitas vezes acaba sendo prejudicada. De acordo com umestudo, roughly three-quarters of surveyed IT leaders said that using AI could make their organizations more vulnerable to cyberattacks. That’s why Commvault built Data Activate within Commvault Cloud’s zero-trust architecture, complete with encryption, RBAC,ecompliance support.

By combining data protection, governance,eactivation in one platform, Commvault enables enterprises to accelerate AI innovation without compromising data security, compliance, or control.

Acelere a inovação sem aumentar os riscos

Commvault’s Data Activate offering helps organizations move faster by making data safely accessible to the tools that drive their business forward – from AI model training to analytics, eDiscovery,ecompliance support automation. Because when backup data becomes usable data, enterprises unlock years of historical intelligenceecontext that most AI models simply don’t have.

As Pranay Ahlawat, Commvault’s Chief TechnologyeAI Officer, said: “Organizations are beginning to realize that their historical data is more than just insurance – it’s a powerful, untapped strategic asset. With Commvault Data Activate, enterprises can confidently export their secondary dataeharness it with the AI platform of their choice to unlock new opportunities for intelligence, innovation,ebusiness growth.”

Por que isso é importante agora

Commvault’s Data Activate offering redefines what’s possible for enterprises that want to innovate responsibly. They make it possible to move from protecting data to activating data – safely, flexibly,eat scale.

In short: Commvault isn’t building another AI platform. We’re building the foundation that lets every AI platform work better – because when data is protected, trusted,eready for activation, innovation happens faster.


FAQs

Q: What is Commvault’s Data Activate offering?
A: Commvault Data Activate is a capability within Commvault Cloud that helps enterprises safely discover, classify,eactivate backup data for AIeanalytics. It supports open formats like Apache IcebergeParqueteis built on a zero-trust, governed architecture for controlled, self-service data access.

Q: How does Data Activate differ from other AI data solutions?
A: Most AI data prep tools work only on live or production data, creating complianceecost challenges. Data Activate works from backup data – data that’s already protectedegoverned – bringing a unique balance of accessibility, compliance support,etrust. It’s built into Commvault Cloud’s policy-controlled environment, so it’s part of a unified cyber resilience platform. Data Activate also regularly publishes updated datasets – rather than relying on one-time bulk exports – helping keep AI pipelines current without manual intervention.

Q: What benefits do organizations gain from using Data Activate?
A: Organizations can accelerate AIeanalytics insights, simplify data operations by reducing ETL complexity,emaintain compliance through automated classification, tagging,eauditing processes.

Q: How does Data Activate support data securityecompliance?
A: Data Activate operates within Commvault Cloud’s zero-trust architecture, applying classification, redaction,eaudit-friendly controls automatically. It helps maintain data privacy, traceability,ecompliance throughout the data lifecycle, aligning with internaleregulatory governance standards.

Q: What types of AI or analytics platforms can connect with Data Activate?
A: Data Activate integrates with leading cloudeAI partners such as Microsoft AzureeSnowflake, supporting open-standard data formats like Apache ParqueteIceberg for maximum flexibilityeportability.

Q: Why is this offering important for enterprises today?
A: As organizations accelerate AI adoption, Data Activate enables them to responsibly unlock the value of historical, protected data – fueling innovation while helping maintain trust, compliance,econtrol.

Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Pontos principais

  • A proliferação de agentes representa um risco de governança. À medida que os agentes de IA se multiplicam, a visibilidade fragmentada e os fluxos de trabalho de recuperação desconectados podem criar uma exposição operacional real.
  • O AI Protect unificará a detecção, o monitoramento e a recuperação orientada de agentes e suas dependências em todas as plataformas, em uma única experiência centrada no agente.
  • O AI Protect será projetado não apenas para avaliar se os ativos estão protegidos, mas também para ajudar a proteger a pilha de agentes e identificar riscos com base no que os agentes estão acessando e realizando.
  • AI Protect will be built on Commvault’s resilience platform – meaning recovery can be tied directly to agent-initiated impact across both data and environments.
  • AI Protect will be part of a broader platform that supports the AI resilience lifecycle – from safely activating data to governing, building, and recovering agentic workflows.

AI agents are no longer a future-state experiment. They’re running in production environments today – querying data, triggering workflows, and making decisions at machine speed. For most enterprises, that’s happening faster than governance frameworks can keep up.

The problem isn’t enthusiasm for AI. It’s the gap between deploying agents and actually knowing what those agents are doing, what data they’re touching, and what to do when something goes wrong. That gap is what Commvault AI Protect will be designed to close.

O problema da governança no cerne da IA agentiva

As organizations scale their AI investments, a new class of operational risk is emerging. AI agents aren’t just tools – they’re autonomous actors that can access sensitive data, interact with critical systems, and trigger cascading changes. Without a clear way to discover, monitor, and govern them, IT and security teams may be flying blind.

The symptoms are familiar:

  • Fragmented visibility: Hyperscaler APIs and observability tools provide partial, siloed views of agent activity. No single view connects agent behavior to data protection, risk, and recovery across platforms.
  • No protection context: Data protection teams can’t easily determine whether assets touched by AI agents are adequately covered or recoverable.
  • Weak risk signals: Agent activity can generate enormous telemetry, but without correlation across identity, access, and impact, distinguishing benign automation from high-risk behavior remains a manual effort.
  • Disconnected recovery: When agent-initiated changes cause problems, tracing the impact and initiating recovery can require manual correlation across tools, increasing time to resolution.

Apresentamos o Commvault AI Protect

AI Protect will be designed to offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents – across enterprise, SaaS, and cloud environments. It will extend Commvault’s existing discovery, protection, and recovery capabilities with agent-centric context, helping teams operate AI agents safely and recover quickly when issues arise.

Discover: A Single, Authoritative Agent Inventory

AI Protect will be designed to discover AI agents (and their dependencies) operating across connected environments on a recurring basis, helping maintain a unified, up-to-date inventory based on configurable discovery cadence. Each agent record will capture its execution environment and the data sources, models, configurations, applications, and infrastructure it interacts with. It will help provide a complete, cross-environment picture of what’s running and what it touches.

Protect: Closing Coverage Gaps Before They Become Incidents

AI agents interact with sensitive data and systems, but traditional protection tools don’t evaluate coverage in the context of agent behavior. AI Protect will be designed to surface protection status for every agent-touched asset – protected, partially protected, or not protected – and help identify gaps introduced by agent activity. Where gaps exist, it will offer recommended actions and protection workflows to enable teams to close them.

Monitor: Turning Telemetry Into Actionable Risk Signals

AI Protect will ingest agent activity from existing audit, event, and telemetry sources and present it in agent-centric context – not as raw logs. A time-ordered activity timeline will show what each agent has done and when, and risk signals will be automatically flagged and categorized when agents access sensitive data, interact with unprotected assets, or exhibit unusual patterns. This will help teams move from reactive triage to proactive awareness.

Recover: Guided Recovery Tied Directly to Agent Impact

When an agent-initiated change causes an issue, AI Protect will surface recovery point availability for impacted assets and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery will be scoped directly to the agent’s impact, not generic incidents, and every action will be time-stamped.

In addition, teams will be enabled to recover the full AI stack – not just the model, but the connected data, configurations, and underlying systems that support it – helping restore the entire environment to a known good state with a single, guided action.

Parte de uma visão mais ampla de resiliência em IA

O AI Protect será um dos três recursos anunciados pela Commvault como parte de uma platform mais ampla de resiliência com IA. DataData Activate enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Studio will enable enterprises to deploy ready-made agents and build custom ones – without writing code. Using a natural language–based Agent Builder, administrators will be able to describe operational intent in plain language, review the proposed workflow, refine it, and deploy it as a governed custom agent from a single interface. AI Studio will be designed to leverage Commvault’s MCP server and integrate with other enterprise applications via MCP, enabling workflows to extend smoothly across systems.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


FAQs

Q: What is Commvault AI Protect?

A: AI Protect is slated to be a governance and resilience solution for AI agents operating across enterprise, SaaS, and cloud environments. It will be designed to automatically discover agents and dependencies, surface protection gaps for the assets they touch, monitor and provide guided recovery workflows when agent-initiated changes cause issues.

Q: How will this be different from general AI observability or monitoring tools?

A: Most observability tools surface telemetry but stop short of connecting agent activity to data protection and recovery. AI Protect will be designed to correlate agent behavior with protection coverage and recovery readiness, and when something goes wrong, provide a guided path to help restore data, configurations, or systems impacted by agent activity.

Q: What environments will AI Protect support?

A: AI Protect will be designed to work across hyperscaler environments (AWS, Azure, Google Cloud), SaaS platforms, and internal enterprise systems – offering a unified, cross-environment view of agent activity and impact.

Q: How will AI Protect identify risk?

A: Risk signals will be derived by correlating agent activity with data access patterns, sensitivity of assets involved, and protection coverage. Rather than raw log analysis, AI Protect will present risk in agent-centric context – flagging specific agents and interactions that warrant attention, along with the reason they were flagged.

Q: How will recovery work?

A: AI Protect will surface recovery point availability for assets impacted by agent activity and guide teams through the appropriate recovery action – whether that’s restoring data, applications, or configurations. Recovery actions will be scoped to agent-initiated impact and will be fully auditable.

Q: How will AI Protect relate to AI Studio and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate governs how data is prepared and activated for AI use. AI Protect will govern agents operating in production. AI Studio will enable teams to build and manage custom agentic workflows. Together, they will form an end-to-end AI resilience lifecycle.

Teja Medasani is Principal Product Manager at Commvault and Vir Choksi is Principal Product Marketing Manager at Commvault.

 

More related posts


Commvault Cloud Compliance

Read more about Commvault Cloud Compliance

Pontos principais

  • AI Studio will be designed to bridge the gap between experimentation and scaled, production-grade AI automation.
  • The Agent Library will offer enterprises visibility of every default and custom agent in one place, with clear descriptions, categories, and enabled status.
  • The Agent Builder will make customization accessible. Natural-language inputs will be able to generate structured, reviewable workflows – no coding required, no black-box behavior.
  • All agent logic will be visible and explicitly saved before deployment, helping meet enterprise requirements for transparency and explainability.
  • AI Studio will be part of an end-to-end platform. Combined with Data Activate and AI Protect, it will be built to support the AI resilience lifecycle.

AI automation promises enormous operational value. But for most enterprises, moving from pilot to production can be harder than expected – especially when it comes to operational workflows like backup, recovery, and incident response. Governance concerns, lack of visibility, and the complexity of stitching together tools can often prevent AI from being used in real, day-to-day resilience operations.

What organizations need is a way to apply AI directly to these workflows – safely, with control, and in a way that fits how resilience teams actually operate. That’s what Commvault AI Studio will be designed for.

Why AI Automation Stalls at the Pilot Stage

McKinsey’s State of AI in 2025 report reveals that 88% of organizations use AI in at least one business function – yet only about one-third have reached scaled adoption beyond early pilots. The barriers are consistent across industries:

  • Limited visibility and control over which agents exist, what they do, and where they’re active – making it difficult for IT and data security teams to oversee operational workflows.
  • High friction to customize automation – teams can be forced to rely on manual scripting or external services to adapt built-in capabilities to real workflows, slowing adoption and limiting ROI.
  • Concerns about trust and governance – without transparency, explainability, and auditability, enterprises can’t confidently move agents from experimentation into production.

As a result, organizations either underutilize AI capabilities or rely on manual processes for tasks that could be automated safely – leaving real efficiency and resilience gains on the table.

Introducing Commvault AI Studio

AI Studio is slated to be Commvault’s answer to the governance-adoption gap. It aims to provide a centralized interface where enterprises can view and manage all agents, deploy ready-made agents, and build custom agents using a workflow-based approach that helps keep behavior visible, auditable, and under control.

Agent Library: A Clear View of Every Agent in Your Environment

OAgent Library will be the entry point to AI Studio. It will present a structured inventory of every agent available in the environment – both default agents built by Commvault and custom agents created by the customer – grouped by type and showing each agent’s name, category, description, and enabled status at a glance.

Default agents include Commvault’s foundational cyber resilience agents, such as Arlie Advisor, Arlie Data Sense, Arlie Recover, among others. The Agent Library will offer teams a single, authoritative view of their resilience agent ecosystem before taking any action.

Agent Management: Operational Control for Every Agent

Selecting any agent from the library will open a dedicated detail view that can help provide transparency into how that agent operates – its purpose, how it’s triggered, what data it uses as inputs, execution limits, and basic usage telemetry.

This view will also include records of agent activity and events. Following this, administrators can enable or disable the agent with a single action. This will apply consistently to both default and custom agents, so every agent in the environment can be subject to the same governance standard.

Agent Builder: From Plain-Language Intent to Governed Workflow

AI Studio’s Agent Builder will enable administrators to create custom agents by leveraging Commvault’s workflows and MCP server – without writing code.
Oexperience will start with natural language. An administrator will be able to describe what they want to automate – for example: “I need an agent that detects when storage or infrastructure issues are starting to impact backups and helps resolve them before they affect SLAs.”


Osystem will be designed to translate that intent into a structured agent configuration, including triggers, conditions, and actions, with optional AI-enabled steps from Arlie – such as Summarize, Generate Recommendation, or Draft Notification – available as explicit workflow steps.
Oadministrator will be able to review the proposed workflow, adjust it as needed – changing trigger frequency, specifying a distribution list, or reordering steps – and save it. The result will be an auditable custom agent that appears in the Agent Library and can be managed through Agent Management like any other agent.

Parte de uma visão mais ampla de resiliência em IA

AI Studio will be one of three capabilities Commvault announced as part of a broader AI resilience platform.Data Activate enables organizations to classify and curate data from protected backup copies and prepare governed datasets for use with LLMs and AI pipelines – publishing updates on a recurring schedule aligned with backup policies, in formats like Apache Iceberg and Parquet, with sensitive data filtered out before activation.

AI Protect will offer centralized visibility, protection context, risk evaluation, and guided recovery for AI agents operating across enterprise, SaaS, and cloud environments – helping teams operate agents confidently and recover quickly when something goes wrong.

Together, the three capabilities will cover the arc of AI resilience: helping safely activate trusted data, govern and recover agents in production, and build the agentic workflows operations actually require.


FAQs

Q: What is Commvault AI Studio?

A: AI Studio will be Commvault’s centralized platform for deploying, building, and managing AI agents. It will include an Agent Library for viewing all agents in the environment, Agent Management for operational control, and an Agent Builder for creating custom agents using workflow-based automation – all without writing code.

Q: Who will AI Studio be designed for?

A: AI Studio will be built for Commvault administrators and IT operators who want to automate operational tasks – like monitoring backup job failures or notifying stakeholders – without relying on manual scripting or external development resources.

Q: How will the Agent Builder work?

A: Administrators will be able to describe their automation intent in plain language. AI Studio will then be able to propose a structured workflow with explicit triggers, conditions, and actions. The administrator can then review, edit if needed, and save the workflow as a custom agent. The resulting agent will be visible, auditable, and managed through the same interface as all other agents.

Q: Can AI be incorporated into custom agents?

A: Yes – but intentionally. AI will be invoked deliberately, not invisibly embedded in agent behavior.

Q: What default agents are available out of the box?

A: AI Studio will launch with a library of default agents across foundational AI and cyber resilience categories, including Arlie Data Sense, Arlie Advisor, and Arlie Recover.

Q: How will AI Studio relate to AI Protect and Data Activate?

A: All three will be part of Commvault’s next-generation AI capabilities. Data Activate helps govern how data is prepared and activated for AI use. AI Protect will help govern agents operating in production. AI Studio will help teams deploy and build custom agentic workflows. Together they will form an end-to-end AI resilience lifecycle.

Teja Medasaniis Principal Product Manager at Commvault andVir Choksiis Principal Product Marketing Manager at Commvault.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Pontos principais

  • Apache Iceberg has become a key data lakehouse format,emany AWS customers are migrating from Glue-managed Iceberg tables to fully managed Amazon S3 Tables for better performanceeautomation.
  • Clumio enables a smooth, Iceberg-aware migration process that helps maintain data integrity, metadata,eversion history while adding air-gapped, immutable protection.
  • The platform automates migration using a simple backup-and-restore workflow, helping reduce the need for custom scripts or manual configuration.
  • Compared to manual or native AWS migration methods, Clumio offers a faster, more scalable,eresilient option for enterprise data lakehouse modernization.
  • Clumio’s collaboration with AWSeavailability in the AWS Marketplace enable organizations to modernize data lakes securelyeconfidently.

AIelatency-sensitive analytics workloads increasingly depend on data lakehouses as their underlying data architecture. Among AWS customers building these environments, Apache Iceberg has become one of the fastest-growing table formats on Amazon S3, providing the transactional consistency, schema evolution,eperformance needed for modern analytics.AWS customers manage Iceberg tables today through the AWS Glue Data Catalog or adopt AWS’s fully managed option, Amazon S3 Tables, to streamline operationseimprove performance.As AWS customers evaluate the growing importance of their Iceberg-based data lakehouses, considerations around protection, resilience,emigration to Amazon S3 Tables naturally become part of that planning. Many teams are now looking for a simple, reliable way to move from Glue-managed Iceberg tables to S3 Tables while strengthening the protection of these critical datasets.As AWS’s 2025 Global Storage Partner of the Year, Commvault is deepening its collaboration with AWS to help customers modernize, protect,eoptimize their cloud-native data.ThroughClumio, Commvault delivers anIceberg-aware, air-gapped cyber resilience solution for AWS –enow helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while enabling long-term protectionerecovery. You can start your free trial in the AWS Marketplace.

The Challenge: Limited Options for Moving to S3 Tables

Organizations are increasingly evaluating migrations from Glue-managed Iceberg tables to fully managed Amazon S3 Tables to improve data lake performanceesimplify operations. According to AWS, S3 Tables can deliver up to3 times faster query performanceeup to 10 times higher transactions per second compared to Iceberg tables stored in general purpose S3 buckets.Many teams also want to offload undifferentiated heavy lifting – such as compaction, snapshot management,eunreferenced file cleanup – while reducing overall storageequery costs.However, existing AWSecommunity guidance, such as AWS’s migration framework, outlines a manual, multi-step process requiring custom scriptingeorchestration. Migrating data while maintaining schema, metadata,eversion history can be time-consumingeerror-prone,emost current approaches focus on replication rather than Iceberg-aware recovery or rollback.Clumio’s migration support for Apache Iceberg tables provides the Iceberg-aware, enterprise-grade migrationeresilience capability that modern data lakehouses have been missing. Solicite uma demonstração to see how Clumio streamlines your migration.

How Clumio Simplifies MigrationeProtection

Clumio para Apache Iceberg na AWS helps automate migration from Iceberg tables registered in the AWS Glue Data Catalog to Amazon S3 Tables, while simultaneously enabling long-term protection for these modern data lakehouse assets.The same Iceberg-aware platform provides air-gapped, immutable backups, isolated recovery points, point-in-time or snapshot-level restores,eretention capabilities that help support compliance requirements – extending Commvault’s leadership in cloud-native cyber resilience.Migrationeprotection work hand in hand:

  • Help protect Iceberg tables registered in the AWS Glue Data Catalog.
  • Restore as fully managed Amazon S3 Tables.
  • Continue helping protect those Iceberg tables with Clumio’s cyber resilience capabilities.

For teams that prefer Infrastructure-as-Code deployment,Clumiooffers a publicly availableTerraform module that supports Apache Iceberg.As AWS customers adopt Amazon S3 Tables, protecting these modern data assets becomes even more important. Threat vectors such as ransomware, accidental deletion, malicious or mistaken changes,eaccount compromise can disrupt AIeanalytics pipelineselead to costly reprocessing. Clumio helps customers mitigate these risks withimmutable, air-gapped backupsand flexible recovery options across accounts, regions, snapshots,epoints in time. For a deeper look at why data lakehouses need purpose-built protection, seeFechando a lacuna na proteção de data lakehouse.

How It Works – From Backup to Restore

The migration process using Clumio follows a straightforward backup-and-restore workflow, designed to minimize effortehelp maintain Iceberg table integrity.Step 1: Connect with the Commvault team for migration program revieweapproval. Please Entre em contato conosco.Step 2: Discovereback up Iceberg tables registered in the AWS Glue Data Catalog, with underlying data stored in S3, using Clumio.Step 3: Restore Iceberg table backups – whether the full snapshot history, a selected subset, or a specific point-in-time version – as Amazon S3 Tables in any account or region.Step 4: Enable incremental backups to maintain protection for your new Amazon S3 Tables.Clumio’s architecture helps reduce the need forehelps provide transactionally consistent Iceberg recovery across accounts, regions,esnapshots.To see the full migration workflow in action – including Iceberg discovery, backup selection, snapshot options,erestoration to Amazon S3 Tables – watch the demo video embedded below. It walks through the entire backup-and-restore flow end to end, showing how Clumio handles the data, metadata,esnapshot migration with no manual configuration required.

Comparing Migration Options

Most migrations to Amazon S3 Tables today depend on manual scripts or native tooling. Here’s how those methods compare against Clumio’s Iceberg-aware approach.

Method Description Key Considerations
DIY scripts/
open source tools
Custom scripts using Athena or Glue APIs to copy dataemetadata Best suited for teams with scripting expertiseecustom migration requirements
Native AWS processes/
snapshots
AWS documentationecommunity guides outline snapshot-based or query-driven migrations Suitable for teams using native AWS servicesemanaging multi-step migration processes
Clumio SaaS-based, Iceberg-aware backuperecovery solution for AWS Simple, Iceberg-aware migration workflow that helps preserve metadataesnapshot lineage while integrating ongoing protection

Solicite uma demonstração to learn how Clumio simplifies migration at scale.

Why This Matters for AWS Customers

As AWS customers modernize their data lakehouses, they need a simple, scalable way to migrate Iceberg tables to Amazon S3 Tableseprotect them against operationalecyber risks. Clumio delivers this by providing Iceberg-aware migration along with air-gapped, immutable protection.AWS is working with Commvault to help customers use Clumio for both protectionemigration to Amazon S3 Tables. The solution is available today in the AWS Marketplaceesupports Iceberg tables across both Glue-managedefully managed S3 Tables environments. Together, CommvaulteAWS provide enterprises with a simple, scalable way to modernize their AI data pipelines.For organizations looking to strengthen resilience across the broader AWS data stack, see our blogs on protecting Amazon S3 data with ClumioeClumio Backtrack for Amazon DynamoDB.If you’d like to discuss your AWS data modernization strategy, please Entre em contato conosco.

Moving Forward with ClumioeAWS

As organizations modernize their data platforms for AI, Clumio helps them migrate confidently to S3 Tables, maintain data integrity,estrengthen their cyber resilience. Clumio simplifies migrationeprotection – helping organizations protect, recover,emove their most valuable data faster.Start your free trial in the AWS Marketplace.


Perguntas frequentes

Q: Why are organizations moving from self-managed Iceberg tables to Amazon S3 Tables?
A: Many teams are migrating to S3 Tables to improve performanceesimplify management. Amazon S3 Tables deliver up to three times faster query performancee10 times higher transaction throughput than self-managed Iceberg tables while reducing operational overhead.Q: How does Clumio simplify the migration process?
A: Clumio automates migration through a backup-and-restore workflow that maintains schemaemetadata consistency. It avoids manual scriptingeenables restoring Iceberg backups directly as S3 Tables across accountseregions.Q: What makes Clumio different from other migration approaches?
A: Unlike do-it-yourself scripts or AWS’s native methods, Clumio is Iceberg-awareeautomated,eit offers built-in cyber resilience features such as immutable backups, point-in-time recovery,eretention capabilities that help support compliance requirements.Q: How does Clumio enhance data protection duringeafter migration?
A: Clumio provides air-gapped, immutable backups that help protect against ransomware, accidental deletion, or malicious changes. It also supports flexible recovery across snapshots, accounts,eregions.Q: Is Clumio available for AWS customers now?
A: Yes, Clumio is available in the AWS Marketplaceeintegrates with both AWS GlueeAmazon S3 Tables environments. customers to modernizeeprotect their AI data pipelines.Q: What’s the first step to get started with Clumio for S3 Tables migration?
A: Organizations can start by contacting Commvault for migration program approvalethen use Clumio to discover, back up,erestore Iceberg tables as Amazon S3 Tables. A free trial is available in the AWS Marketplace.Vir Choksi is Principal Product Marketing Manager at Commvault.

Related Blogs

More related posts


Clumio

Read more about Clumio

Pontos principais

  • Commvault’s unified threat detection consolidates risk signals and context into a single view, integrating with partners to help reduce alert fatigue and bridge the gap between security ops and data protection teams.
  • Arlie®, Commvault’s AI assistant, helps translate complex incidents into plain-language summaries and recommends next steps – making it easier for non-experts to respond quickly and confidently.
  • Rather than treating entire backups as clean or compromised, Synthetic Recovery™ works at the file level to identify and assemble the most recent clean data, minimizing data loss and recovery downtime.
  • Cleanroom™ Recovery, an isolated environment for forensic investigation, has been enhanced with runbooks to make threat analysis more repeatable, auditable, and safe – helping minimize risks for production systems.

Commvault’s enhanced cyber recovery capabilities focus less on traditional backup and more on helping organizations stay resilient in the face of modern cyber threats. They’re designed to help security and data protection teams seeking faster insights, cleaner recovery options, and stronger validation that their data can be kept safe and recoverable.

At the core is an upgraded threat-detection experience that brings risk, signals, and context together in a single, unified view. Instead of sifting through disconnected alerts, teams see prioritized risks across their environment, enriched with partner integrations like CrowdStrike and Netskope, so they can focus on what truly matters. This helps reduce alert fatigue and bridges the gap between security operations and data protection.

Arlie for the Assist

AI also plays a central role throughArlie, Commvault’s AI-enabled assistant for data security. Arlie helps summarize complex incidents into clear, human-readable narratives: what happened, when it started, which systems were impacted, and what other tools are seeing. From there, Arlie recommends next moves – such as engaging the security team, using a cleanroom for deeper analysis, or triggering a safer recovery path – so even non-experts can act quickly and confidently.

Synthetic Recovery Helps Restore Clean Data

Recovery itself has evolved with new options that are purpose-built for cyber events rather than routine restores.Synthetic Recovery automatically locates and assembles the most recent clean versions of data at the file level, helping reduce manual effort and lower the risk of restoring compromised content. Instead of treating entire backups as “all good” or “all bad,” Synthetic Recovery is designed to help preserve as much recent, safe data as possible, helping to minimize data loss and downtime.

Cleanroom™ Recovery for Forensic Analysis

For teams that need to investigate attacks in depth,Cleanroom Recovery provides an isolated, secure environment to help analyze suspicious data while helping to reduce risk to production systems. This environment is orchestrated with our new runbooks feature to help streamline setup and validation, making forensic work more repeatable and less error prone. It can be particularly helpful when demonstrating to auditors and regulators that steps have been taken to contain a threat, preserve evidence, and follow best practices.

Finally, the platform’s reporting and compliance capabilities tie everything together, helping to turn technical response actions into clear, defensible records. Teams can export details, show chain of custody, and support demonstration of clean, validated recoveries, helping them work toward meeting regulatory requirements and building trust with stakeholders.

Overall, these new features further enhance our Commvault cyber recovery platform to a broader cyber resilience platform that helps detect faster, recover smarter, and validate that your data is safe and clean.

To learn more, watch the Commvault Cyber Recovery demo.

Perguntas frequentes

Q: What makes these updates different from traditional backup solutions?

A: The focus has shifted from routine data backup to cyber resilience – emphasizing faster threat detection, cleaner recovery from cyber events specifically, and compliance validation.

Q: Who are these features designed for?

A: Primarily security and data protection teams that need faster insights, cleaner recovery processes, and documented proof that data is safe and recoverable.

Q: How does Arlie help non-technical users?

A: Arlie helps summarize incidents into clear narratives (what happened, when, which systems were affected) and recommend specific next steps, so teams don’t need deep technical expertise to act decisively.

Q: What is Synthetic Recovery, and when should I use it?

A: Synthetic Recovery automatically locates and assembles the most recent clean file versions after a cyber event. It is useful when you need to recover quickly and reduce the risk of restorating compromised data.

Q: What is Cleanroom Recovery used for?

A: It helps provide a secure, isolated environment for deep forensic analysis of an attack – useful for investigating threats, preserving evidence, and proving to regulators that proper containment procedures were followed.

Q: How does the platform support regulatory compliance? A: It generates exportable reports with chain-of-custody details and validated recovery records, giving teams the documentation needed to meet regulatory requirements and build stakeholder trust.

Nico Guerrera is Senior Technical Marketing Manager at Commvault.

More related posts


Cyber Recovery

Read more about Cyber Recovery

AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Pontos principais

  • Detection alone is not enough – organizations need integrated, orchestrated recovery to minimize business disruption from ransomware.
  • The CISCO XDR and Commvault® Cloud integration connects threat detection directly to clean recovery actions within the same security workflow.
  • Uma recuperação segura exige processos de restauração validados e isolados para ajudar a reduzir o risco de reinfecção e retomar as operações com confiança.
  • A ativação de ações de backup e recuperação diretamente a partir de ferramentas de segurança ajuda a preservar dados críticos em um estágio inicial e a reduzir os prazos de recuperação.
  • A resiliência unificada combina segurança e recuperação, ajudando a reduzir atritos entre os ambientes de Detecção e Resposta Estendidas (XDR) e de Orquestração, Automação e Resposta de Segurança (SOAR), ao mesmo tempo em que melhora a velocidade e a confiança na resposta.

If there’s one thing I’ve learned from talking with security leaders across industries, it’s this: Detection is only half the job. The other half, the part that determines whether the business keeps moving, is response and recovery. And when ransomware hits, recovery isn’t just about speed. It’s about confidence, it’s about cleanliness, and it’s about speed.

That’s why this announcement matters. We’ve expanded our partnership with Cisco with a new integration between Cisco XDR and Commvault Cloud, built to unite ransomware response and recovery in a single, coordinated workflow.

Too many organizations still live with a painful gap between what security teams see and what IT teams can safely do next. When every second counts, that gap becomes the difference between containing an incident and watching it evolve into business disruption. With this integration, teams can move from detection to decisive recovery actions inside the security operations workflow, helping minimize impact when time is the enemy.

And here’s the truth: In a crisis, the business doesn’t care who owns which “console.” The business cares about outcomes. Can we preserve critical data early? Can we recover cleanly without reinfection? Can we restore the right systems confidently instead of guessing? How fast can we get back to viabilidade mínima? That’s the gap we’re closing, bringing recovery actions into the de resposta a incidentes flow, where decisions are already being made.

This is where “clean recovery” stops being a talking point and becomes the new standard.

Recovery has turned into an exercise in trust: trust that your recovery points are safe, trust that your backups aren’t already compromised, and trust that you’re not reintroducing risk while trying to restore operations. The uncomfortable reality is that defenders increasingly have less time to respond.

According to Sophos’ o Relatório sobre Adversários Ativos de 2026, “the speed with which attackers attempt to go after AD after gaining access to the system sped up by 70% over last year, down to a median of just 3.40 hours.”

That kind of speed forces de resposta a incidentes to operate in an immediate, orchestrated way across silos, and it raises the bar for recovery. Because fast restores don’t help if they aren’t clean.

With this new integration, security operations teams can trigger Commvault Cloud actions directly from Cisco XDR, helping preserve data early and move toward clean recovery.

If a SOC manager gets notice of a threat detected in Cisco XDR, they can initiate a backup of core infrastructure VMs right away, and then restore impacted systems into Commvault Cloud Cleanroom Recovery, a secure, isolated cloud environment designed for investigation and validation, before confidently returning systems into production. This brings recovery actions in the same workflow as detection, so teams can respond faster and recover with confidence.

The result is a tighter connection between detection and recovery, so security teams can act decisively at the earliest signs of an attack. By validating recovery in an isolated cleanroom before returning systems to production, organizations reduce reinfection risk, preserve critical data, and shorten recovery timelines, all from tools SOC teams already trust.

 

A Commitment to Unified Resilience

Zooming out, this integration with Cisco XDR is an important milestone, and it’s also part of a bigger direction we’re committed to: unified resilience, where security and recovery work together instead of operating in separate lanes. And it’s not an “either/or” proposition. It’s a growing ecosystem designed to meet teams where they work.

Another great example of this is our integration with Splunk SOAR, that helps improve threat detection and drive faster, more automated response. Commvault can send threat detection, data security, and backup and recovery intelligence directly into Splunk, enriching security events and helping alert SecOps teams and automated actions in Splunk can reduce response time without bouncing between interfaces.

So, whether a customer’s operational hub is XDR or SOAR, the goal stays the same: reduce friction, speed decisions, and make recovery provable.

The Cisco XDR integration is generally available globally and offered at no additional cost to existing Commvault customers. If you want to dig deeper, here are a few good places to start:

Ouentre em contato comigo no LinkedIn, and I’m happy to talk through what “detection to clean recovery” looks like in the real world.

FAQs

Q: Why is detection only half the battle in ransomware response?
A: Detection identifies threats, but response and recovery determine whether the business can continue operating. Without a coordinated recovery plan, even fast detection can still lead to prolonged downtime and disruption.

Q: What does “clean recovery” mean in practice?
A: Clean recovery involves restoring systems in a secure, isolated environment to validate that backups are uncompromised before returning them to production. This approach helps reduce the risk of reinfection and enable greater confidence in restored systems.

Q: How does the Cisco XDR and Commvault integration improve de resposta a incidentes?
A: The integration allows security teams to trigger backup and recovery actions directly from Cisco XDR. This unified workflow helps preserve data early, initiate secure restoration, and move from detection to recovery without switching between disconnected tools.

Q: What role does the Cleanroom Recovery environment play?
A: Cleanroom Recovery provides an isolated cloud space for investigation and validation of restored systems. Teams can analyze and confirm system integrity there before confidently bringing workloads back into production.

Q: How does this integration support broader security ecosystems like SOAR?
A: In addition to Cisco XDR, Commvault integrates with platforms like Splunk SOAR to enrich threat intelligence and automate response actions. This ecosystem approach helps security teams reduce friction, accelerate decisions, and make recovery outcomes more predictable.

Q: Is the Cisco XDR integration available to existing customers?
A: Yes, the integration is generally available worldwide and is offered at no additional cost to existing Commvault customers, making it easier to adopt unified detection and recovery workflows.

Michael Fasulois Senior Director, Portfolio Marketing, at Commvault.

Related BlogsCleanroom Recovery abrem caminho para uma nova era em resiliência cibernética

Commvault inaugura uma nova era de resiliência empresarial unificada

A próxima evolução na proteção Cloud

As 5 etapas essenciais para a recuperação limpa

Seu manual moderno para resposta rápida e recuperação limpa

More related posts


Cyber Resilience

Read more about Cyber Resilience

There’s a lot of talk about modernization – Cloud, AI, automation, security transformation. But what does modernization actually look like when you’re responsible for keeping systems running, data protected, and recovery viable under pressure?

In this episode of STRIVE, I had the pleasure of sitting down with Gilman Treantos – a 25-year IT veteran whose career spans everything from mainframes to modern cyber resilience architecture. This conversation provides a practitioner’s view of what modernization really means when outages, ransomware, and operational risk are part of the daily equation.

Watch the episódio completo.

Key Takeaways: What Modern Cyber Readiness Actually Requires

  • Modernization isn’t about new tools – it’s about resilient architecture. Technology evolves, but recovery discipline, testing, and cross-team coordination are what separate reactive organizations from resilient ones.
  • Cyber readiness demands collaboration between security and infrastructure. Silos create blind spots. Unified visibility and shared responsibility can create speed in recovery.
  • Backup tools are more powerful than most teams realize. When used creatively, they can support large-scale migrations, isolated recovery, and transitions designed to minimize data loss.
  • Testing is non-negotiable. A recovery plan that hasn’t been rehearsed is a liability, not a strategy.
  • Career resilience mirrors technical resilience. Proactivity, curiosity, and willingness to solve hard problems are as critical as any platform.

From Blockbuster to Cyber Resilience

Gilman’s journey didn’t start in a war room or a security operations center. It started at Blockbuster.

Without formal IT training, he leaned into troubleshooting. That curiosity became mainframe work. That work became distributed systems. That evolved into data protection and cyber resilience leadership.

What stands out isn’t the career arc – it’s the mindset. He built a reputation by taking on the problems no one else wanted. Fixing fragile systems. Supporting overlooked initiatives. Solving issues that crossed organizational boundaries.

That mentality translates directly to modernization, because modern cyber readiness is built by people willing to dig into uncomfortable complexity.

Sneak Peek: The Modernization Playbook

In this segment, Gilman explains why modern cyber recovery requires more than traditional malware detection — and how anomaly detection, ThreatScan, and isolated recovery environments can help strengthen enterprise resilience.

Modernization Under Pressure

One of the most compelling parts of the episode is a real-world example: evacuating a remote data center in a single night. No data loss. No prolonged downtime. No operational chaos.

By leveraging Commvault LiveSync in a creative way, Gilman and his team were able to migrate infrastructure quickly and cost-effectively – using capabilities that weren’t originally designed for that exact scenario.

That’s modernization in practice.

The House of Cards Problem

As organizations scale, permissions sprawl. Backup systems grow complex. Security tools layer on top of infrastructure without full alignment. Over time, environments become fragile.

Gilman describes this dynamic as something many teams underestimate: a slow accumulation of technical and operational debt. Modernization, in his view, isn’t just upgrading platforms. It’s simplifying architecture, improving visibility, and breaking silos between cybersecurity and infrastructure teams.

Cyber readiness means:

  • As equipes de segurança e de backup compartilham dados de telemetria.
  • Os ambientes de recuperação são isolados e testados.
  • A detecção de malware vai além dos fluxos de trabalho principais.
  • As decisões relativas à infraestrutura levam em conta a velocidade de recuperação.

This is where modernization and resilience intersect.

Threats Are Evolving. So Must Recovery.

Ransomware isn’t slowing down. Threat actors are more sophisticated. Malware hides inside legitimate workflows. Gilman’s perspective is blunt: Preparation must be proactive.

He advocates for:

  • Testes regulares de recuperação de desastres
  • Ambientes de recuperação isolados prontos para serem ativados
  • Ferramentas de detecção de anomalias integradas aos processos de backup
  • Exercícios interequipes que simulam situações de perturbação do mundo real

Watch the Full Episode

Check out our full STRIVE conversation to learn:

  • Como Gilman desenvolveu sua abordagem à proteção de dados ao longo de 25 anos.
  • Os detalhes por trás de uma migração projetada para minimizar a perda de dados.
  • Por que a colaboração entre segurança e infraestrutura é essencial.
  • Conselhos práticos para profissionais da área de resiliência.
  • What modernization really demands in today’s threat landscape.

Assista agora sobre.

If you care about resilience, recovery, or leading IT through uncertainty, this is 20 minutes well spent.

FAQs

Q: What does “modernization” mean in the context of cyber readiness?

A: It means building resilient, testable, and collaborative systems that can recover quickly under real-world pressure – not just upgrading to newer platforms.

Q: Why is collaboration between security and infrastructure teams so important?

A: Because recovery depends on shared visibility. Security detects threats, but infrastructure enables restoration. Without alignment, response slows and risk increases.

Q: How can backup tools support modernization beyond recovery?

A: When used creatively, they can enable data center migrations, isolated recovery environments, anomaly detection, and large-scale operational shifts.

Q: How often should disaster recovery environments be tested?

A: Regular testing – ideally quarterly or aligned with major infrastructure changes – builds confidence and reveals gaps before an actual incident.

Chris Mierzwa is Senior Director, Portfolio Marketing, at Commvault.

Related BlogsComo a SMMPA fortaleceu a resiliência cibernética com Cleanroom Recovery

Preparação cibernética em meio a tensões geopolíticas: orientações para nossos clientes, parceiros e comunidade

Por que a IA está prejudicando sua estratégia de resiliência (e o que fazer a respeito)

Física x Marketing: Acelerando a recuperação sem deixar de respeitar as leis da física

Modernizando a segurança cibernética financeira: De reativo a resiliente

More related posts


Readiness

Read more about Readiness

The RSA Conference, held from March 23 – 26 in San Francisco, is one of the premier events in the cybersecurity industry, bringing together experts, thought leaders, and innovators to discuss the latest trends and solutions in cyber resilience and data protection.
The energy was palpable, the learning top-notch, and the city buzzing. With so much to see, including our ResOps Rumble and The Rumble After Party on Monday evening, we wanted to make sure you didn’t miss these exciting announcements from Commvault.
Key Takeaways

  • Commvault earned major industry recognition with a Global InfoSec Award for innovation in cyber resilience.
  • Expanded threat hunting capabilities help organizations detect risks in backups and recover clean data faster.
  • New data and AI security enhancements help extend visibility, classification, and governance across structured and unstructured data.
  • Integration with Microsoft Security helps enable faster, coordinated threat detection and recovery workflows.
  • Strategic partnerships and industry initiatives highlight a shift toward unified resilience operations as a core security discipline

  1. Commvault wins the 2026 Market Disruptor Cyber Resilience Global InfoSec Award.

After being named Outstanding in the Cyber Resilience category at the 2025 Global InfoSec Awards, we have accelerated our innovation roadmap, redefining cyber resilience beyond traditional backup and recovery to help address the realities of today’s AI-driven threat landscape.
This year, Global InfoSec has recognized Commvault as Market Disruptor in the cyber resilience category. We provide a unified cyber resilience platform designed to deliver AI-enabled data protection, proactive threat detection, advanced ransomware recovery, and a single operational view across enterprise environments.
Unlike other solutions, Commvault® Cloud helps empower customers to protect, recover, and manage their data, applications, and production workloads – across on-premises, public, private, hybrid, SaaS, and multi-cloud environments.
On the topic of market disruption and innovation, we have made a few major announcements leading up to the conference.

  1. Commvault Announces Expanded Threat Hunting Capabilities

Anunciamos uma parceria estratégica reforçada entre a Commvault e a HPE –recently announced expanded threat hunting capabilities within Commvault Cloud Threat Scan. The enhancements help organizations rapidly identify risks within backup environments and recover validated clean data, helping reduce reinfection risks and prolonged downtime.
To address this challenge, Commvault now delivers two complementary scanning modes within Commvault Cloud Threat Scan:

  • Hyper Threat Hunting helps enable targeted searches across backup data using threat hunting artifacts such as hashes and YARA rules to identify known indicators of compromise at scale. Hash-based hunting helps provide fast, index-based detection, while YARA-based analysis helps support more targeted pattern matching for deeper investigation.
  • Deep Inspection provides layered file-level analysis using malware signatures, machine learning, heuristic analysis, and AI-enabled encryption detection to help uncover known threats, suspicious variants, and ransomware related activity that may evade exact-match indicators alone.

Together, these detection modes allow close collaboration across incident response and recovery teams to isolate affected data and help make informed recovery decisions. They can schedule recurring scans for continuous monitoring or conduct targeted searches during active incident response scenarios, helping provide flexibility for both ongoing protection and time-sensitive response.

  1. Commvault Announces an Expansion of Data and AI Security Capabilities

On the same day,we announced an expansion of data and AI security capabilities within Commvault Cloud, enabled via our recente aquisição da Satori. The advancements extend data discovery, classification, and risk assessment into structured data environments and introduce real-time access governance for structured databases, including vector databases used in AI applications. These innovations expand Commvault’s existing data security posture management functionality for unstructured data, while data access governance adds real-time control of structured data access.
These advancements also unify visibility by identifying sensitive data, surfacing exposure and policy violations, and consolidating risk insights to help organizations prioritize remediation based on impact. This helps yield improved resilience, prioritized risk remediation, support for compliance, and reduced data exposure to help strengthen resilience across both production and backup data.

  1. Commvault Announces an Expanded Integration with Microsoft Security

On the first morning of the conference, we announced anexpanded integration with Microsoft Security to better connect threat detection with trusted recovery. The new integration uses Microsoft Sentinel, Microsoft Security Copilot, and the Commvault Cloud platform to streamline resilience operations (ResOps) and enable real-time data insights, helping organizations move quickly from identifying a threat to validating and restoring clean data faster and with greater confidence.
This new integration helps enable coordinated workflows between security and recovery teams. Security alerts from Commvault Cloud are ingested into Microsoft Sentinel data lake where security operations center analysts can enrich these incidents with partner intelligence to access impact and validate scope. In the coming quarters, these insights can help drive automated, policy-based recovery workflows to accelerate and orchestrate clean recovery. You can learn more from our blog here.

  1. NetApp and Commvault Advance Cyber Resilience with Strategic Alliance 

On the topic of alliances, we alsoannounced a strategic alliance with NetApp® to deliver a powerful, integrated solution for enterprise data protection and cyber resilience. The unified solution enables resilience, security, and rapid recovery for customers across on-premises and cloud environments, helping give organizations confidence that their data is available, immutable, and recoverable.
This alliance addresses a critical need for scaling resilience via unified cyber detection and ransomware recovery. By combining Commvault’s leading resilience, protection, and recovery capabilities with NetApp’s enterprise-grade data platform with built-in intelligence and AI-enable ransomware detection, together we’re creating a highly differentiated, end-to-end cyber resilience solution.

  1. TIME + Commvault CISO of the Year

Last but not least in a newsworthy few weeks, we are very excited to announce thelaunch of the inaugural TIME and Commvault CISO of the Year Award. The branded award, selected by Commvault and a panel of industry experts, recognizes enterprise security leaders who are not only defending against cyber threats but also redefining resilience in an increasingly complex threat landscape.
The CISO of the Year Award recognizes leaders who are transforming cybersecurity into a driver of trust, operational strength, and long-term resilience. They embrace critical practices and emerging disciplines, including ResOps, which is rapidly becoming a core discipline for modern enterprise security.
As indicações for the CISO of the Year Award will be accepted by Commvault from March 23 through June 20, 2026. Submissions will be reviewed by a panel of industry experts. The panel and Commvault will choose finalists and the winning CISO of the Year based on pre-defined criteria. You can read more about the criteria on the nominations page.
Commvault Cyber Resilience a Highlight of RSAC

RSAC 2026 made one thing clear: Cyber resilience is no longer a future aspiration – it’s a present-day mandate. From industry recognition to expanded threat hunting, deeper data and AI security, and stronger ecosystem integrations, Commvault continues to push the boundaries of what organizations can expect from a modern resilience platform.
These announcements reflect a broader shift toward unifying security, data protection, and recovery into a cohesive strategy that helps organizations act faster, respond smarter, and recover with confidence in the face of evolving threats.
As the threat landscape grows more complex, the ability to not only detect and defend but also recover with great confidence is becoming a defining competitive advantage. The innovations highlighted at RSAC – alongside strategic partnerships and recognition of industry leaders – underscore Commvault’s commitment to enabling that outcome.
If RSAC is any indication of where the industry is headed, ResOps will continue to take center stage, and organizations that embrace this approach will be well positioned to navigate whatever comes next.


FAQs

Q: What are the new threat hunting capabilities Commvault introduced?
A: Commvault introduced Hyper Threat Hunting and Deep Inspection within itsThreat Scan solution. These features combine fast detection with advanced analysis to help identify both known and emerging threats in backup data.
Q: How do Commvault’s new data and AI security capabilities benefit organizations?
A: The enhancements to Commvault’s data and AI security capabilities expand visibility into sensitive data across structured and unstructured environments. They also add real-time access governance, helping organizations reduce risk and improve compliance.
Q: What is the significance of the Microsoft Security integration with Commvault Cloud?
A: The integration helps connect threat detection with recovery by linking Commvault Cloud with Microsoft Sentinel and Security Copilot. This is designed to enable faster decision-making and more automated recovery processes.
Q: What does the Commvault and NetApp alliance bring to customers?
A: The alliance combines Commvault’s resilience platform with NetApp’s data infrastructure and AI-enabled ransomware detection. This creates a unified solution designed to deliver stronger data protection and faster recovery across environments.
Q: What is the TIME and Commvault CISO of the Year Award?
A: The TIME + Commvault CISO of the Year award recognizes a security leader who exemplifies modern resilience leadership through a ResOps approach.
This program celebrates CISOs who treat resilience as a core business capability not just a technical function, those bridging security, IT, and operations to enable their organizations to recover quickly, operate confidently, and innovate without increasing risk​​.
​​​The honoree selected ​by Commvault ​will be featured in a TIME​ ​branded​ ​article and video, with additional recognition across TIME and Commvault channels​. The honoree will also be invited to Commvault’s annual SHIFT event. ​

More related posts


Threat Scan

Read more about Threat Scan

Pontos principais

  • Security must scale like Agent Smith: In The Matrix, Agent Smith multiplied rapidly to overwhelm Neo. Security teams face a similar challenge today as threats and signals grow faster than analyst capacity. AI-enabled security agents help teams scale investigations without needing to scale headcount.
  • Correlating signals improves investigation confidence: The Commvault Security Investigation Agent correlates backup intelligence with security signals from platforms like Netskope, CrowdStrike, and Palo Alto Networks to determine whether threats discovered in backup data also impacted production systems.
  • Cyber resilience will become agent-driven: The Commvault Security Investigation Agent is the first step toward a future where specialized AI agents assist security teams with investigations, recovery decisions, and faster restore workflows.

Introdução

In The Matrix, there’s a moment that feels surprisingly relevant to today’s technology landscape. Agent Smith discovers he can duplicate himself. One becomes many, and suddenly Neo is surrounded by an army of identical agents operating simultaneously.

In many ways, that scene mirrors the world we’re entering today with agentic AI. Across industries, and especially in cybersecurity, we’re beginning to see the rise of specialized AI agents that can work independently, scale rapidly, and assist humans in ways that were previously impossible. But unlike Agent Smith’s relentless takeover, the goal of these agents isn’t domination. It’s defense.

Expandir a escala e, ao mesmo tempo, eliminar silos

Security operations today face a fundamental scaling problem. The number of systems, signals, and security tools continues to grow, but the number of analysts does not.

Organizations now ingest telemetry from endpoint security platforms, network defenses, cloud monitoring tools, and identity protection systems. Each of these tools generates its own alerts and dashboards, often operating in isolation from one another. The result is an overwhelming amount of data spread across disconnected silos.

It’s tempting to assume the solution is simply hiring more analysts, but anyone who has managed large teams knows that adding people introduces its own challenges. As teams grow, communication becomes more complex, coordination slows down, and the efficiency of investigations often decreases.

What security teams really need is not just more people, but more intelligence and automation to help analysts move faster and see the bigger picture.

One of the most persistent silos in security operations has been the divide between backup systems and security tools. Traditionally, security teams monitor production environments through their security information and event management tools while backup environments operate in a separate console.

Backup data is often only examined after an incident occurs, when organizations are already deep in recovery mode. Yet attackers increasingly target backup systems precisely because they know they are critical to recovery.

Ransomware operators frequently encrypt production systems, attempt to corrupt backups, or leave malicious artifacts hidden inside protected datasets. This means that backup environments often contain valuable evidence of an attack, but that intelligence has historically been difficult for security teams to access and correlate with other signals.

O novo agente de investigação de segurança

Commvault’s new integration with Microsoft Sentinel and Microsoft Security Copilotfoi projetada para preencher essa lacuna. Por meio dessa integração, Cloud do Commvault Cloud podem ser transmitidos diretamente para o Sentinel Data Lake, reunindo os dados de telemetria de backup no mesmo ambiente analítico que os sinais cloud de terminais, redes e cloud.

Em vez de ocorrer de forma isolada, a atividade de backup agora pode ser analisada em conjunto com o ecossistema de segurança mais amplo. Mas o verdadeiro potencial dessa integração reside na introdução do Commvault Security Investigation Agent.

O Agente de Investigação de Segurança auxilia os analistas a investigar possíveis ameaças, correlacionando sinais detectados em ambientes de backup com sinais provenientes de outras plataformas de segurança. Quando um analista fornece o nome do host de um servidor, o agente coleta eventos de segurança gerados pelo Commvault Threat Scan Risk Analysis, incluindo anomalias no backup, eventos de criptografia que possam indicar atividade de ransomware, malware detectado em conjuntos de dados protegidos e backups que contenham dados confidenciais.

Em seguida, o agente correlaciona esses eventos com os dados de telemetria de outras ferramentas de segurança nas quais as organizações já confiam, como Netskope, CrowdStrike e Palo Alto Networks. Ao analisar conjuntamente a atividade nessas plataformas, o agente pode ajudar a determinar se o comportamento suspeito identificado nos dados de backup também aparece nos ambientes de produção.

Como conseguir o agente?

Let’s first walk you through how you can start with our first agent focused on security investigations. Then we’ll share how we plan to rapidly spawn new agents – just like Agent Smith – so customers can take control of investigations, recovery decisions, and restore operations, giving security and operations teams the intelligence they need to respond faster and recover with confidence.

Configurar o conector

Antes de ativarmos o Commvault Security Investigation Agent, você precisará instalar e configurar o Commvault Cloud .

  1. Installation: Instructions for how to install the Commvault Cloud Solution, along with permissions and pre-requisites, isaqui.

Screenshot: Installation details for the Commvault Cloud Data Connector in the Microsoft Sentinel Content Hub.

  1. Configuration: Once installed, configuration details areaqui.
 Use Commvault Security Investigation Agent

Assim que o Cloud Commvault Cloud for instalado, você poderá usar o novo Agente de Investigação de Segurança.

  1. Acessehttps://securitycopilot.microsoft.com/agents.
  2. Search for “Commvault Security Investigation Agent.”
  3. Click on “Set up” Agent.
  4. Click on “AcesseAgent.”
  5. Click on “Run” => “One time.”
  6. Provide the “Hostname” for the host you’d like help investigating, and click “Submit.”
    1. Note: Hostname is the name of the server that we want to check for events of Commvault and partners like Netskope, CrowdStrike and Palo Alto.
  7. O agente será executado e, como resultado, você receberá uma análise detalhada e recomendações.

Screenshot: The detailed analysis of the Commvault Security Investigation Agent being run on a host that is part of an investigation.

Conclusão

The Matrix may have dramatized the idea of multiplying agents, but it captured an important truth about scale. When Agent Smith multiplied, the dynamics of the fight changed entirely.

Cybersecurity is undergoing a similar shift. Attackers are increasingly leveraging automation and AI to scale their operations. The only way defenders can keep pace is by scaling their own capabilities through intelligent systems that augment human expertise.

With the integration between Commvault, Microsoft Sentinel, and Microsoft Security Copilot – and with the introduction of the Commvault Security Investigation Agent – we are beginning to see what that future looks like. It’s a world where security operations are no longer constrained by silos, where investigations move faster, and where AI-enabled agents work alongside analysts to strengthen cyber resilience across the entire environment.

Over the coming year, Commvault plans to introduce additional agents – just like Agent Smith multiplying in The Matrix – that can help security teams run Commvault Threat Scan, spin up Cleanroom environments for SOC analysts to safely investigate incidents, and accelerate recovery by identifying the safest data to restore.

We’re also excited to collaborate with Microsoft to enable customers to use Microsoft Foundry to build and extend their own agents, allowing them to tailor automation and investigations to their unique environments.

By combining Commvault’s deep cyber resilience capabilities with Microsoft’s AI and security ecosystem, we’re helping organizations move toward a future where intelligent agents help analysts investigate faster, break down silos, and strengthen resilience across the entire environment.


FAQs

Q: What are AI agents in security operations (SecOps/ResOps)?
A: AI agents are specialized, autonomous tools that assist security teams by analyzing data, correlating signals, and supporting investigations. They operate alongside human analysts to help accelerate decision-making and improve response times across complex environments.

Q: Why is scaling security operations such a challenge today?
A: Security teams face an explosion of alerts and data from multiple tools, while analyst headcount grows slowly. This imbalance creates bottlenecks, making it difficult to investigate threats efficiently without automation and intelligent assistance.

Q: How does the Commvault Security Investigation Agent improve threat investigations?
A: The agent correlates backup data with signals from security platforms like CrowdStrike, Netskope, and Palo Alto Networks. This combined view helps enable analysts to determine whether threats detected in backups also impacted production systems, increasing confidence in investigations.

Q: What problem does integrating backup data into security workflows solve?
A: Backup environments often contain critical evidence of attacks but have historically been siloed from security tools. Integrating this data helps enable teams to analyze threats holistically, uncover hidden risks, and make more informed recovery decisions.

Q: How can organizations start using the Commvault Security Investigation Agent?
A: Organizations need to install and configure the Commvault Cloud connector within Microsoft Sentinel. Once set up, the agent can be accessed through Microsoft Security Copilot to run investigations by simply providing a hostname.

Q: What does the future of AI agents in cyber resilience look like?
A: The future points toward multiple specialized agents helping handle investigations, recovery planning, and restore operations. These agents will help break down silos, accelerate response, and enable more resilient security operations across the entire environment.Ritu Singh is Senior Product Manager and Rich Vorwaller is Director, Product Management, at Commvault.


Blogs relacionados

MCP 2.0 explicado: Protegendo os agentes de IA antes que eles se protejam sozinhos

Por que a IA está prejudicando sua estratégia de resiliência (e o que fazer a respeito)

Mantendo a resiliência contra explorações de acesso lateral

Você está preparado para os ciclos de vazamento de dados?

Tendências de ransomware para 2026: IA, resiliência e MTCR

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Pontos principais

  • AI is accelerating data creation and distributed workflows, making traditional reactive approaches inadequate for enabling resilience.
  • Resilience operations (ResOps) help teams shift from reactive troubleshooting to coordinated action, with Commvault applying AI across three areas: protecting AI data, models, and pipelines; leveraging AI to guide and accelerate response; and extending AI across the broader resilience ecosystem.
  • Practical AI agents are designed to surface operational issues (Arlie Data Sense), guide protection decisions (Arlie Advisor), and enable conversational workflows (MCP server).
  • Data security and governance remain foundational. AI must be trained to respect access controls, maintain auditability, and operate within policy boundaries.
  • Organizations can start small with targeted agents and scale toward coordinated, intelligent operations.

AI introduces both new challenges and potential breakthroughs for enterprise resilience. On one hand, traditional siloed tools for protection, recovery, and governance weren’t designed to operate across constantly evolving AI environments that span multiple platforms.
On the other hand, AI-enabled resilience tools can deliver a transformative impact by helping teams maintain visibility, enforce policy, and recover cleanly. For IT and security teams, the question is how best to leverage the benefits of AI while mitigating the operational risks it can pose.
Em um webinar recente, I sat down withTeja Medasani, Principal Product Manager, AI, at Commvault, to explore real-world use cases that put AI agents to work in resilience workflows across cloud, SaaS, on-premises, and AI-native platforms.

Why AI Is Redefining Resilience Operations

The rapid growth and dynamic nature of AI-native environments have put operational workflows under pressure. Manual tagging, spreadsheets, and logic quickly drift out of sync. Sprawling job history tables and audit trails slow manual troubleshooting and make subtle warning signs easy to miss. Recovery processes that assume centralized data and isolated failures are poorly suited for exponential data growth and fragmented workloads across platforms.
When data, workloads, and environments span platforms, resilience can’t remain siloed in separate teams, tools, and policies. A new operating model is needed: resilience operations, or ResOps.

What ResOps Looks Like in Practice

The ResOps framework addresses these challenges across three dimensions:

  • Protect AI: Safeguarding AI data, models, and pipelines across environments so they remain recoverable and compliant.
  • Leverage AI: Using AI to help reduce manual effort, surface operational insight, and guide response and recovery decisions.
  • Extend AI: Connecting ResOps across tools and teams to help protect conversational interactions and integrated workflows.

In the webinar, we focused primarily on leveraging and extending AI, highlighting key roles AI agents can play in day-to-day operations. These examples center onArlie, Commvault’s AI assistant. Designed to help users interpret data, understand issues, and move toward action more efficiently, Arlie includes a library of agents purpose-built to help address specific resilience workflows.
By helping reduce repetitive analysis, surfacing meaningful signals, and guiding decisions around security-aware recovery, these agents can help teams take actions more quickly and confidently. Arlie Data Sense, Arlie Advisor, and Commvault’s MCP server illustrate a few of the possibilities unlocked by AI-enabled ResOps.

Surfacing Operational Issues with Arlie Data Sense

Arlie Data Sense helps teams make sense of dense operational data like job history tables and audit trails. Instead of manually scanning through hundreds of rows to find patterns or diagnose failures, users can triggerArlie to help analyze the data and generate an executive summary highlighting anomalies and emerging issues.
Teams can ask follow-up questions in natural language and explore data further through interactive summaries or visualizations. When a job fails, Arlie can help analyze logs, summarize the failure, identify the possible cause, and provide next steps for resolution.

Guiding Response Decisions with Arlie Advisor

As workloads are added, ownership changes, and requirements shift, maintaining protection coverage across environments becomes increasingly difficult.Arlie Advisor is designed to help teams create and validate protection plans at scale by evaluating the characteristics and current protection coverage for each resource, and then highlighting where adjustments may be needed.
Recommendations are presented clearly with reasoning explained, so teams can evaluate them and decide how to apply them within existing governance processes. This helps teams maintain consistency across dynamic environments.

Extending Resilience Workflows with MCP Server

Resilience workflows often need to connect with ticketing systems, collaboration tools, and security platforms outside the Commvault platform, and they need to be accessible to users who aren’t resilience experts. Commvault’s MCP server makes it possible to extend workflows without custom integrations or significant training by allowing conversational interaction.
Users can ask questions or request actions in natural language, with their prompts translated into governed API calls behind the scenes – for example, to automatically create tickets in ServiceNow for failed jobs.

Coordination and Clarity Across Teams and Platforms

The examples above share a common theme: coordination. Effective resilience requires visibility, policy enforcement, and clean recovery across environments. AI can help strengthen these capabilities by helping teams identify what matters and act more quickly.
While the evolution of resilience from reactive recovery to continuous insight and guided action has become essential, it doesn’t need to happen all at once. Teams can start with targeted agents that address specific operational pain points and then build toward more coordinated operations as capabilities mature and teams gain confidence.
The key is to begin the ResOps journey now – because the challenges posed by evolving resilience requirements will only keep growing.
Assista ao webinar completo sob demanda to see detailed demos of Arlie Data Sense, Arlie Advisor, and conversational resilience in action, and explore how AI-enabled ResOps can help support your operational workflows.

Perguntas frequentes

Q: What is resilience operations?

A: ResOps is an operating model that unifies data security, identity resilience, and cyber recovery into a continuous, automated discipline rather than treating them as separate IT functions. ResOps helps transform resilience from a reactive response to incidents into an active practice that helps continuously understand data access patterns, detect threats and anomalies, and enable fast, intelligent recovery at scale.
Q: What is Arlie and how has it evolved?

A: Arlie, short for autonomous resilience, was first introduced in 2023 as an AI assistant to help users navigate the Commvault platform more easily. As AI capabilities have evolved, Arlie has evolved as well.
In addition to answering questions and guiding configuration, Arlie now also includes a library of purpose-built agents to address specific resilience workflows, such as surfacing operational insights, recommending protection strategies, and guiding security-aware recovery decisions. Arlie has become an entry point into operational insight rather than just a how-to assistant.
Q: How does Arlie Data Sense help with operational troubleshooting?

A: Arlie Data Sense helps teams make sense of dense operational data like job history tables and audit trails. Instead of manually scanning through hundreds of rows to find subtle warning signs or diagnose issues, users can trigger Arlie to analyze the full data set and generate an executive summary highlighting patterns, anomalies, and emerging issues.
Teams can ask follow-up questions in natural language and explore data through interactive summaries or visualizations. For failed jobs, Arlie provides root-cause analysis by analyzing logs, summarizing failures, identifying possible causes, and providing personalized next steps for resolution.
Q: What does “guided action” mean in the context of AI-enabled resilience?

A: Guided action refers to AI helping teams move from insight to response more efficiently by recommending specific actions based on analysis of operational data and protection coverage. Rather than simply surfacing information, AI agents like Arlie Advisor help evaluate resource characteristics, identify gaps between current protection and policy expectations, and present clear recommendations with reasoning.
Teams retain decision-making authority and can evaluate recommendations within their existing governance processes, but the agent helps reduce the manual effort required to identify what needs attention and what actions may be appropriate.
Q: How does MCP server enable conversational resilience workflows?

A: MCP server uses Model Context Protocol technology to enable conversational interaction with resilience workflows through natural language. Users can ask questions or request actions in everyday language, and those requests are translated into governed API calls behind the scenes.
Identity, role-based access control, and audit logging remain in place, so the conversational interface doesn’t bypass security requirements. This approach helps reduce friction for experienced teams, lower barriers for new users, and enable resilience workflows to integrate more easily with other enterprise systems like ticketing platforms through standardized interfaces.
Q: How does Commvault enable AI to respect security and governance requirements?

A: In A Commvault Cloud, AI interactions inherit the same identity and role-based access controls that govern the rest of the platform. When AI surfaces insights or recommends actions, it operates within the governance framework customers already rely on.
This means AI respects existing access controls, maintains auditability through standard logging, and operates within clearly defined policy boundaries. The architecture is designed to prevent natural language interactions or agent recommendations from bypassing the security and governance requirements already in place for the platform.
Q: Can organizations adopt AI-enabled ResOps incrementally?

A: Yes. Organizations can start with targeted AI agents that address specific operational pain points rather than transforming their entire resilience practice at once. For example, teams might begin by using Arlie Data Sense to help surface insights from operational data, then add Arlie Advisor to help maintain protection coverage at scale, and later enable conversational workflows through MCP server for easier integration with other systems.
This incremental approach allows teams to build confidence with AI-enabled capabilities, demonstrate value in specific workflows, and scale toward more coordinated, intelligent operations over time as the organization’s needs and capabilities evolve.
Vir Choksi is Principal Product Marketing Manager at Commvault.

Blogs relacionados

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Note: “MCP 2.0” is used here as a colloquial reference to the next-generation evolution of the Model Context Protocol. MCP itself uses date-based versioning (e.g., the latest release being 2025-11-25 at the time of this document’s release) and does not officially define a 2.0 release.

AI agents are no longer just answering questions – they’re taking action. They’re reading files. They’re modifying systems. And in some cases, they’re making decisions that ripple across an entire enterprise.That’s why Model Context Protocol (MCP) 2.0 matters.In a episódio recente do STRIVE, Commvault’s thought leadership series on cyber readiness, I sat down with Werner Nel, Principal, Security and AI Intelligence, at Commvault, to unpack what MCP 2.0 really changes – and why security leaders can’t afford to treat it as a minor spec update.This isn’t a theoretical conversation. It’s a practical look at how enterprises can enable AI innovation without widening their blast radius.

Pontos principais: O que o MCP 2.0 realmente muda

  • O MCP 2.0 marca uma mudança da simples adoção da IA para a prestação de contas.
  • O OAuth permite o acesso com o mínimo de privilégios para agentes de IA.
  • Esquemas estruturados podem ajudar a mitigar a injeção de prompts e o uso indevido.
  • Os fluxos de solicitação podem incluir pontos de pausa essenciais para ações de alto risco.
  • MCP 2.0 may help improve security – but doesn’t eliminate risk.
  • É essencial compreender a autoridade do agente e o alcance da ação.

Por que o MCP 2.0 é um ponto de virada

MCP 1.x was about adoption.It gave enterprises a way to connect AI models to real tools and real data. But as Werner explains, that first wave was never designed to answer the hardest question: How do we let AI agents execute real work inside the enterprise – without turning them into a security liability?

MCP 2.0 is the industry’s first serious attempt to answer that question.Instead of focusing purely on connectivity, it shifts attention to authorization, control, and visibility – three things security teams care deeply about, especially as agents move from read-only assistants to actors with real power.

As três principais mudanças na área de segurança

  1. OAuth comes to MCP. MCP 2.0 introduces OAuth support, giving enterprises a standardized way to assign permissions and enforce least privilege. Instead of relying on vague trust assumptions, agents can be scoped to exactly what they’re allowed to do—and nothing more.
  2. Structured schemas help reduce prompt injection risk. Structured schemas act like an allowlist for agent actions. If a tool isn’t explicitly defined in the schema, it won’t execute. This can help reduce prompt injection risk and other manipulation techniques that were easier to exploit in earlier implementations.
  3. Elicitation flows add a “pause button.” Elicitation flows can enable workflows to pause mid-execution so a high-risk step may trigger confirmation, validation, or even credential escalation. This can help shift teams from “log and hope” to more deliberate control over sensitive actions.

Antevisão: MCP 2.0 em ação

Esta prévia destaca por que autoridade, alcance de impacto e reversibilidade são as três questões mais importantes que as empresas devem levar em conta ao implantar agentes de IA.

The Gaps MCP 2.0 Doesn’t Solve (And Why That’s Important)

MCP 2.0 is a big step forward – but it’s not the finish line. As Werner highlights in STRIVE, there are still meaningful gaps enterprises need to account for in real-world deployments.For example, enterprises still can’t fully cryptographically prove that an MCP server is the authentic original (vs. a clone or modified copy). Similarly, even if the protocol improves authorization and input discipline, organizations still need to think about signing tools and binaries, and about the environment where MCP servers and models run – because a compromise can translate into broad access depending on how it’s deployed.The takeaway: MCP 2.0 improves the protocol, but organizations still have to make smart decisions about trust, containment, monitoring, and oversight.

Uma estrutura simples para avaliar o risco de agentes de IA

One of the most practical moments in the episode is Werner’s three-question risk lens – something CISOs and architects can apply immediately:

  • Que poderes tem o meu agente?
  • Qual é o raio de alcance da explosão?
  • Até que ponto a medida tomada é reversível?

These questions help teams move from generic “AI risk” discussions to concrete decisions about permissions, containment, and how to handle high-impact actions that may not be easy to roll back.

Assista ao episódio completo de STRIVE

This blog only scratches the surface. In the full 20-minute STRIVE podcast, you’ll hear:

  • Por que o MCP 2.0 evoluiu tão rapidamente.
  • O que os CISOs devem priorizar neste momento.
  • Para onde o MCP 3.0 provavelmente está se dirigindo.
  • Como as equipes de segurança podem acompanhar essa evolução à medida que os agentes se tornam mais autônomos.

Assista ao episódio completo de STRIVE no Readiverse.Aprofunde-se no assunto e avalie se você está pronto para isso.

Perguntas frequentes

Q: What is MCP 2.0?

A: MCP 2.0 is an updated protocol that governs how AI models interact with enterprise tools and data, with a strong focus on security, authorization, and control.Q: How is MCP 2.0 different from MCP 1.x?

A: MCP 1.x focused on connectivity and onboarding. MCP 2.0 prioritizes securing those interactions.Q: Does MCP 2.0 eliminate AI security risk?

A: No. It can help improve security hygiene but must be paired with strong architecture and governance.Q: What is an elicitation flow?

A: An elicitation flow allows AI workflows to pause for confirmation before executing high-risk actions.Chris Mierzwa is Senior Director, Portfolio Marketing, at Commvault.


Blogs relacionados

 

 

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

When you’re responsible for powering communities across southern Minnesota, cybersecurity isn’t just about protecting data. It’s about making sure the lights stay on. For Southern Minnesota Municipal Power Agency (SMMPA), implementing Commvault® Cleanroomfoi uma decisão estratégica que transformou sua abordagem à resiliência cibernética.

Enfrentando o desafio de frente

SMMPA serves as an electric wholesaler to 17 municipal utilities. With approximately 50 employees supporting critical power infrastructure, the organization must maintain constant resilience against increasingly sophisticated cyber threats, where even a short disruption could have widespread impact.

After more than a decade as a Commvault customer, SMMPA faced a new wave of cyber readiness requirements. Cyber insurance providers introduced stricter mandates, including backups isolados and malware scanning at rest.

At the same time, the team needed confidence that it could rapidly recover mission-critical systems such as domain controllers, SQL databases, and application servers, without risking the restoration of compromised data.

“As our cyber readiness requirements evolved, we started evaluating Cleanroom more seriously,” says Alan Wagner, Manager of IT & Corporate Cybersecurity at SMMPA. “We were thinking about additional ways to safeguard and protect ourselves. Cleanroom sounded like it would be a good solution for that.”

Having relied on Commvault for more than a decade and recently expanding into Commvault Cloud SaaS protection for Microsoft 365, SMMPA viewed Cleanroom as a natural next step in strengthening its cyber resilience strategy and helping it meet new compliance expectations.

Uma jornada de implementação colaborativa

SMMPA’s Cleanroom deployment in March 2025 showcased the power of collaboration between its team and Commvault. Sam Mack, IT/OT and Cybersecurity Specialist at SMMPA, appreciated the responsive partnership: “The Commvault team was quick to address any questions we had during setup.”

The team worked together to optimize its VMware virtual machine configuration for the Azure environment. “We discovered we needed to install some additional tools on the virtual machines to get them running smoothly within Cleanroom,” Sam explains. This fine-tuning meant its recovery solution was calibrated for its specific infrastructure.

The result? A successful implementation that met all SMMPA’s requirements and positioned it for robust cyber resilience.

Protegendo o que mais importa

SMMPA uses Cleanroom to protect its critical infrastructure, including file servers, application servers, SQL servers, virtual domain controllers, and print servers.

“We’re an Office 365 shop, and we use Commvault Cloud to back up that infrastructure,” Sam says. “In the event of a compromise, getting those domain controllers, file servers, and SQL servers is going to be our priority.”

The solution was particularly well suited to SMMPA’s environment. “I have to give Commvault and their teams a lot of credit for bringing Cleanroom to our attention,” Sam says. “Our cyber insurance policy is really big on pushing for backups isolados and malware scanning at rest, so Cleanroom was the perfect fit.”

O valor da confiança

While SMMPA has been fortunate not to face a real-world cyberattack requiring Cleanroom, the solution provides valuable peace of mind to the team.

“It gives me a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time,” Alan says. “Cleanroom gives us confidence that we can restore our systems without worrying that something malicious is being brought back with the data. Nothing is ever 100% guaranteed, but since implementing Cleanroom, I’ve had far fewer concerns.”

The organization conducts annual testing of its Cleanroom capabilities, with plans to potentially increase the frequency to biannual testing. This regular validation helps keep the team familiar with the recovery process and maintain confidence in its ability to respond effectively to any incident.

“Cleanroom gives us a more secure feeling that if something happened, we would be able to get back up and running in a reasonable amount of time – without the concern, or with a minimal concern, that there’s something malicious in the data being restored.”

– Alan Wagner, Manager of IT & Corporate Cybersecurity, SMMPA

As SMMPA continues to refine its cybersecurity strategy, Cleanroom remains a cornerstone of its defense. The straightforward integration with its existing Commvault infrastructure, combined with the specific capabilities that meet its cyber insurance requirements, made it an obvious choice.

Cara Peterson is Voice of the Customer Manager at Commvault.


Blogs relacionados

More related posts


CleanroomRecovery_Thumbnail_888x500

Commvault Cleanroom

Read more about Commvault Cleanroom

Pontos principais

  • A Commvault está ampliando seu portfólio de resiliência de identidade para oferecer suporte à Okta, com o início do acesso antecipado previsto para abril de 2026.
  • A identidade tornou-se um dos principais vetores de ataque, com107 bilhões de registros de identidade expostos em 2024e57% dos ataques cibernéticos tendo início com credenciais comprometidas.
  • The new capabilities can help provide automated, policy-driven protectionegranular, point-in-time recovery for critical Okta objectseconfigurations.
  • Backup data is stored in immutable, air-gapped storage to help safeguard identity environments from ransomwareeunauthorized changes.
  • The solution extends Commvault’s unified resiliência de identidade platform across hybrid environmentsewill be priced on a per-user basis.

Identity has become the new frontline of cyber defense –ethe stakes have never been higher.

Today, Commvault is announcing the expansion of its resiliência de identidade portfolio to include support for Okta, delivering automated protectionerapid recovery for one of the enterprise’s most critical control planes.Early Access is expected to begin in April 2026.

As credential theft accelerateseidentity exposures surge worldwide, organizations can no longer treat identity systems as simply another application.Identity is the gateway to everything – users, applications, APIs, automation,eincreasingly, AI agents.When identity fails, the business stops.

Por que a resiliência de identidade é importante agora

Os números revelam uma realidade alarmante:

The rapid growth of non-human, agentic,eAPI-based identities has dramatically expanded the attack surface.Meanwhile, hybrid cloud adoption, SaaS sprawl,eAI-enabled automation have elevated identity providers like Okta to mission-critical infrastructure.

While Okta is built on a resilient platform, when an identity provider is disrupted – whether due to human error, misconfiguration, ransomware, or malicious tampering – the consequences are rapid:

  • Os usuários ficam sem acesso.
  • Os aplicativos não conseguem autenticar.
  • Os sistemas geradores de receita ficam paralisados.
  • Os serviços voltados para o cliente ficam fora do ar.

And yet, many enterprises still rely on manual scriptsead hoc processes to restore identity environments – increasing downtime, operational complexity,erisk.

That’s the gap Commvault is helping to close.

Trazendo a recuperação automatizada de identidades para a Okta

Commvault’s expanded resiliência de identidade capabilities can help provide automated protectionegranular recovery for critical Okta objectseconfigurations.

Rather than rebuilding entire environments after an incident, organizations can precisely restore what was impacted – quicklyeconfidently.

“Identity is the new cyber battleground, with most modern attacks targeting identity systems,” said Pranay Ahlawat, Chief TechnologyeAI Officer at Commvault.“By extending our resiliência de identidade capabilities to Okta, we’re helping customers protect one of their most critical control planesehelping ensusre they can rapidly recover accessemaintain business continuity even in the face of disruption.”

Principais Recursos

Accelerated recovery from identity disruptions: Automated, policy-driven protection of critical Okta objects – including users, groups, applications,epolicies – can help organizations to restore access quickly following outages, operational mistakes, or cyber incidents.

Granular, point-in-time recovery: Can help precisely restore only deleted, misconfigured, or compromised objectsesettings.No full-environment rebuilds required.

Ransomware-resistant protection: Backup data is stored in Commvault-managed immutable, air-gapped storage isolated from production environments, helping safeguard identity data from ransomwareeunauthorized changes.

Streamlined, integrated recovery: Recover complex, interconnected identity systems through a unified workflow – helping reduce operational overheadesave valuable time during incidents.

Unified resiliência de identidade platform: Support for Okta extends Commvault’s single-platform approacha ambientes híbridos de identidade, ajudando a manter a aplicação consistente de políticas,governança,erecovery across providers.

Acesso antecipado previsto para abril de 2026

Commvault’s resiliência de identidade support for Okta is expected to be available through public Early Access in April 2026, with general availability planned for Summer 2026.

The solution will be offered globally as part of the Commvault Cloud Identity Resilience suiteepriced on a per-user basis.

If identity is now the enterprise control plane, resilience must extend to identity itself.With support for Okta, Commvault continues advancing unified resilience at enterprise scale – helping organizations recover faster, minimize disruption,estay operational in the face of escalating identity-driven cyber risk.

Learn more about resiliência de identidade Saiba mais no SHIFT 2025.Registre-se agoraem nosso webinar “Identidade sob ataque: recupere o controle com a resiliência de identidade da Commvault, agora com suporte à Okta”.

Perguntas frequentes

Q: Why is resiliência de identidade becoming a top priority for enterprises?
A: Identity systems now function as the enterprise control plane, governing access for users, applications, APIs,eAI agents.As credential thefteidentity-based attacks increase, disruptions to identity providers can immediately halt business operations.Protectingerecovering identity infrastructure has become mission-critical.

Q: What does Commvault’s support for Okta include?
A: The expanded capabilities help provide automated protectionegranular recovery for essential Okta objects such as users, groups, applications,epolicies.This will help organizations restore specific items impacted by outages, misconfigurations, or cyber incidents without rebuilding entire environments.

Q: How does granular, point-in-time recovery benefit security teams?
A: Instead of performing full-environment restores, teams can precisely recover only deleted or compromised objectsesettings.This approach helps reduce downtime, lower operational risk,eaccelerate restoration of normal access.

Q: How does Commvault protect identity data from ransomware?
A: Backup data is stored in immutable, air-gapped storage managed by Commvaulteisolated from production environments.This architecture helps safeguard identity configurations from ransomwareeunauthorized modifications.

Q: When will Okta support be available?
A: Public Early Access is expected to begin in April 2026, with general availability planned for Summer 2026.The offering will be available globally as part of the Commvault Cloud Identity Resilience suite.

Q: How does this expansion fit into Commvault’s broader resilience strategy?
A: Adding Okta support helps strengthen Commvault’s unified, single-platform approach to resiliência de identidade across hybrid environments.It enables consistent governança, policy enforcement,erecovery workflows, helping organizations maintain business continuity even during identity-driven disruptions.

Katharine Colucci is a Product Marketing Manager at Commvault.


Blogs relacionados

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Periods of geopolitical instability, including the current conflict in the Middle East, can lead to an increase in cyber activity from both state‑linked groups and opportunistic threat actors. Government agencies and industry organizations have encouraged businesses to maintain a heightened security posture during this time.
At Commvault, we’re doing exactly that. We’ve elevated our internal awareness, tightened our operational discipline, and reinforced our resilience measures. Commvault also works with a trusted threat intelligence partner, a CloudSEK, para ajudar a monitorar riscos em constante evolução e orientar nossa postura de segurança. Incentivamos nossos clientes, parceiros e colegas do setor a tomarem medidas semelhantes para se manterem informados e reforçarem os principais controles cibernéticos.

Em que as organizações devem se concentrar neste momento

1. Know when to shift into “heightened alert” mode

Have clear internal criteria for when to increase monitoring, limit non-essential changes on critical systems, or accelerate incident‑response readiness. These moves don’t need to be dramatic – they just need to be deliberate and well‑coordinated.

2. Strengthen identity and access discipline

During periods of heightened regional tensions, many threat actor campaigns rely on compromising user accounts. Reinforce good hygiene: regular credential rotation, strong authentication, careful review of unusual login behavior, and prompt investigation of anything that looks out of place. For practical steps to reduce identity-related risk, see Commvault’s recent blog on Melhores práticas de segurança.

3. Pay closer attention to your internet-facing perimeter and remote access

Threat actors often take advantage of internet‑facing systems or remote access tools during global flare‑ups. Ensure these systems are well‑maintained, updated, and monitored.

4. Be prepared for potential availability disruptions

DDoS and hacktivism activity often spikes during regional conflicts. Talk with your service providers, understand your mitigation options, and rehearse your internal escalation and communications plan so you’re ready if availability becomes a target.

5. Validate your ability to recover quickly

In times of uncertainty, resilience matters as much as prevention. Ensure your critical data is backed up securely, stored in multiple forms and locations, and restorable on short notice. Practicing recovery is just as important as having the backups themselves.

6. Watch for misinformation, social engineering, and false noise

Periods of conflict tend to bring surges in defacements, false breach or shutdown claims, and social‑media‑driven narratives. Treat sensational claims cautiously, verify impacts through trusted channels, report suspicious communications quickly, and maintain steady communication practices.

7. Stay aligned with trusted advisories

Follow alerts and guidance from reputable government and industry bodies. These sources regularly highlight shifts in regional threat activity and recommend practical steps organizations can take to prepare. A few resources include: Alertas de Cibersegurança da CISAUK NCSC Reports & AdvisoriesAlertas de Segurança do CERT-EU; and o Banco de Dados Nacional de Vulnerabilidades do NIST.


Stay ready, stay resilient

Cybersecurity during global instability is not about panic, it’s about posture. By staying informed, tightening foundational practices, and strengthening resilience, organizations can navigate turbulent periods with confidence.
If you’d like help reviewing your preparation or refining your approach, our team is here to support you.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Pontos principais

  • As estratégias tradicionais de resiliência estão se mostrando insuficientes diante da escala,da velocidade e da autonomia dos sistemas baseados em IA.
  • Ransomwares industrializados e ataques baseados em IA agora têm como alvo os sistemas de backup,minando os alicerces da Recovery.
  • As organizações precisam deixar de contar com equipes de segurança e Recovery isoladas e adotar um modelo unificado e contínuo,conhecido como operações de resiliência.
  • A resiliência baseada em IA requer visibilidade de dados em tempo real,detecção contínua de ameaças e Recovery inteligente e limpa em escala.
  • Plataformas modernas permitem uma Recovery rápida e verificada,ajudando as organizações a evitar o dilema entre restaurar rapidamente e restaurar com segurança.

À medida que as organizações correm para adotar a IA,os CISOs e CIOs estão chegando a uma constatação gritante: as estratégias de resiliência que funcionavam para a infraestrutura tradicional estão falhando. Sistemas que conseguiam se recuperar de ataques em horas agora podem levar dias. Abordagens de backup projetadas para dados centralizados podem ter dificuldades com cargas de trabalho distribuídas entre nuvens e plataformas de IA. Enquanto isso,as ameaças e as vulnerabilidades potenciais crescem a cada dia.Em um webinar recente,Tim Zonca,vice-presidente de marketing de portfólio da Commvault,abordou uma questão urgente enfrentada pelos líderes de segurança: como manter a resiliência quando a IA muda fundamentalmente as regras?

What Industrialized Ransomware and AI Mean for Resilience

CISOs and CIOs are under pressure. In spite of billions spent on cyber defense,nation-states and professional crime rings continue to reap ever larger payoffs from their victims. Ransomware-as-a-service has become widespread,and advanced AI automation is accelerating the industrialization of malware. By including backup systems in their attacks,adversaries are undermining the very foundation of resilience.

As attacks become more sophisticated,targets are becoming more vulnerable. AI is scaling faster than organizations can secure,with exponential data growth,fragmentation across environments,more complex supply chains,and autonomous systems operating with minimal oversight. AI agents and non-human identities now outnumber humans 80 to 1. When these systems make mistakes or expose vulnerabilities,the impact can cascade across interconnected business processes.

Breaches and failures are now almost inevitable; the only question is whether you can recover fast enough to keep your business running. For organizations using legacy systems that assume human-controlled systems,centralized data,and isolated failures,the answer may well be no.

Making Resilience Operational

As AI agents make decisions across the environment,including a significant number of errors,it’s no longer enough to focus on protecting infrastructure. Security leaders must now broaden their operational focus across three critical areas:

  • Proteger continuamente os dados na fonte e monitorar anomalias.
  • Controlar as identidades de pessoas,identidades não humanas e dispositivos que acessam e utilizam dados de forma autônoma.
  • Alcançar a recuperação previsível de dados em grande escala,sem comprometimento ou corrupção.

Tradicionalmente,a segurança de dados,a resiliência de identidade e a recuperação cibernética têm funcionado como disciplinas independentes,cada uma com sua própria equipe,ferramentas,políticas e requisitos. Esses silos deixam vulnerabilidades para os invasores explorarem e retardam a recuperação quando os sistemas de IA falham. Para preencher essas lacunas,as organizações devem unificar esses recursos em um ciclo contínuo e automatizado. Chamamos essa abordagem deoperações de resiliência (ResOps).

O ResOps abrange três requisitos essenciais para a resiliência da IA:

  • Understanding your data landscape: Knowing where data lives,its sensitivity,who’s accessing it (including AI agents and non-human identities),and what policies govern that access in real time. For AI workloads,this extends to protections like LLM prompt governance to control how models access data.
  • Continuous threat detection: Automated systems that constantly monitor for anomalies,compromised identities,and data corruption. When AI systems are making thousands of autonomous decisions,you can’t wait for periodic security reviews.
  • Intelligent recovery: Automated,comprehensive restoration for entire cloud-native applications and their dependencies. To prevent re-infection,teams must validate data integrity and conduct forensic analysis in an isolated cleanroom before moving trusted data back to production.

Enabling ResOps in practice

To help companies make the move to ResOps,Commvault has introducedCommvault Cloud Unity,o lançamento de plataforma mais significativo de nossa história. Ele foi projetado para reunir as três dimensões da resiliência:

A next-generation architecture brings AI automation to all facets of data protection,segurança de dados,resiliência de identidade,and recovery. For security and IT teams,the platform provides simplicity at scale with one experience,one policy engine,and one interface designed to protect data,predict threats,and accelerate clean recoveries.

As security leaders know all too well,recovering from the most recent backup minimizes data loss but risks restoring compromised data. Rolling back to a verified clean state may eliminate threats but means losing hours or days of business-critical transactions or AI model training.

With Commvault Cloud,o monitoramento contínuo de ameaças and verified clean recovery points help eliminate this forced choice. The platform architecture automatically maps dependencies across distributed systems,helps maintain immutable backups,and helps enable one-click restoration of entire environments. Recovery can be both fast and clean,helping minimize loss as well as risk.

See ResOps in action

Assista ao webinar completo sob demanda to learn more about ResOps,explore the architecture and services of Commvault Cloud,and rethink your resilience strategy for the AI age.


FAQs

 Q: What is Resilience Operations (Res Ops)?

A: ResOps is an operating model that unifies segurança de dados,resiliência de identidade,and recuperação cibernética into a continuous,automated discipline rather than treating them as separate IT functions. ResOps transforms resilience from a reactive response to incidents into an active practice that continuously understands data access patterns,helps detect threats and anomalies,and enables fast,intelligent recovery at scale.

Q: Why can’t traditional backup and recovery handle AI workloads?

A: Traditional backup tools were designed for centralized,human-controlled systems with isolated failures. AI workloads involve autonomous agents accessing distributed data across clouds and complex dependencies between microservices and containers,and they operate at a scale that manual processes can’t match.

When AI systems fail or are attacked,you need to recover not just data but entire application infrastructures with all their configurations,policies,and relationships – capabilities traditional backup tools lack.

Q: What does “unified resilience” mean in practice?

A: Unified resilience means bringing segurança de dados,identity management,and recuperação cibernética together under a single platform,policy engine,and operational model rather than managing them as separate functions with different teams and tools.

In practice,this provides a consistent approach to protect all workloads and data locations,automatically correlate security events with access patterns,and orchestrate comprehensive recovery that restores both data and the complete application infrastructure needed to use it.

Q: What’s the difference between cyber resilience and AI resilience?

A: Cyber resilience focuses on protecting infrastructure and recovering from security incidents,treating resilience as an operational state for confronting threats. AI resilience expands this to address challenges unique to AI-driven systems: autonomous agents making decisions with minimal oversight,exponential growth of data and non-human identities across environments,and cascading failures where problems in interconnected AI systems impact entire business operations rather than staying isolated.

Q: How does ransomware target backup systems?

A: Ransomware increasingly targets backup systems by exploiting compromised credentials with privileged access,moving laterally from production systems to connected backup repositories,or exploiting vulnerabilities in backup software itself. Modern ransomware families specifically hunt for backup infrastructure to encrypt or delete recovery points,preventing organizations from restoring clean data and maximizing pressure to pay ransom. This makes offline,immutable,or air-gapped backups essential for resilience.

Q: What is the clean vs. complete recovery dilemma?

A: The clean vs. complete recovery dilemma is the forced choice organizations face during incident response. You can recover from the most recent backup to minimize data loss but risk restoring compromised or corrupted data; or you can roll back to a verified clean state before the incident to eliminate threats but lose significant business-critical data. Traditional backup tools make organizations choose between completeness and safety,while modern resilience platforms aim to provide both simultaneously through o monitoramento contínuo de ameaças and verified recovery points.

Q: What is a cleanroom in recuperação cibernética?

A: A cleanroom in recuperação cibernética is an isolated,secure environment completely separated from production systems to help organizations safely test,validate,and analyze recovered data before restoring it to active use. Cleanrooms help enable forensic investigation of compromised systems,testing of recovery procedures,and verification that restored data is free from malware or corruption – all without risking reinfection of production environments or exposing sensitive data during analysis.

Sam Curcuruto is Director of Product Marketing at Commvault.


Related BlogsRepensando a resiliência para a era da IA

A CIO’s Perspective: Strengthening Business Resilience in the AI Era

Resiliência contra a máquina de IA

Cleanroom Recovery abrem caminho para uma nova era em resiliência cibernética

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Pontos principais

  • “Instant restore” claims often break down at scale due to real-world I/O operations per second (IOPS), rehydration, and infrastructure constraints.
  • Mass live mounts on deduplicated backup storage can cause performance collapse, forcing slow rehydration back to primary storage.
  • Cleanrooms help enables parallel forensic investigation and business recovery instead of serial, delay-driven downtime.
  • Identity compromise expands the blast radius, making isolated recovery and Active Directory (AD) restoration critical to secure operations.
  • Automated cleanroom runbooks and repeatable testing help organizations validate real recovery metrics before a crisis occurs.

Let’s start with a quick story about a “ransomware‑proof” environment that took 72 hours to recover, way beyond the organization’s expectations for recovery time objective. It is exactly the kind of situation where Commvault’s Cleanroom could have helped turn a painful, three‑day outage into a faster, more controlled recovery with less risk.

War Story: Physics vs. Marketing

On Reddit, a user shared how the financial services firm they work for was hit by a breach. They assumed they had a “dream stack” for quick recovery (but can you really have a “dream stack” without Cleanroom?): immutable backups, secure storage snapshots, and a modern hypervisor. The datasheets promised “instant mass restore,” yet the business sat offline for three days while everyone tried to drag their environment back to life.

The root cause was not that backups failed, but that the real‑world physics of rehydration, forensics, and identity were never tested at scale. The original poster mentioned that having access to a cleanroom environment would have sped up the process. Let’s dig into this further and address why.

Commvault’s Cleanroom is designed to address exactly these weak points: It helps automate clean, isolated recovery into the cloud, validates data, and orchestrates recovery in a way that aligns with how incidents actually unfold, not just how diagrams look on slides.

Problem 1: The Rehydration Trap

In the story, “live mounting” a handful of virtual machines (VMs) worked fine, but trying to live mount hundreds crushed the backup appliance. The random I/O running directly on deduplicated, compressed backup storage collapsed the IOPS, forcing the team to rehydrate everything back to primary Non-Volatile Memory Express at about 3 TB/hour for roughly 100 TB of data.

Commvault Cleanroom helps recover workloads into an isolated Azure‑based cleanroom built on scalable cloud compute and storage instead of trying to run production at scale off a backup appliance.

This allows you to restore critical VMs into a purpose‑built recovery environment, use cloud elasticity to absorb I/O, and automate the recovery sequence so the right systems (identity, core apps, critical data) come up first without bottlenecking on a single backup target.

Problem 2: The Forensic Drag

In the audit, the tech stack was ready in about four hours, but legal delayed touching anything for 72 hours because they had no pre‑provisioned cleanroom. Without an isolated environment with zero routes back to production, the forensics team could not safely investigate while the business recovered, so everyone waited for the all-clear before starting any real restore.

Cleanroom provides an on-demand, isolated recovery environment explicitly built for simultaneous recovery and forensic analysis. You can spin up a fenced cleanroom in Azure in hours, recover systems into it, and let security and legal teams perform read‑only forensics and threat scanning while operations validates applications and prepares for cutover – dramatically shrinking “forensic drag” as a contributor to downtime.

Problem 3: Identity Blast Radius

The environment in the story had a single admin account with access to both the hypervisor and backup console, which meant if attackers pivoted that far, immutability could become just another setting they flipped off. Identity, not just data, was the real blast radius problem.

Cleanroom is designed to help reduce dependency on the compromised production identity plane during recovery, allowing isolated access and planned support for AD restoration in the cleanroom.

By recovering identity services into an isolated cleanroom and using separate, least‑privilege access paths, you can help validate AD, help enforce proper authorizations, and help protect backup control planes from being trivially compromised by the same credentials that were used in production.

How Cleanroom Would Change This Story

If this customer had used Cleanroom, their recovery story could have been very different.

For organizations that already invest in “ransomware‑proof” stacks, the missing piece is often not more features but a cleanroom strategy that respects physics, identity, and legal reality. Commvault Cleanroom is designed to close that gap and help turn recovery from a three‑day war story into a controlled, provable, and much faster operation.

Perguntas frequentes

Q: Why did the “instant mass restore” approach fail in the ransomware scenario?
A: While live mounting a few VMs worked, scaling to hundreds overwhelmed the backup appliance due to I/O constraints. Deduplicated and compressed backup storage is not designed to handle full production workloads at scale, leading to performance collapse and delayed recovery.

Q: What is the “rehydration trap” in disaster recovery?
A: The rehydration trap occurs when organizations must restore large volumes of compressed backup data back to primary storage before systems can operate normally. This process is limited by throughput rates, which can dramatically extend recovery times when dealing with tens or hundreds of terabytes.

Q: How does a cleanroom help reduce forensic-related downtime?
A: A cleanroom provides an isolated environment where forensic teams can safely investigate while IT simultaneously restores systems. This parallel approach helps eliminate long waiting periods for legal or security approval before beginning recovery efforts.

Q: Why is identity such a critical factor in ransomware recovery?
A: If attackers compromise administrative credentials tied to both production and backup systems, immutability controls may no longer provide protection. Isolated identity recovery and least-privilege access can help limit blast radius and support a safer restoration process.

Q: How does Cleanroom help improve recovery orchestration?
A: Cleanroom helps automates workload sequencing, cleanpoint validation, and cloud-based recovery infrastructure provisioning. This structured approach aligns recovery with how incidents actually unfold, helping organizations regain control faster and with greater confidence.

Q: What is the strategic lesson for organizations with “ransomware-proof” stacks?
A: Advanced features alone do not guarantee fast recovery. A cleanroom strategy that accounts for infrastructure physics, identity isolation, and legal realities helps enable organizations to turn theoretical resilience into measurable, repeatable recovery performance.

Nico Guerrera is Senior Solutions Marketing Manager at Commvault.

Blogs relacionados

Recuperação de florestas do Active Directory: Por que os métodos manuais não são mais viáveis

Teste de recuperação: A peça que falta na maioria dos programas de resiliência cibernética

Seu manual moderno para resposta rápida e recuperação limpa

Desbloqueando a resiliência cibernética: o poder das salas limpas

Why Cleanroom and Cyber Testing are Critical for Cyber Resilience

More related posts


Cyber Resilience

Read more about Cyber Resilience

In the current cybersecurity landscape, we are drowning in data but starving for insight. Traditional AI excels at pattern recognition (correlation), but in high-stakes security environments, correlation is a liability.

Causal AI provides the “reasoning” (the why), while agentic AI provides the “execution” (the how). To build truly resilient systems, we must move beyond predicting threats to understanding the causal mechanisms that allow them to flourish.

1. The Problem Statement: The Crisis of Trust

Modern Security Operations Centers (SOCs) face a fundamental trust gap. Legacy predictive models often flag “anomalies” that are merely noise, leading to alert fatigue.

  • The problem: Data is noisy, correlated, and lacks labels.
  • The consequence: Analysts struggle to distinguish between a “correlated event” (a user logging in from a new IP) and a “causal event” (that login directly initiating unauthorized data egress).
  • The solution: Integrating causal AI to provide an auditable, human-readable logic chain for every automated action.

2. Causal AI in Action: Cybersecurity Use Cases

By applying structural causal models, organizations can shift from reactive patching to proactive resilience.

  • Causal chain of breach formation: Instead of viewing a breach as a single event, causal AI maps the “butterfly effect” of minor configuration changes and how they chain together to create a critical vulnerability.
  • Optimal control selection: If a budget only allows for one upgrade, causal AI can simulate the “do-calculus”: If we implement micro-segmentation instead of endpoint detection and response, how does the causal probability of lateral movement change?
  • Vulnerability prioritization via causal risk: Move beyond the static Common Vulnerability Scoring System. Use causal AI to prioritize vulnerabilities based on their actual “causal reachability” within your specific network topology.
  • Digital twins for posture simulation: Create a “security digital twin” to run “what-if” interventions. This allows CISOs to stress-test resilience strategies in a virtual environment before deploying them to production.

3. The Resilience Framework: Reasoning + Execution

True resilience is the ability of a system to maintain state and purpose during an attack. We propose a two-tier architecture:

Component Role Analog
Causal AI Reasoning & decisioning The brain
Agentic AI Execution & recovery The hands
The Feedback Loop:

When an agentic AI performs a task (e.g., isolating a compromised server), causal AI monitors the logs (Step 4: State Recovery). If the agent fails, causal AI analyzes the telemetry to determine if it was a systemic failure or an external cause (e.g., “The agent didn’t fail; the inventory API returned a null value”).

4. Graceful Degradation and Fallback Tiers

Resilience requires knowing when to stop. We implement “causal fallbacks” so that if the AI reasoning becomes uncertain, the system degrades safely rather than failing catastrophically.

Tier 1: Full autonomy: Causal AI confirms high confidence in the root cause; agentic AI remediates.

Tier 2: Augmented human-in-the-loop: Causal AI provides the “reasoning path” to a human analyst for rapid approval.

Tier 3: Rules-based mode: The system reverts to “causal Six Sigma” logic – a strict, pre-defined safety protocol that prioritizes uptime over optimization.

Tier 4: Fail-closed: If causal integrity is lost, the system isolates critical segments to prevent the butterfly effect of a spreading breach.

5. Industry Impact: Beyond the SOC

  • Healthcare & Internet of Medical Things: Causal AI can distinguish between a malfunctioning heart monitor (systemic noise) and a targeted attack on medical telemetry.
  • Telecommunications & 5G: Managing the complex causal dependencies of network slicing to verify that a breach in a low-security slice cannot causally impact emergency services.

6. Measuring Success: The New KPIs

Success in a causal AI–enabled environment is measured by the quality of decisions, not just the quantity of blocked threats:

  • Mean time to causal discovery: The speed at which the true root cause is identified vs. the initial symptom.
  • Intervention efficacy: The percentage of security changes that resulted in the predicted reduction of risk.
  • Counterfactual accuracy: How closely the digital twin simulations match real-world incident outcomes.

What’s Next

The future of cyber resilience is not just smarter AI but more logical AI. By combining the execution power of agentic systems with the reasoning depth of causal AI, we can build security architectures that don’t just survive attacks – they understand them.

Vidya Shankaran is Field CTO at Commvault.

© 2025 Commvault. See www.commvault.com/IPfor trademarks and patents.

More related posts


Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience
Thumbnail_Blog-Dangerous-Silos-IDC-Resops-2026 (1)

The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan

Read more about The Importance of Recovery Point Objective (RPO) in Your Business Continuity Plan
Thumbnail_Blog-IDC-Resops-2026

Business Continuity Planning for the Cloud-Native Era

Read more about Business Continuity Planning for the Cloud-Native Era

Key Takeaways

  • A Commvault Cloud Backup & Recovery for DevOps now includes support for Atlassian Jira,extending enterprise-grade data protection to mission-critical project workflows.
  • Backups automatizados e baseados em políticas,além de opções de recuperação granular,ajudam as equipes a restaurar rapidamente espaços,itens de trabalho e configurações do Jira.
  • Features integradas de resiliência cibernética,como backups imutáveis e armazenamento isolado na nuvem,ajudam a proteger os dados do Jira contra ransomware e alterações não autorizadas.
  • A proteção unificada no Jira,Azure DevOps,GitHub e GitLab reduz a proliferação de ferramentas e simplifica a resiliência dos dados de DevOps.
  • A proteção do Jira está disponível por meio do acesso para Adotantes Antecipados,com disponibilidade geral prevista para março de 2026.

Temos o prazer de anunciar a extensão doCommvault® Cloud Backup & Recovery for DevOpspara incluir suporte ao Atlassian Jira. Essa atualização trazproteção,Recovery e resiliência cibernética de nível empresarialto Jira,helping organizations safeguard mission-critical project data against data loss and cyber incidents.

With this release,teams now have a unified way to protect critical sprint plans,work items,and configurations alongside their code,pipelines,and repositories in Azure DevOps,GitHub,or GitLab,all with a single solution.

Why Protecting Jira Data Matters

Jira has become a cornerstone for many organizations,supporting everything from agile software development and product releases to IT service management. It houses the plans,workflows,and task data that teams depend on to help execute mission-critical work.

Despite its importance,Jira is not immune to data loss. Accidental deletions,misconfiguration,and malicious activity can quickly erase valuable project history and disrupt active work.

When Jira data is lost or becomes unavailable,teams lose visibility,sprints stall,releases are delayed,service commitments are missed,and productivity suffers as teams attempt to recreate lost information.

A reliable backup and recovery strategy for Jira is critical to help maintain continuous business and help minimize the risk of downtime,operational disruption,and potential failure to meet data retention or regulatory compliance requirements.

Enterprise-Grade Protection for Jira A Commvault Clouddelivers enterprise-scale protection and recovery for Jira,helping organizations safeguard mission-critical Jira data against cyber incidents,disasters,and operational mistakes.

Key features:

  • Automated,policy-based backups of Jira spaces,work items,and configurations,including attachments,custom fields,and board settings.
  • Granular recovery of individual spaces or work items,as well as full-site recovery to a specific point in time.
  • Simplified compliance through centralized control,audit logging,and extended retention to help support regulatory and internal requirements.
  • Cyber resilience withbackups imutáveis,armazenamento isolado na nuvem,and arquitetura de confiança zeropara ajudar a proteger os dados contra ransomware e alterações não autorizadas.
  • Unified protection for Jira,Azure DevOps,GitHub,GitLab,and other enterprise workloads from a single platform.

Unifying DevOps Data Resilience with Commvault

By unifying Jira protection with other DevOps platforms in A Commvault Cloud Backup & Recovery for DevOps,enterprises can gain a holistic approach to data resilience across the full DevOps lifecycle – from planning and issue tracking to code and delivery. The result is fewer tools,reduced complexity,and confidence that sprint plans and backlog items are rapidly recoverable when it matters most.

Early Availability

Atlassian Jira protection is now available through Early Adopter access with general availability planned for March 2026.

Learn more about Commvault’s support for Atlassian Jira,Saiba mais no SHIFT 2025.

To learn more about how to get access to getting access to Jira protection or schedule a demo,contact your Commvault account team.

FAQs

Q: Why is backing up Atlassian Jira important?
A: Jira houses critical sprint plans,workflows,and issue data that many teams rely on to deliver projects and services. Data loss from accidental deletion,misconfiguration,or malicious activity can disrupt releases and impact productivity,making a reliable backup and recovery strategy essential.

Q: What Jira data can A Commvault Cloud protect?
A: A Commvault Cloud helps protect Jira spaces,work items,configurations,attachments,custom fields,and board settings. This comprehensive coverage helps organizations maintain full visibility and recover both detailed items and entire sites when needed.

Q: How does recovery work with A Commvault Cloud for Jira?
A: The solution helps support granular recovery of individual spaces or work items,as well as full-site recovery to a specific point in time. This flexibility enables teams to restore exactly what they need without unnecessary disruption.

Q: How does this solution support compliance and cyber resilience?
A: Centralized control,audit logging,and extended retention help organizations meet regulatory and internal requirements. Immutable backups,armazenamento isolado na nuvem,and a arquitetura de confiança zero help strengthen protection against ransomware and unauthorized changes.

Q: Can Jira protection be managed alongside other DevOps platforms?
A: Yes. A Commvault Cloud unifies protection for Jira with Azure DevOps,GitHub,GitLab,and other enterprise workloads within a single platform,helping reduce complexity and enable a holistic approach to DevOps data resilience.

Q: When will Jira protection be generally available?
A: Atlassian Jira protection is currently available through Early Adopter access,with general availability planned for March 2026. Organizations can contact their Commvault account team to learn more or schedule a demo.

Katharine Colucci is a Product Marketing Manager at Commvault.

 

More related posts


Thumbnail_Blog_DevOps_2025

Enhance Resilience with Backup & Recovery for DevOps

Read more about Enhance Resilience with Backup & Recovery for DevOps
Zz05MThhZTc3NmU0MTQxMWVmYTYwZWJlYTg2ZTllNjQ5Yw

A Blueprint for Effective Cloud Recovery

Read more about A Blueprint for Effective Cloud Recovery
Commvault-cloud-availability-LinkedIn

Experience True, Cloud Cyber Resilience – Available now in Commvault Cloud

Read more about Experience True, Cloud Cyber Resilience – Available now in Commvault Cloud
Thumbnail_Blog-SHIFT-Announcement-Recover-Clean-2025-Linkedin

Recover Clean, Recover Fast

Read more about Recover Clean, Recover Fast
Thumbnail_Blog–CloudRewind2025–Linkedin

Built for Resilience, Optimized for Scale: The Cloud Rewind Architecture

Read more about Built for Resilience, Optimized for Scale: The Cloud Rewind Architecture
Thumbnail_Blog-SHIFT-Announcement-Commvault-Cloud-Unity-2025-Linkedin

A New Era of Enterprise Resilience

Read more about A New Era of Enterprise Resilience