Skip to content

Backup and Recovery na nuvem explicados: da detecção de ameaças à Recovery completa

Saiba como o Backup and Recovery na nuvem funcionam para ajudar a proteger dados intactos, validar a Readiness para recuperação e restaurar as operações comerciais após um ataque de ransomware ou incidente cibernético.


O processo ideal de Backup and Recovery na nuvem começa com a detecção de ameaças, como ransomware, acessos suspeitos ou atividades anormais nos dados. As organizações podem, então, obter cópias de backup limpas e imutáveis; validar pontos de recuperação não afetados; e isolar sistemas comprometidos. Uma vez verificados, os aplicativos e dados críticos podem ser restaurados por meio de processos automatizados de Recovery, ajudando a minimizar o tempo de inatividade, reduzir a perda de dados e restaurar as operações comerciais de forma rápida e segura.


A resiliência cibernética é cada vez mais avaliada pelo que acontece depois que os invasores conseguem entrar. As organizações têm investido pesadamente em prevenção, detecção e resposta, mas o ransomware, a exploração de vulnerabilidades, o uso indevido de credenciais, as configurações incorretas na nuvem e o comprometimento de terceiros continuam a interromper as operações.

Para muitas equipes, o desafio da Recovery não se resume mais simplesmente à existência de backups. Trata-se de saber se esses backups estão intactos, protegidos, validados e prontos para restaurar serviços críticos quando os sistemas de produção não forem mais confiáveis.

Essa distinção é importante porque os ataques cibernéticos continuam a gerar tanto riscos aos dados quanto interrupções operacionais. De acordo com oRelatório de Investigações sobre Vazamentos de Dados 2026da Verizon, o ransomware esteve envolvido em 48% dos vazamentos, um aumento em relação aos 44% do ano anterior. O relatório também constatou que a exploração de vulnerabilidades se tornou o vetor de acesso inicial mais comum para os vazamentos, subindo para 31%, enquanto o uso indevido de credenciais caiu para 13%.

Os esforços de Backup and Recovery na nuvem precisam dar suporte a todo o processo, desde a detecção até a restauração. Isso começa com a identificação de atividades suspeitas antes que os dados comprometidos sejam restaurados. Continua com pontos de Recovery protegidos e imutáveis, que oferecem às equipes opções de Recovery viáveis quando os sistemas de produção não são mais confiáveis.

A partir daí, as organizações precisam de uma maneira de validar quais pontos de recuperação estão livres de ameaças e restaurar cargas de trabalho críticas na ordem correta. O resultado é uma estratégia de recuperação que ajuda as equipes a passar da resposta a incidentes para a restauração operacional com mais confiança.

 


Por que o Backup and Recovery na nuvem são uma estratégia de resiliência cibernética?

Traditional backup strategies were designed to help organizations recover from hardware failures, accidental deletion, and localized outages. Those use cases still matter, but today’s recovery requirements are broader.

Ataques cibernéticos podem afetar simultaneamente cargas de trabalho de produção, sistemas de identidade, configurações na nuvem, aplicativos SaaS e ambientes de backup. Quando isso ocorre, a recuperação não se resume apenas a restaurar uma cópia dos dados. Trata-se de determinar em quais sistemas se pode confiar, quais pontos de recuperação permanecem intactos e quais serviços precisam ser restabelecidos primeiro.

É por isso queo Backup and Recovery na nuvemse tornaram uma parte essencial da resiliência cibernética. Uma estratégia moderna deve ajudar as equipes a detectar atividades suspeitas, proteger os dados de Recovery, validar a integridade do Backup e restaurar operações críticas em uma sequência controlada. Ela também deve ajudar a viabilizar testes regulares, pois um plano de Recovery que não tenha sido testado pode não funcionar como esperado durante um incidente real.

Isso marca uma mudança do backup como uma apólice de seguro para a capacidade de recuperação como uma capacidade operacional. As cópias armazenadas ainda são importantes, mas são apenas uma parte da equação da recuperação. As equipes também precisam ter certeza de que os dados de recuperação não foram alterados, que os fluxos de trabalho de restauração foram testados e que a empresa sabe quais serviços devem ser restaurados primeiro.

O Backup and Recovery na nuvem tornam-se mais fáceis de entender quando vistos como um ciclo de vida. Os cinco estágios abaixo mostram como as organizações podem passar da detecção precoce de ameaças à Recovery validada e à melhoria da resiliência a longo prazo.


Etapa 1: Detectar ameaças antes que o risco à Recovery se espalhe

Recovery começa antes mesmo de os sistemas serem restaurados. Em um incidente cibernético, a primeira prioridade é entender se atividades suspeitas afetaram os dados de produção, os dados de backup ou ambos.

Se as equipes restaurarem a partir de um ponto de Recovery comprometido, elas podem reintroduzir arquivos corrompidos, artefatos de malware ou alterações não autorizadas no ambiente. Esse risco torna a detecção de ameaças uma parte importante do Backup and Recovery na nuvem, e não apenas uma preocupação das operações de segurança.

Estratégias modernas de Recovery devem incluir visibilidade sobre atividades anormais em cargas de trabalho, ambientes de backup e pontos de Recovery. As equipes podem precisar investigar sinais como:

  • Comportamento incomum de criptografia
  • Picos repentinos de exclusão
  • Alterações inesperadas de privilégios
  • Padrões anormais de backup
  • Indicadores de malware

Esses sinais podem ajudar as equipes a entender para onde um ataque pode ter se espalhado e quais dados podem exigir uma análise adicional antes da restauração.

Timing is another essential factor. Microsoft’s O Relatório de Defesa Digital 2025da Microsoft constatou que a maioria dos ataques investigados por sua Equipe de Detecção e Resposta (DART) apresentou tempos de permanência curtos, o que significa que as equipes de recuperação podem não ter semanas para compreender o escopo total do comprometimento antes que os invasores se desloquem lateralmente, acessem dados confidenciais, interfiram nos serviços ou tentem afetar os sistemas de backup. O contexto da detecção pode ajudar as equipes a evitar tratar todos os pontos de recuperação como igualmente confiáveis.

59% dos ataques investigados pelo Microsoft DART tiveram tempo de permanência de sete dias ou menos, o que torna a detecção precoce fundamental para as decisões de Recovery.
Fonte:Relatório de Defesa Digital da Microsoft 2025

Threat detection doesn’t eliminate recovery risk on its own. It helps create a more informed recovery process. When suspicious activity is identified early, organizations can isolate affected systems, investigate impacted data, and avoid restoring recovery points that may reintroduce the same threat.

Isso proporciona às equipes de segurança, TI e Recovery um ponto de partida mais claro para a próxima etapa: proteger pontos de recuperação não comprometidos antes que os invasores possam alterá-los ou removê-los.


Etapa 2: Proteger os pontos de recuperação íntegros contra ataques

Em um incidente cibernético, os backups não são apenas cópias armazenadas. Eles fazem parte do caminho de Recovery, o que significa que os invasores podem tentar interferir neles. Se os dados de backup forem alterados, criptografados, excluídos ou tornados inacessíveis, a organização pode perder uma de suas melhores opções para restaurar as operações sem depender de sistemas de produção comprometidos.

That’s why os pontos de recuperação intactosprecisam de proteção em camadas. O armazenamento de backup imutável e indelével pode ajudar a preservar os dados por um período de retenção definido. Cópias externas ou isoladas ajudam a criar uma separação do ambiente de produção. Criptografia, controles de acesso e permissões baseadas em funções ajudam a limitar quem pode acessar ou alterar as configurações de backup. Juntas, essas medidas de segurança tornam mais difícil para os invasores interferirem nos dados de que as equipes podem mais precisar durante a recuperação.

O objetivo é preservar as opções de recuperação. O relatório da Verizon de 2026 constatou que69% das vítimas de ransomwareem seu conjunto de dados não pagaram o resgate, um aumento em relação aos 65% do ano anterior. O relatório também observa que a mediana dos pagamentos de resgate continuou a diminuir, o que é atribuído, em parte, a melhores adaptações defensivas e ao aumento da resiliência das vítimas. As equipes precisam de backups íntegros que possam realmente usar, de modo que pagar um resgate não seja o único caminho de volta aos negócios.

A conhecida regra de backup 3-2-1 ainda oferece uma base útil: mantenha três cópias dos dados, em duas mídias ou plataformas diferentes, com pelo menos uma cópia armazenada fora do local ou isolada. As estratégias modernas de Backup and Recovery na nuvem frequentemente ampliam esse modelo com armazenamento imutável, padrões com isolamento físico, retenção baseada em políticas e cópias replicadas em ambientes de nuvem ou híbridos.

Com pontos de recuperação protegidos em vigor, as equipes podem reduzir suas opções de restauração e avançar para a validação com uma visão mais clara do que está pronto para ser recuperado.


Etapa 3: Verificar quais backups estão prontos para restauração

Ter backups não significa estar pronto para a recuperação. Antes de restaurar os sistemas de produção, as equipes precisam saber quais pontos de recuperação estão utilizáveis, quais cargas de trabalho foram afetadas e quais dependências devem ser restauradas junto com elas.

Um backup recente pode conter os dados comerciais mais atualizados, mas também pode incluir arquivos corrompidos, alterações não autorizadas ou vestígios de malware. Um backup mais antigo pode estar mais limpo, mas pode causar maior perda de dados. A validação ajuda as equipes a fazer essa escolha com base em evidências, em vez de suposições.

Esse trabalho começa com a definição do escopo do incidente. As equipes de segurança e de TI precisam entender quando a atividade suspeita começou, quais sistemas foram afetados e se serviços de identidade, bancos de dados, compartilhamentos de arquivos, aplicativos SaaS ou configurações em nuvem foram afetados.

Elas também precisam confirmar se o ponto de recuperação suporta o aplicativo como um todo, e não apenas os dados por trás dele. Uma restauração de banco de dados, por exemplo, pode depender da disponibilidade e do estado adequado dos servidores de aplicativos, permissões, chaves de criptografia, rotas de rede e serviços de identidade.

Ambientes de Recovery isolados podem ajudar as equipes a testar essas condições antes de restaurar o ambiente de produção. Em um ambiente controlado, as equipes podem, com segurança:

  • Analisar pontos de Recovery selecionados.
  • Analisar alterações nos arquivos.
  • Confirmar a inicialização do aplicativo.
  • Testar o acesso dos usuários.
  • Verificar se os sistemas dependentes se comportam conforme o esperado.

A validaçãotambém deve orientar a sequência de Recovery. As equipes podem precisar restaurar primeiro os serviços de identidade, depois a infraestrutura central, em seguida os aplicativos essenciais e, por fim, as cargas de trabalho de suporte.

Ao testar os pontos de recuperação antes da restauração, elas podem restringir suas opções e decidir quais sistemas estão prontos para serem restaurados, quais precisam de análise adicional e quais devem permanecer isolados até que o risco seja melhor compreendido.

A próxima etapa é quando essa decisão se transforma em ação: restaurar os sistemas, aplicativos e dados de que a empresa precisa em primeiro lugar.


Etapa 4: Restaurar as operações essenciais na ordem correta

A restore plan starts with the organization’s minimum viable operating state. That means identifying the people, systems, applications, data, and communication channels the business needs to function at a basic level during a disruption.

Para algumas organizações, isso pode começar com serviços de identidade e comunicações com os funcionários. Para outras, pode priorizar aplicativos voltados para o cliente, sistemas de pagamento, sistemas clínicos, operações de fabricação ou plataformas de logística. A ordem deve refletir o impacto nos negócios, não apenas a conveniência técnica.

Dependencies are where many recovery plans become more complicated. An application may be listed as “critical,” but it still depends on identity, DNS, network connectivity, databases, storage, encryption keys, APIs, and monitoring. If those pieces are not restored in the right state, the application may come back online but remain unusable. That is why recovery teams need dependency mapping before an incident, not during one.

Manuais de procedimentos e fluxos de trabalho orquestrados ajudam a transformar essas decisões em etapas repetíveis. Eles podem definir quem aprova a restauração, qual ambiente deve ser usado, quais verificações devem ocorrer antes que o acesso à produção seja restaurado e quando a próxima camada de sistemas pode entrar em operação. Isso é importante quando as equipes de segurança, infraestrutura, aplicativos, nuvem e negócios estão trabalhando simultaneamente.

A restauração também precisa de pontos de verificação. Após o retorno de cada carga de trabalho importante, as equipes devem confirmar se os usuários conseguem se autenticar, se os dados estão disponíveis, se as integrações estão funcionando e se o monitoramento está em vigor. Essas verificações ajudam a detectar problemas antes que a Recovery se expanda para a próxima camada de sistemas.

A velocidade ainda é importante, mas o controle é igualmente importante. Uma restauração rápida pode gerar mais trabalho se os dados errados forem recuperados, se faltarem controles de acesso ou se uma aplicação for restaurada sem os sistemas necessários para sua execução. A abordagem mais eficaz é restaurar em fases, confirmar que cada serviço crítico está funcionando e, então, continuar expandindo a Recovery à medida que o ambiente se estabiliza.


Etapa 5: Transformar as lições aprendidas com a Recovery em uma continuidade mais sólida

Depois que os serviços essenciais forem restaurados, as equipes ainda precisam entender o que funcionou, o que causou atrasos e em que pontos o plano de Recovery não correspondeu à realidade. Esse acompanhamento é o que transforma o Backup and Recovery na nuvem em uma atividade de resposta em uma prática contínua de resiliência.

O primeiro passo é analisar a própria Recovery. As equipes devem fazer perguntas como:

  • Com que rapidez as equipes detectaram atividades suspeitas?
  • Os pontos de recuperação válidos foram fáceis de identificar?
  • Quais etapas de validação demoraram mais do que o esperado?
  • Em que pontos os fluxos de trabalho de restauração ficaram lentos?
  • As pessoas certas foram envolvidas no momento certo?

Essas respostas podem revelar lacunas que nem sempre são de natureza técnica. A Recovery pode ser bem-sucedida e, mesmo assim, expor problemas relacionados à tomada de decisões, comunicação, aprovações ou transferências de responsabilidade entre equipes.

Essas constatações devem ser incorporadas diretamente à próxima versão do plano de recuperação. Se um aplicativo crítico dependia de um sistema que não estava documentado, atualize o mapa de dependências. Se os controles de acesso retardaram a restauração, esclareça o processo de aprovação. Se os testes de recuperação deixaram de incluir uma carga de trabalho essencial, adicione-a ao próximo exercício. Se os líderes de negócios não tinham visibilidade sobre o que foi restaurado e o que ainda estava fora do ar, melhore os relatórios e os caminhos de escalonamento.

Testes regulares são o que mantêm esse trabalho com os pés no chão. Exercícios simulados, restaurações isoladas, testes de Recovery sem interferências e validação de Recovery entre nuvens ajudam as equipes a identificar problemas antes que um incidente real as force a aprender sob pressão. Eles também ajudam a fornecer aos líderes evidências mais claras de onde a organização está pronta e onde ainda há trabalho a ser feito.

Com o tempo, o objetivo é um programa de Recovery que se torne mais preciso após cada teste e cada incidente. As equipes ficam mais bem preparadas, as etapas de Recovery são melhor compreendidas e a organização tem um caminho mais claro para manter as operações essenciais em funcionamento durante interrupções.


Transformando a Recovery na nuvem em resiliência empresarial

 Cloud backup and recovery now plays a larger role than traditional data protection alone. It is the connected process of detecting recovery risk, protecting backup data, validating clean restore options, and restoring critical services when production environments can no longer be trusted.

Em um incidente cibernético, essas atividades não podem ser realizadas como etapas separadas. O contexto da ameaça deve determinar quais backups devem ser revisados. A proteção do backup deve preservar as opções de Recovery de que as equipes possam precisar. A validação deve determinar o que está pronto para ser restaurado. A restauração deve trazer de volta os serviços dos quais a empresa depende, em uma ordem controlada.

Um backup que não seja confiável, não tenha sido testado ou não possa ser restaurado no momento certo pode não proporcionar à empresa o resultado de que ela precisa. Um processo de restauração que ignore a identidade, as dependências de aplicativos ou as prioridades de negócios pode deixar os sistemas tecnicamente recuperados, mas operacionalmente incompletos.

A oportunidade maior é tratar a recuperação como uma prática contínua de resiliência. Isso significa testar planos antes de um incidente, atualizar mapas de dependências à medida que os ambientes mudam e usar cada exercício ou evento de recuperação para melhorar a próxima resposta.

As organizações que se recuperam mais rapidamente não são necessariamente aquelas com o maior número de cópias de dados. É fundamental saber quais dados são utilizáveis, quais serviços são mais importantes e como restaurá-los sob pressão.

O desafio é tornar a Readiness para a recuperação tão operacional quanto a detecção e a resposta. O Backup and Recovery na nuvem fornecem uma base prática para esse trabalho quando tratados como um caminho contínuo, desde a detecção de riscos até a restauração dos negócios.

As organizações devem desenvolver essa capacidade para se posicionarem melhor a fim de restaurar dados íntegros, recuperar serviços críticos e manter os negócios em andamento quando ocorrerem interrupções.

 

Acelerar a Recovery segura após ataques cibernéticos

Learn more about how Commvault’s data backup and recovery solutions can help organizations detect threats, recover clean data, and reduce downtime.

Perguntas frequentes

Qual é a diferença entre backup na nuvem e recuperação de desastres?

O backup em nuvem tem como objetivo criar cópias seguras dos dados para restauração, enquanto a recuperação de desastres se concentra na restauração de aplicativos, sistemas e operações comerciais após uma interrupção ou um ataque cibernético. Juntos, eles ajudam a garantir a continuidade dos negócios e a resiliência.

Por que os backups imutáveis são importantes para a resiliência cibernética?

Os backups imutáveis e indeléveis foram projetados para ajudar a impedir que os dados de backup sejam alterados, criptografados ou excluídos dentro das configurações de retenção definidas. Em combinação com o Commvault AirGap e a identificação automatizada do Cleanpoint, os recursos de backup imutável da Commvault ajudam a manter as organizações preparadas, com uma fonte de recuperação verificada e limpa disponível quando os sistemas de produção forem comprometidos.

O que devo procurar em uma solução de Backup and Recovery na nuvem?

Procure uma plataforma que unifique ambientes híbridos e multicloud, armazenamento imutável, orquestração automatizada de Recovery e gerenciamento centralizado. O Commvault Cloud foi projetado levando em conta esses requisitos, ajudando as organizações a proteger infraestruturas diversificadas e, ao mesmo tempo, minimizar o tempo de inatividade durante a Recovery e a complexidade operacional.

A solução de backup da Commvault oferece proteção contra ransomware e backups em ambiente isolado (air-gapped)?

Sim. A Commvault ajuda as organizações a fortalecer a resiliência cibernética por meio de backups imutáveis, opções de recuperação em ambiente isolado, detecção de ameaças, recursos de recuperação limpa e proteção em camadas contra ransomware, projetados para ajudar a reduzir os riscos de Recovery e o tempo de inatividade.

A Commvault oferece testes automatizados de backup e relatórios de conformidade?

Sim. A Commvault oferece testes automatizados de Recovery, validação de backup, relatórios de conformidade e visibilidade pronta para auditoria, a fim de ajudar as organizações a verificar a capacidade de recuperação, comprovar a conformidade e melhorar a Readiness para a recuperação.

Recursos relacionados

Vídeo

Recuperação de ataques cibernéticos: Como alcançar a viabilidade mínima em minutos, não em dias

Quando ocorrem ataques cibernéticos, cada minuto custa US$ 14.000 e a Recovery total leva, em média, 24 dias. Mas e se você pudesse alcançar a viabilidade mínima em minutos, em vez de dias?
Assista ao vídeo sobreabout Recuperação de ataques cibernéticos: Como alcançar a viabilidade mínima em minutos, não em dias
Solução

Commvault AirGap

Proteção cibernética aprimorada com armazenamento cloud imutável e com air-gap.
Explore a solução sobreo Commvault AirGap

Pontos principais 

  • A adoção da IA está se acelerando, contribuindo para tornar os funcionários mais eficientes, produtivos e competitivos. 
  • As organizações precisam de governança e diretrizes para adotar a IA de forma responsável e em grande escala. 
  • Security and productivity don’t have to compete – they can reinforce one another.  
  • AI will become one of security’s most valuable tools for managing cyber risks.  
  • A adoção da IA funciona melhor quando inovação e segurança caminham juntas. 

One of the things I’ve enjoyed about the Pronto. Ou não.O que caracteriza esta série é que cada conversa se baseia na anterior. Começamos explorando as oportunidades e os riscos da IA autônoma. Em seguida, analisamos como as organizações podem construir confiança à medida que a IA se torna parte do dia a dia dos negócios. Este episódio aborda a próxima questão lógica: como, na prática, podemos usar a IA com segurança? 

Comedian Nathan Macintosh sits down with Rinki Sethi, CISO and CSO at Upwind Security, for a conversation about what responsible AI adoption actually looks like. They cover everything from AI governance and guardrails to user experience and the growing role AI will play in cybersecurity.  

Nathan continues to ask the questions many of us are wondering. Should we be worried? How much more productive do we need to be? And can AI actually make security better?  

Assista ao episódio completono Readiverse. 

What I appreciated most about this conversation is that Rinki is genuinely excited about new technology and protecting it. She didn’t frame AI as something organizations need to worry about. Instead, she focused on encouraging businesses to move forward with confidence by putting the right guardrails in place. Here are the ideas that stayed with me. 

O impulso à adoção da IA 

One thing that becomes clear from the conversation is that many organizations aren’t only encouraging their employees to adopt AI – they’re mandating it. These companies recognize that using AI helps people solve problems more efficiently, which is essential for staying competitive. 

“Every single company has a mandate … we’ve got to use AI everywhere in the company.”

– Rinki Sethi 

A questão já não é se a IA tem lugar no ambiente de trabalho, mas sim se os funcionários dispõem das diretrizes adequadas para utilizá-la de forma responsável. À medida que a adoção da IA se acelera, as organizações precisam de normas claras sobre quais ferramentas de IA os funcionários podem usar e como os dados da empresa são protegidos. 

Prévia: Governança da IA

Rinki explains that governance isn’t just about protecting against new risks. It’s about creating a framework that helps employees use AI responsibly while keeping pace with evolving regulations and industry standards. 

O benefício oculto da produtividade 

Here’s something I never thought about before. Rinki explains that AI isn’t simply helping people work faster. In many cases, it’s leaving room for the highest-performing employees to excel.  

She used software developers as an example. When AI-powered coding assistants became available, many assumed they’d only help less experienced developers. Instead, some of the best engineers began using them to move faster. They were able to solve more complex problems and spend more time on creative work rather than repetitive tasks. 

That kind of productivity is exactly why organizations are mandating AI. It doesn’t limit what people can do – it helps give them more space to focus on higher-value work. 

“You can be way more creative with how you’re doing things … cause you’re creating the space for that.”

– Rinki Sethi 

AI’s Role in Cybersecurity 

“How can AI be used to help with security and not be just looked at as a demon thing that’s here to take us out?”

– Nathan Macintosh 

When we talk about AI and security, the conversation is often focused on risk. But Rinki believes that AI will become one of cybersecurity’s greatest advantages. 

Security teams are already overwhelmed by the volume of alerts, logs, and data they need to investigate every day. Human analysts simply can’t keep up. Rather than replacing security professionals, AI assists them by filtering through massive amounts of data in seconds. This helps analysts identify false positives so they can focus on investigating real threats. 

My takeaway is that the future of cybersecurity isn’t about people versus AI – it’s about people working alongside AI to help make better decisions, respond faster, and scale their operations in ways that weren’t possible before. 

Ready for What’s Next? 

Cada episódio dePronto. Ou não. has reminded me that the biggest AI conversations are often about people – how we adapt, how we learn, and how we build the confidence to use new technology responsibly. The real opportunity for organizations isn’t just adopting AI. It’s creating an environment where employees can use AI to work smarter, become more creative, and deliver better outcomes for the business. 

Assista ao episódio completono Readiverse. 

Perguntas frequentes 

P: Por que as organizações estão adotando a IA tão rapidamente? 
R:Muitas organizações veem a IA como uma forma de ajudar a melhorar a produtividade, aumentar a eficiência e proporcionar aos funcionários mais tempo para se dedicarem a tarefas de maior valor agregado. 
P: O que é governança de IA? 
R:A governança da IA é o conjunto de políticas, processos e mecanismos de supervisão que ajuda as organizações a adotar a IA de forma responsável, ao mesmo tempo em que gerencia os riscos relacionados à segurança, à privacidade e à conformidade. 
P: Por que a experiência do usuário é importante para a segurança? 
R:Controles de segurança que criam atritos desnecessários muitas vezes levam as pessoas a buscar soluções alternativas. Projetar sistemas seguros que também sejam fáceis de usar ajuda a melhorar tanto a adesão quanto a proteção. 
P: A IA pode ajudar a melhorar a segurança cibernética? 
R:A IA pode ajudar as equipes de segurança a analisar grandes volumes de dados, o que contribui para reduzir os falsos positivos. Isso, por sua vez, ajuda as equipes a priorizar as ameaças e a responder de forma mais eficiente aos eventos de segurança. 
P: As pessoas deveriam ter medo da IA? 
R: Rinki’s perspective is that a healthy sense of skepticism is valuable, but fear shouldn’t prevent organizations from adopting technology responsibly. Education, governance, and strong security practices can help organizations use AI with confidence. 
Q: What’s the biggest takeaway from this episode? 
R: AI adoption isn’t about choosing between innovation and security. Organizations that combine strong governance with practical security measures will be better positioned to take advantage of AI’s benefits while managing its risks. 

Katherine Demacopoulos is Senior Director of Global Content Strategy and Programs at Commvault. 

More related posts


AI Data Resilience

Read more about AI Data Resilience

AI-Ready Data Protection

Read more about AI-Ready Data Protection

Como o Mythos e o GPT-5.5-Cyber podem transformar a segurança de dados na nuvem

Modelos especializados de IA para segurança cibernética poderiam acelerar a detecção de vulnerabilidades e os fluxos de trabalho de ataques em várias etapas. Além da prevenção, as equipes de segurança de dados na nuvem precisam de maior visibilidade, governança e Readiness para uma recuperação eficaz. 

Pontos principais

A IA cibernética de ponta reduz o tempo entre a detecção e a ação, mostrando por que as organizações precisam de uma segurança de dados em nuvem voltada para a resiliência, baseada em Recovery eficiente e ResOps. 

  • Claude Mythos e GPT-5.5-Cyber continuam sendo modelos de acesso restrito, mas oferecem uma visão de um futuro em que a IA poderá raciocinar em fluxos de trabalho cibernéticos complexos e acelerar tanto as operações de defesa quanto, potencialmente, as dos invasores.
  • À medida que o tempo entre a descoberta de uma vulnerabilidade e sua exploração diminui, as organizações precisam de maior visibilidade sobre as dependências na nuvem, os riscos relacionados à identidade e as rotas de ataque interconectadas antes que ocorram interrupções.
  • Recovery não se resume mais apenas à restauração de backups. As organizações precisam definir sua “empresa mínima viável”, validar pontos de recuperação confiáveis e restaurar sistemas críticos na sequência correta.
  • As operações de resiliência alinham as equipes de segurança, TI e negócios em torno de resultados mensuráveis de Recovery, ajudando as organizações a gerenciar dados, priorizar a Recovery e restabelecer operações confiáveis com maior segurança.

 Claude Mythos e o GPT-5.5-Cyber podem afetar a segurança dos dados na nuvem ao agilizar a identificação, o teste e a resposta aos riscos. Seu impacto ainda é incerto, mas eles apontam para a necessidade de maior visibilidade dos dados, governança de acesso e Recovery eficaz em todos os ambientes de nuvem. 

Claude Mythos e o GPT-5.5-Cyber estão oferecendo às equipes de segurança uma visão antecipada do que uma IA cibernética mais especializada poderia significar para a segurança dos dados na nuvem. 

Nenhum dos dois modelos está amplamente disponível, e seu impacto a longo prazo ainda é incerto. Mas a existência deles é importante porque os ambientes em nuvem já são difíceis de proteger. Dados confidenciais, sistemas de identidade, aplicativos SaaS, pipelines de desenvolvimento, cargas de trabalho de IA e infraestrutura de Recovery muitas vezes dependem uns dos outros de maneiras que são difíceis de perceber até que algo dê errado. 

The UK AI Security Institute’s Avaliação de abril de 2026 of Claude Mythos Preview found significant improvement on multi-step cyber-attack simulations, including the ability to execute multi-stage attacks on vulnerable networks when explicitly directed in a controlled environment.  

A mesma avaliação alertou que seus resultados diferem dos ambientes do mundo real e não comprovam se o Mythos seria capaz de atacar sistemas bem protegidos. Ainda assim, ela mostra por que as equipes de segurança de dados na nuvem devem ficar atentas a essa tendência. 

As cyber AI capabilities mature, the question is not only whether attacks get faster. It’s whether the window between discovering a weakness and exploiting it continues to shrink. When that clock compresses, cloud data security is no longer just about preventing compromise. Instead, the question shifts to whether organizations can understand risk quickly enough, govern access consistently, and recover trusted operations before disruption spreads. 

Por que o Mythos e o GPT-5.5-Cyber são importantes 

A importância do Mythos e do GPT-5.5-Cyber não reside no fato de que todas as organizações terão acesso a eles de repente. Com base nas informações públicas atuais, trata-se de modelos controlados e de acesso restrito. Para as equipes de segurança de dados em nuvem, sua importância está no que eles sugerem sobre a direção da IA cibernética: sistemas mais especializados, criados para dar suporte a fluxos de trabalho complexos de segurança. 

Essa distinção é importante. Um assistente de IA de uso geral pode ajudar a resumir alertas ou redigir um relatório de incidente. Um modelo especializado de IA cibernética é diferente. Ele pode ser projetado para analisar vulnerabilidades, infraestrutura, caminhos de ataque, controles defensivos e etapas de validação. Em ambientes autorizados, isso poderia ajudar as equipes de segurança a testar ambientes, priorizar exposições e fortalecer o planejamento de Recovery antes de um incidente. 

Para as equipes de segurança de dados na nuvem, o impacto prático tem menos a ver com os nomes dos modelos e mais com o fluxo de trabalho que eles representam. Os riscos na nuvem geralmente decorrem de conexões entre sistemas: uma carga de trabalho mal configurada, um conjunto de dados exposto, uma identidade com permissões excessivas, uma dependência de backup ou um caminho de recuperação não testado. A IA cibernética especializada poderia facilitar a avaliação mais rápida dessas relações, especialmente em ambientes de grande porte, onde a análise manual pode deixar passar de vista como um problema afeta outro. 

That shift mirrors a broader change happening across cybersecurity. The challenge is becoming less about identifying individual vulnerabilities and more about understanding how interconnected systems behave under pressure. AI may soon help defenders reason across identities, cloud workloads, backups, SaaS applications, AI pipelines, and business dependencies simultaneously — revealing not just isolated risks, but how those risks combine into operational failure. 

Isso também muda a forma como as organizações devem pensar sobreprontidão. Se a IA puder ajudar os defensores a lidar com tarefas cibernéticas complexas de maneira mais eficiente, técnicas semelhantes poderão, eventualmente, influenciar também os fluxos de trabalho dos invasores. A preocupação não é apenas que os ataques se tornem mais rápidos. É que a lacuna entre encontrar uma vulnerabilidade, testá-la e agir sobre ela possa diminuir. 

Cloud data security teams now have to plan for a harder question: what happens when the same types of AI-assisted workflows that help defenders validate risk also make weak points easier to find, test, and chain together? That’s where the cloud environment itself becomes the issue. 

A IA está elevando o nível de exigência em relação à segurança de dados na nuvem 

Most organizations don’t have one neat cloud environment. They have multiple clouds, SaaS platforms, data lakes, identity systems, development pipelines, backup repositories, and AI workloads that all depend on each other.  

That complexity already creates gaps: sensitive data can be overexposed, access permissions can drift, and recovery plans may not reflect how the business actually runs.  

Na prática, essas falhas raramente permanecem isoladas. Um bucket de armazenamento com dados confidenciais pode não parecer urgente por si só. Uma conta de serviço com permissões excessivas pode parecer um problema de configuração rotineiro. Uma dependência de Recovery não testada pode passar despercebida porque o sistema ainda está em funcionamento. Mas, quando esses problemas se interligam, podem criar um caminho que leva da exposição à interrupção. 

Attackers are well aware of these vulnerabilities. Mandiant’sRelatório M-Trends 2026observa que os operadores de ransomware estão cada vez mais visando a infraestrutura de backup, os serviços de identidade e os planos de gerenciamento de virtualização. O relatório também destaca como os invasores estão utilizando tokens OAuth de longa duração, cookies de sessão, chaves codificadas e tokens de acesso pessoal para se deslocarem entre ambientes. 

Agora, vamos incluir no cenário uma IA cibernética mais avançada: se os modelos puderem ajudaridentificar vulnerabilidades mais rapidamente, test exploitability more effectively, or connect weak signals across systems, defenders could benefit. However, attackers may eventually benefit, too—especially if similar capabilities become more accessible or are recreated elsewhere. 

22 seconds 
Median time between an initial access event and hand-off to a secondary threat group  

Source: Mandiant’s Relatório M-Trends 2026 

That’spor que essa conversa?can’t stop at “AI makes attacks faster.” Frontier IA cibernéticamuda o ritmo da segurança. À medida que o tempo entre a descoberta, a validação e a exploração se reduz, cada atraso na compreensão das dependências da nuvem ou na preparação da Recovery se torna mais oneroso. 

Como a IA cibernética de última geração poderia transformar a defesa na nuvem? 

While the full impact of Mythos and GPT-5.5-Cyber is still unknown, they point to three practical shifts cloud data security teams should be watching. Each one comes back to the same issue: cloud data security now depends on how quickly organizations can understand risk, act on it, and recover when something goes wrong. 

Os defensores cibernéticos precisam estar atentos a:

  • Velocidade:ferramentas assistidas por IA podem ajudar os defensores autorizados a revisar códigos, classificar vulnerabilidades, analisar malware, validar patches e testar controles mais rapidamente do que os fluxos de trabalho tradicionais permitem. 
  • Escala:o risco na nuvem raramente se concentra em um único local. Uma vulnerabilidade em um aplicativo, uma identidade com permissões excessivas, um bucket de armazenamento mal configurado e um caminho de Recovery não testado podem se transformar em uma cadeia de ataque. 
  • Pressão sobre a recuperação: If AI helps attackers move faster, organizations need to recover faster and cleaner. Backups alone aren’t enough if teams don’t know which data is clean, which identity systems can be trusted, or whether recovery will reintroduce compromised assets.

Para os defensores, a maior mudança talvez seja a forma como o trabalho é sequenciado. Hoje, muitas equipes passam do alerta para a investigação, da correção para o planejamento de Recovery em etapas separadas, muitas vezes envolvendo equipes diferentes. A IA cibernética poderia compactar esse fluxo de trabalho, ajudando as equipes a passar de um sinal para um conjunto de próximas ações recomendadas com mais rapidez. 

That doesn’t mean decisions should become automatic. It means teams may need clearer rules for when to trust a recommendation, when to escalate to a human reviewer, and when to move from investigation into recovery preparation. A model may help identify a possible attack path, but people still need to decide whether to close access, isolate a workload, preserve evidence, notify stakeholders, or prepare a clean recovery path. 

É aqui que o processo se torna tão importante quanto as ferramentas. A IA cibernética de última geração poderia ajudar os defensores a agir mais rapidamente, mas somente se as equipes tiverem etapas claras de validação e planos de Recovery em vigor. Sem essa estrutura, a velocidade pode gerar confusão. Com ela, os fluxos de trabalho assistidos por IA poderiam ajudar as equipes a agir mais cedo, mantendo o controle sobre como o risco é avaliado e como as decisões de Recovery são tomadas. 

Por que a Recovery limpa se torna mais importante à medida que os riscos se tornam mais dinâmicos 

When cloud risk moves faster, recovery planning has to become more precise. It’s not enough to know that backup copies exist. Teams need confidence that the data they restore is trustworthy, the recovery environment is isolated, and the systems coming back online won’t reintroduce the same threat that caused the disruption. 

Isso é importante porque os ambientes em nuvem sãoaltamente interconectados.Uma identidade comprometida, um conjunto de dados corrompido, uma máquina virtual afetada ou uma carga de trabalho mal configurada podem gerar incerteza em vários serviços. Durante um incidente, as equipes podem precisar determinar quais pontos de recuperação estão limpos, quais dependências devem ser restabelecidas primeiro e se os dados restaurados podem dar suporte às operações de negócios com segurança. 

Recovery also changes the way teams think about priority. The goal isn’t necessarily restoring everything immediately. It’s restoring enough of the business to operate safely. 

Many organizations know which applications they consider “critical,” but far fewer have defined their minimum viable company: the smallest combination of identities, cloud services, data, applications, and infrastructure required to keep the business functioning during disruption. Those dependencies often become visible only when recovery is tested under realistic conditions. 

Em um cenário de ameaças dominado pela IA, determinar a “empresa mínima viável” é crucial. A descoberta mais rápida de vulnerabilidades e o desenvolvimento mais eficiente de cadeias de ataque podem exercer mais pressão sobre as equipes de Recovery para que tomem decisões com alto grau de confiança em prazos apertados. 

What’s more, identity systems, cloud configurations, business communications, customer-facing applications, and the data they depend on may all need to come back in a deliberate sequence — not simply according to technical priority, but according to what the business needs first to operate. 

As organizações precisam de processos de recuperação que ajudem a validar dados limpos, preparar a recuperação em ambientes isolados, proteger dependências críticas de identidade e testar planos de recuperação antes que um incidente torne isso necessário. À medida que os recursos de IA cibernética amadurecem, as equipes de segurança de dados na nuvem devem tratar a recuperação limpa como parte da estratégia de segurança, e não como uma etapa posterior ao incidente. 

Construindo uma segurança de dados orientada para a resiliência 

A segurança de dados na nuvem tem se concentrado frequentemente na prevenção da exposição: identificar dados confidenciais, classificá-los, controlar o acesso e reduzir riscos. Esse trabalho continua sendo importante. Na verdade, ele se torna ainda mais relevante à medida que os sistemas de IA consomem dados corporativos por meio de solicitações, sistemas de recuperação, pipelines de treinamento, fluxos de trabalho analíticos e suporte automatizado à tomada de decisões. 

That’s because data may move into new contexts without moving into a new system of record. A sensitive dataset might support a retrieval workflow, shape a model response, or appear in a prompt log. That makes governance less about one location and more about how data is accessed, reused, and recovered across workflows. 

Mas a prevenção por si só não é suficiente para a próxima fase da segurança de dados na nuvem. Se a IA cibernética especializada pode ajudar as equipes de segurança a descobrir vulnerabilidades, testar caminhos de ataque e conectar sinais fracos mais rapidamente, então os programas de segurança de dados precisam levar em conta o que acontece depois que uma exposição é identificada ou explorada. Visibilidade e controles de acesso são apenas parte do quadro. As equipes também precisam de um caminho claro para uma recuperação confiável. 

Descobrir esse caminho requer mais do que melhores ferramentas de segurança. Requer um modelo operacional de Recovery que alinhe os líderes de segurança, TI e negócios em torno de prioridades compartilhadas de Recovery antes que um incidente ocorra. Cada vez mais, as organizações estão descrevendo essa disciplina como ResOps, ou operações de resiliência: uma abordagem estruturada para tornar a Recovery mensurável, repetível e vinculada aos resultados de negócios, em vez de apenas ao sucesso do backup. 

No ResOps, as organizações devem entender: 

  • Quais conjuntos de dados são mais críticos para as operações de negócios? 
  • Quais identidades, serviços em nuvem e fluxos de trabalho de IA dependem de conjuntos de dados críticos para os negócios? 
  • As políticas de governança e acesso estão alinhadas ao risco de negócios? 
  • Qual é o estado operacional mínimo viável que a organização deve restaurar primeiro? 
  • Essas decisões de Recovery podem ser validadas antes de um incidente, em vez de durante ele? 

That’s the shift Mythos and GPT-5.5-Cyber point toward. The future of cloud data security won’t be defined by prevention alone. As cyber AI compresses the time between discovery and action, organizations will need equal confidence in how they recover. That means understanding cloud dependencies before an incident, defining the minimum viable business they need to restore, and treating recovery as an operational discipline rather than a technical afterthought. 

Mythos and GPT-5.5-Cyber matter not because every organization will use these models tomorrow, but because they reveal where cybersecurity is heading. As AI accelerates both defense and attack, the organizations that perform best won’t simply be the ones with the strongest preventive controls. They’ll be the ones that can prove they know what to recover, in what order, and how to restore trusted operations before uncertainty becomes business disruption. 

Perguntas frequentes

Quando esses modelos especializados serão disponibilizados ao público?

Não há um cronograma confirmado para o acesso público em larga escala. As informações atuais indicam que o Claude Mythos está sendo restrito a organizações selecionadas por meio de programas controlados, enquanto a OpenAI descreve o GPT-5.5-Cyber como disponível apenas para profissionais de segurança cibernética credenciados por meio de sua estrutura “Trusted Access for Cyber”.

É provável que os ataques de IA aumentem?

Não necessariamente. Mas eles mostram que a IA avançada pode dar suporte a fluxos de trabalho cibernéticos mais complexos, o que significa que as organizações devem se preparar para ciclos mais rápidos de detecção, teste e exploração.

Quais riscos as equipes devem priorizar em primeiro lugar?

Comece obtendo visibilidade sobre dados confidenciais, caminhos de acesso, configurações incorretas na nuvem, dependências de identidade e Readiness para Recovery. Os recursos de segurança de dados e IA da Commvault podem ajudar as equipes a classificar dados, gerenciar o acesso e identificar riscos em ambientes de nuvem. 

Por que a Recovery é importante para a segurança dos dados na nuvem?

Porque a prevenção pode falhar. Os recursos de resiliência cibernética da Commvault podem ajudar as organizações a identificar pontos de Recovery não comprometidos, validar a Recovery em ambientes isolados e restaurar dados e serviços críticos sem reintroduzir ativos comprometidos. 

A Commvault oferece detecção de ameaças com suporte de IA?

Sim. A Commvault pode utilizar recursos baseados em IA para ajudar a identificar ameaças, detectar atividades anômalas, priorizar riscos e acelerar a resposta a incidentes. Em combinação com fluxos de trabalho de resiliência cibernética e Recovery, podemos ajudar as equipes a aprimorar seus fluxos de trabalho de resposta e recuperar dados críticos com maior confiança.


At Commvault, we talk a lot about cyber resilience, the ability to recover from whatever challenges come your way. But for one engineer at Australian technology services provider Perfekt, it is his personal resilience that helps him succeed.

Viktor Trokhin left Ukraine when the war began, traveling through five countries before eventually reuniting with his family in Australia. He brought more than six years of ICT experience, deep technical expertise, and a determination to continue his career in tech.

Like many skilled professionals starting over in a new country, Viktor wasn’t just adapting to a new workplace. He was building expertise in new technologies, communicating in a second language, and finding his place in a different professional environment.

Marcus Rolim, Managed Services General Manager at Perfekt and Viktor’s manager, saw his potential immediately.

“Our engineering development program is built around people,” Marcus says. “We invest heavily in mentoring and creating opportunities for engineers from different backgrounds.”

Over the years, Perfekt has welcomed engineers from around 10 different countries. Rather than following a standard training path, the company focuses on each person’s strengths, providing mentoring, practical experience, and support where it’s needed most.

For Viktor, that meant building on his existing expertise while gaining experience with Commvault Cloud and cyber resilience.

As he worked with customers, Arlie – the AI assistant in Commvault Cloud – became a natural part of his daily workflow. Whether he was exploring product capabilities, troubleshooting an issue, or looking for guidance, Arlie helped him quickly find trusted information without interrupting his work.

Then came an unexpected benefit.

Because Arlie supports multiple languages, Viktor could work through complex concepts in his native language before switching to English when speaking with customers or colleagues. While this wasn’t the use case Perfekt originally envisioned, it quickly became a valuable learning advantage.

“When an engineer can explore a complex question in their own language, understand the reasoning behind the answer, and then communicate it clearly in English, it changes the learning experience,” Marcus says. “It allows their technical ability to come through without language becoming a barrier.”

Today, Viktor is an Infrastructure & Data Protection Engineer at Perfekt, supporting customers while continuing to deepen his expertise in cyber resilience.

When Viktor left Ukraine, he carried with him years of experience, deep technical expertise, and an unwavering determination to continue the career he had worked so hard to build. Today, he helps organizations strengthen their cyber resilience, drawing on the same resilience that helped him rebuild his own life.

Maybe that’s why this story resonates. Viktor’s resilience shaped his own future. Today, it helps him make a difference for others.

That’s what putting people first looks like: organizations like Perfekt investing in people, and technology like Commvault Cloud helping them thrive.

Chris DiRadoé diretor de Experiência do Produto na Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Como os líderes de segurança podem proteger seus dados mais confidenciais?

A segurança de dados e IA permite que as organizações identifiquem, classifiquem e controlem o acesso a dados confidenciais entre usuários, sistemas e soluções de IA.

Pontos principais

Os dados são a força vital das empresas modernas, ajudando a orientar decisões-ctêm e impulsionar iniciativas de IA. Dado o seu valor, conhecer e proteger seus dados é essencial.

  • 90% das organizações têmdados confidenciais na nuvem expostos, que podem ser identificados pela IA. Isso torna a visibilidade dos ativos de dados o primeiro e mais crítico passo para reduzir os riscos corporativos. 
  • 40% dos arquivos enviadosou compartilhados com ferramentas de IA generativa contêm Informações de Identificação Pessoal (PII) ou dados da Indústria de Cartões de Pagamento (PCI). Esse uso indevido de dados confidenciais representa um risco significativo para as organizações no que diz respeito à privacidade e a violações regulatórias. A descoberta e a classificação de dados constituem a base de uma segurança eficaz, ajudando as organizações a identificar dados confidenciais em ambientes estruturados, semiestruturados e não estruturados. 
  • A proteção da IA requer o controle tanto dos dados de treinamento quanto das interações em tempo de execução. As organizações precisam verificar se os dados confidenciais não estão expostos por meio de entradas, saídas ou do comportamento do modelo.
  • Overpermissive access is one of the most persistent data risks for modern businesses. With users, applications, and service accounts often retaining unnecessary access to sensitive data, the “attack surface” is expanded.
  • Recursos relacionados
  • Segurança

Sensitive data now moves across clouds, applications, and AI workflows without clear visibility — creating exposure risks that traditional security controls cannot address alone. Commvault Data and AI Security helps organizations discover and classify sensitive data, govern access for both human and machine identities, and maintain compliance with GDPR, HIPAA, and PCI DSS across the full data lifecycle.


Por que a exposição de dados confidenciais é a maior falha de segurança?

Os dados são o combustível inestimável que impulsiona as empresas modernas. Por isso, as organizações passaram a priorizar investimentos significativos em ferramentas sofisticadas de segurança.

However, according to Varonis’ Relatório sobre o Estado da Segurança de Dados de 2025, 90% das organizações ainda têm dados confidenciais expostos na nuvem. Da mesma forma, 88% das organizações possuem usuários fantasmas inativos, mas ainda habilitados.

Masthat’snem todos.According to IBM’s Relatório sobre o Custo de uma Violação de Dados 2025, 53% das organizações vítimas de violação relataram que os dados dos clientes foram comprometidosPII. EssesAs estatísticas apresentam um quadro claro: embora os dados sejam fundamentais para as empresas, a visibilidade e a segurança geral continuam sendo questões críticas. 

Os dados não estão mais restritos a bancos de dados estruturados. Eles estão espalhados por arquivos, e-mails, plataformas em nuvem, aplicativos SaaS e terminais. Grande parte deles é não estruturada, duplicada ou não gerenciada, o que dificulta seu rastreamento e proteção.

A IA está agravando esse problema. Sobre40% dos arquivos enviados para ferramentas de IA generativa contêm informações confidenciais, muitas vezes sem governança nem supervisão. À medida que a adoção da IA cresce, também aumenta o número de sistemas e identidades que interagem com os dados.

Sem visibilidade sobre quais dados existem e onde estão armazenados, as organizações não conseguem protegê-los de forma eficaz. Essa falta de visibilidade é a raiz do problema atual de segurança de dados.


Quais são os pilares da segurança de dados e IA?

Para enfrentar o desafio da exposição de dados,as organizações precisam de uma abordagem estruturada que traga consistência e controle à forma como os dados são gerenciados. A segurança de dados e IA baseia-se em três pilares fundamentais:Descoberta de dados,Classificação de dados,and Data & AI Access Governance.

Cada pilar aborda uma lacuna importante:

  • Discovery provides visibility into where data resides across environments. This includes structured systems such as databases,as well as semi-structured and unstructured sources that are often overlooked.
  • Classification adds context by identifying the type and sensitivity of data. It enables organizations to distinguish between operational data,sensitive personal information,financial records,intellectual property,and other high-risk categories.
  • Access governance enables organizations to verify that data is used appropriately. It defines who or what can access data,under what conditions,and with what level of control.

These three pillars do not exist independently. They create a connected system that fully covers data and AI security. Discovery identifies the complete data landscape,classification defines the appropriate sensitivity,and access governance enforces control based on that context.

This model even extends beyond human users to include machine identities such as AI models. In modern environments,these non-human identities often represent a significant portion of data access activity. Bringing these pillars together can help organizations move from fragmented security controls to a unified,policy-driven approach.


Como as organizações podem identificar e classificar dados confidenciais?

A identificação e a classificação são fundamentais para um modelo de segurança de dados bem-sucedido. No entanto, muitas vezes são as etapas mais difíceis de implementar de forma eficaz.

Isso ocorre porque os ambientes de dados modernos são altamente fragmentados. As informações confidenciais estão espalhadas por várias plataformas em nuvem, sistemas locais, aplicativos SaaS e terminais. Uma parte significativa desses dados é não estruturada, o que dificulta sua identificação e categorização.

Alguns dos desafios mais notáveis incluem:

  • Dados ocultos que existem sem conhecimento, aprovação ou supervisão de segurança.
  • Formatos inconsistentes entre dados estruturados e não estruturados.
  • Rápido crescimento dos dados devido à adoção de IA, que supera os esforços de classificação manual.

Para lidar com isso, as organizações precisam de recursos de descoberta escaláveis e estruturas de classificação. A classificação adequada pode atribuir significado às vastas quantidades de dados existentes. Isso normalmente inclui categorias como PII, informações de saúde protegidas (PHI), PCI, propriedade intelectual, além de chaves e segredos.

O valor da classificação decorre de como ela é utilizada. Uma vez que os dados são classificados, as organizações podem aplicar efetivamente políticas de retenção e exclusão, restringir ou monitorar o acesso e habilitar o mascaramento ou a supressão de campos confidenciais.

Em grande escala, uma abordagem madura de descoberta e classificação não apenas garante a cobertura, mas também ajuda a produzir resultados significativos. Isso pode incluir menor exposição, melhor aplicação de políticas e redução mensurável de riscos.


Quais são os principais riscos de um acesso excessivamente permissivo?

De acordo com uma pesquisa daReliaQuest, 99% das identidades na nuvem possuem privilégios excessivos. Da mesma forma, umestudo de 2025 do Ponemon Institutedestaca que 61% das empresas americanas sofreram violações de dados causadas por funcionários nos últimos dois anos, com o custo médio desses incidentes chegando a impressionantes US$ 2,7 milhões.

Isso comprova que, mesmo quando as organizações compreendem seus dados, o acesso continua sendo um dos pontos mais vulneráveis em termos de segurança.

O acesso excessivamente permissivo ocorre quando usuários, aplicativos ou contas de serviço têm mais acesso aos dados do que o necessário. Esse problema é generalizado porque os controles de acesso costumam ser concedidos de forma ampla por conveniência e raramente são revisados.

O impacto é significativo. O acesso excessivo aumenta a probabilidade de exposição acidental, risco interno e exploração durante uma violação.

Para resolver isso, as organizações devem, em primeiro lugar, inspecionar cuidadosamente os padrões de acesso. Isso inclui descobrir quem está acessando dados confidenciais, quais sistemas ou identidades estão envolvidos e se esse acesso está alinhado às necessidades do negócio.

Deve-se dar atenção especial às contas privilegiadas e às identidades de serviço. Elas geralmente possuem permissões abrangentes e podem acessar grandes volumes de dados confidenciais em diversos sistemas.

Nesse contexto, uma governança de acesso eficaz é fundamental. Isso requer:

  • Alinhar as políticas de acesso com a classificação de dados.
  • Monitorar continuamente os padrões de uso.
  • Identificar e corrigir desvios de acesso ao longo do tempo.

Ao reduzir o acesso desnecessário, as organizações ajudam a limitar sua superfície de ataque e a melhorar a proteção geral dos dados.


Como as organizações devem gerenciar os dados utilizados pelos sistemas de IA?

A adoção da IA está se disseminando rapidamente por todas as facetas dos negócios modernos. Isso introduz um novo nível de complexidade na forma como os dados são acessados, processados e expostos.

Os conjuntos de dados de treinamento geralmente incluem grandes volumes de dados provenientes de toda a organização. Sem classificação e governança adequadas, esses conjuntos de dados podem conter informações confidenciais ou sujeitas a regulamentação.

Isso gera riscos em várias etapas:

  • Durante a preparação e o treinamento dos dados.
  • Quando os modelos interagem com dados em tempo real.
  • Por meio de resultados que podem expor involuntariamente informações confidenciais.

Portanto, a classificação deve preceder o treinamento do modelo. Isso significa validar e classificar todos os dados utilizados nos conjuntos de dados e remover informações confidenciais quando necessário.

Da mesma forma, após a implantação de ferramentas de IA, as equipes de dados devem avaliar continuamente como os modelos utilizam e expõem os dados. Elas também devem aplicar mecanismos de controle adequados, como mascaramento ou supressão, quando necessário.

Os sistemas de IA não devem ser tratados separadamente da segurança de dados. Eles são uma extensão da forma como os dados são utilizados e devem ser governados de acordo com isso. Ao integrar esses recursos de segurança de dados e de IA ao ciclo de vida mais amplo do desenvolvimento de IA, as organizações podem ajudar a reduzir riscos sem deixar de possibilitar a inovação.


Como a classificação de dados contribui para a conformidade regulatória?

A conformidade regulatória depende da capacidade de identificar e controlar dados confidenciais. Estruturas como o GDPR, a HIPAA e o PCI DSS definem requisitos específicos sobre como os dados devem ser tratados. No entanto, esses requisitos não podem ser cumpridos sem que se saiba, primeiro, onde os dados regulamentados estão localizados.

É por isso que os programas de conformidade fracassam sem uma base de dados adequada.

Nesses casos, a classificação de dados atua como a espinha dorsal da conformidade, mapeando os dados para categorias regulatórias. Ela permite que as organizações apliquem controles direcionados com base na sensibilidade dos dados e imponham políticas críticas para o ciclo de vida dos dados.

Isso abre uma infinidade de recursos essenciais:

  • Aplicação de políticas de retenção e exclusão
  • Restrição do acesso a dados regulamentados
  • Implementação de controles cruciais de privacidade

Isso também simplifica os processos de auditoria. As organizações podem demonstrar onde os dados confidenciais estão armazenados, como são protegidos e quem tem acesso a eles. A governança de acesso fortalece ainda mais a conformidade, garantindo que apenas identidades autorizadas possam interagir com dados regulamentados.

Juntas, a classificação de dados e os controles de acesso redefinem a conformidade para a era moderna, impulsionada pela IA.


Conclusão: O que é necessário hoje para uma segurança eficaz de dados e IA?

A segurança moderna de dados e IA não é mais definida por defesas de perímetro ou controles isolados. Ela exige uma abordagem contínua e unificada que conecte visibilidade, classificação e governança de acesso ao longo de todo o ciclo de vida dos dados.

Para colocar essa abordagem em prática, as organizações devem, primeiro, compreender seus dados, identificando exatamente onde todos eles estão armazenados. Em seguida, devem controlar como o acesso a eles é feito. Por fim, as organizações devem garantir que os sistemas de IA os utilizem de forma responsável. Esses recursos devem atuar em conjunto, e não de forma independente, para ajudar a reduzir a exposição e manter a confiança.

À medida que os volumes de dados crescem e a adoção da IA se acelera, o desafio não será apenas proteger os dados, mas demonstrar onde os dados confidenciais estão, quem pode acessá-los e como eles são protegidos em todos os sistemas. Aquelas que adotarem uma abordagem estruturada e orientada por políticas estarão mais bem posicionadas para ajudar a reduzir riscos, atender às expectativas regulatórias e possibilitar a inovação com confiança.

Perguntas frequentes

O que é segurança de dados e IA?

A segurança de dados e IA consiste na prática de identificar, classificar e gerenciar o acesso a dados confidenciais em todos os sistemas, usuários e modelos de IA. A solução Commvault Data and AI Security oferece esses recursos em ambientes híbridos — permitindo que as organizações garantam que os dados permaneçam visíveis, controlados e protegidos ao longo de todo o seu ciclo de vida, incluindo a forma como são utilizados no treinamento e nos resultados da IA.

Por que a exposição de dados confidenciais é um grande risco?

A exposição de dados confidenciais representa um grande risco, pois muitas vezes as organizações não têm visibilidade sobre onde os dados estão armazenados e quem tem acesso a eles, o que aumenta a probabilidade de violações, uso indevido e infrações regulatórias. A Commvault ajuda a mitigar esse risco por meio de uma abordagem unificada que combina descoberta de dados, classificação e governança de acesso em ambientes híbridos.

Quais são os principais pilares da segurança de dados?

Os três pilares fundamentais da segurança de dados são a descoberta, a classificação e a governança de acesso. A Commvault oferece cada um deles — a Descoberta de Dados identifica onde os dados confidenciais estão localizados em todos os ambientes, a Classificação de Dados define sua confidencialidade e tipo, e a Governança de Acesso a Dados e IA aplica o controle de acesso alinhado às políticas comerciais e regulatórias.

Por que o acesso excessivamente permissivo é perigoso?

O acesso excessivamente permissivo permite que usuários, aplicativos e contas de serviço acessem mais dados do que o necessário — aumentando o risco de exposição acidental, ameaças internas e exploração. A Governança de Acesso a Dados e IA da Commvault resolve essa questão por meio do monitoramento contínuo dos padrões de acesso, do alinhamento das permissões com a classificação de dados e da identificação e correção de desvios de acesso em ambientes híbridos.

Como as organizações devem ajudar a proteger os dados utilizados pela IA?

As organizações podem proteger os dados de IA classificando os conjuntos de dados antes do treinamento e monitorando continuamente como os modelos acessam e expõem os dados. O Commvault Data and AI Security oferece suporte a isso por meio de controles de descoberta, classificação e governança, incluindo mascaramento, supressão e restrições de acesso — ajudando a garantir que dados confidenciais não sejam expostos durante o treinamento de IA, pelo comportamento dos modelos ou pelos resultados gerados.

Como a classificação de dados ajuda a garantir a conformidade?

A classificação de dados contribui para a conformidade ao identificar dados regulamentados, como Informações de Identificação Pessoal (PII), e ao associá-los aos controles adequados. A Classificação de Dados da Commvault ajuda as organizações a aplicar políticas de retenção e exclusão alinhadas com o GDPR, a HIPAA e o PCI DSS — além de fornecer as evidências prontas para auditoria necessárias para demonstrar como os dados confidenciais são identificados, protegidos e gerenciados.

Explore recursos relacionados

Explorar

What are the Key Risks of Data & AI Security?

Explore how AI introduces new data vulnerabilities – from model training to exposure to runtime risks – and the layered practices organizations use to govern workloads responsibly.
Leia o artigoabout What are the Key Risks of Data & AI Security?
Livro branco

Análise dos riscos de segurança da IA

Um relatório de Readiness para seu CISO e CIO, para que possam verificar o que mudou com o MCP 2.0 e o que fazer para que sua organização esteja preparada.
Leia o white paper sobreabout Análise dos riscos de segurança da IA


Pontos principais

  • Replace subjective claims about “ease of use” with a measurable data protection gearing ratio: protected capacity divided by the number of full-time administrators.
  • A medição da capacidade protegida por ETI oferece uma visão mais significativa da eficiência operacional do que métricas tradicionais, como o número de tarefas de backup por administrador.
  • O índice de proteção de dados deve ser usado como referência antes da migração de uma plataforma e medido novamente após a migração para validar as melhorias operacionais.
  • Fatores como ambientes multicloud, requisitos de Recovery cibernética e obrigações de conformidade podem influenciar o índice, portanto, ele deve ser avaliado dentro do contexto de cada ambiente.
  • As organizações devem solicitar que os fornecedores se comprometam com resultados operacionais mensuráveis, em vez de confiar em alegações qualitativas sobre simplicidade.

Every vendor evaluation I have sat in eventually reaches the same dead end. One side says the platform is simple to run. The other side says their platform is simpler.

Nobody can prove either claim, so the conversation drifts to the demo, the reference call, the gut feeling in the room. That is not how you should be making a decision that determines how your team will spend the next five years.

I have run production data protection environments. I have watched teams get buried under fragmented tooling that promised automation and delivered tickets instead.

“Reduced complexity” is not a feeling you should have to take on faith. It is something you should be able to calculate.

A métrica que faltava ao setor

We have started using a simple ratio internally and with customers: total protected capacity divided by the number of full-time staff required to run it. We call it the data protection gearing ratio.

Protected Capacity (PB) / FTEs = Data Protection Gearing Ratio

That’s it. No survey questions about satisfaction. No adjectives. A number, calculated from data you already have.

Here is why it matters more than the metrics it replaces. Calculating the number of backup jobs per person made sense a decade ago, when a job represented a discrete unit of manual effort. It does not reflect how modern platforms operate today, where automation absorbs the routine work and a single administrator can be accountable for petabytes, not job counts.

Measuring jobs per person in an automated environment tells you nothing about whether the automation is actually working.

Como isso funciona na prática

One clarification before the number, because it trips people up. Protected capacity means the full, uncompressed, undeduplicated size of the applications being protected, not the physical disk behind them.

That distinction matters because it is the whole point. Commvault’s own production environment protects 42,39 PB of application data on 9,26 PB of physical disk, an 81,91% space savings from deduplication and compression.

The ratio is not just a measure of how many petabytes a person can watch over. It is a measure of how much architecture is doing the work before headcount ever enters the picture.

With that in mind: Commvault runs its own production backup environment on 42,39 PB of protected capacity with two FTEs. That is a gearing ratio of 21.20 PB per FTE. Industry benchmarks for modern platforms typically land between 5 and 25 PB per FTE, depending on environment complexity, so that number sits at the high end of what is achievable today.

Métrico  Valor  Definição 
Capacidade Protegida (Front-End)  42,39 PB  Full, uncompressed, undeduplicated application size protected in our environment 
Capacidade total do disco  9,26 PB  Armazenamento físico de destino 
Espaço total utilizado  7,89 PB  Current utilization 
Total de dados gravados  7,67 PB  Dados lógicos gravados no disco 
Economia de espaço  81,91%  Eficiência de desduplicação e compactação 
FTEs de proteção de dados  2  Number of full-time admins managing Commvault’s own production backup estate 

Data Protection Gearing Ratio = 42,39 PB / 2 FTEs = 21.20 PB per FTE

I want to be direct about what this number does not do. It does not account for a multi-cloud footprint, cyber recovery requirements, or a compliance-heavy application mix, all of which will pull the ratio down for reasons that have nothing to do with how good the platform is.

A ratio in isolation is not a verdict. A ratio measured before and after a migration is.

That is the actual use case. Baseline your current environment on your current tools. Set a target ratio based on your growth projections and your team’s capacity. Then hold your vendor to it after the implementation is done, not just during the sales cycle.

A implicação no nível da diretoria

Se você é quem aprova a migração para uma nova plataforma, não estão apenas pedindo que confie que a nova plataforma seja mais fácil de operar. Estão pedindo que você invista em um resultado operacional específico. Uma meta de índice de proteção de dados oferece uma maneira de incluir esse resultado no caso de negócios e verificá-lo 12 meses depois.

Essa é a mesma disciplina que aplicamos ao tempo médio de recuperação limpa (MTCR). A capacidade de recuperação não é algo que se alega, é algo que se mede e se remedeia até que o número revele a verdade. A eficiência operacional merece o mesmo padrão.

O Desafio

Ask your current vendor for the gearing ratio of your own environment today. If they cannot produce it, that tells you something about how well they understand what “simple to manage” means for your team.

And if you are evaluating a new platform, do not accept “easier to use” as an answer. Ask what ratio they will commit to, and ask again after year one.

Perguntas frequentes

Q: What is the data protection gearing ratio?

A: The data protection gearing ratio measures the amount of protected data capacity managed by each full-time administrator. It provides an objective way to evaluate operational efficiency rather than relying on subjective impressions of platform usability.

Q: Why is this metric more useful than backup jobs per administrator?

A: Modern data protection platforms automate much of the routine work that previously required manual effort. As a result, counting backup jobs no longer reflects the true workload or efficiency of an operations team.

Q: What does “protected capacity” mean in this calculation?

A: Protected capacity refers to the full, uncompressed, and undeduplicated size of the application data being protected. This measurement reflects the actual workload managed by the platform rather than the physical storage consumed after optimization.

Q: Does a higher gearing ratio always indicate a better platform?

A: Not necessarily. Environmental complexity, including multi-cloud deployments, cyber resilience requirements, and regulatory obligations, can reduce the ratio even when the platform performs well. The metric is most valuable when comparing the same environment before and after a migration.

Q: How should organizations use the data protection gearing ratio during vendor evaluations?

A: Organizations should establish a baseline using their current environment, define a target ratio aligned with future growth, and ask vendors to commit to achieving measurable improvements after implementation. This approach shifts the conversation from marketing claims to verifiable business outcomes.

Q: What is the broader business value of this metric?

A: The data protection gearing ratio enables executives to quantify expected operational efficiency gains and include them in the business case for a platform investment. It also provides a benchmark that can be reviewed after deployment to confirm the promised results were achieved.

Rajiv Kottomtharayilé diretor de produtos da Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Noprimeiro episódio da nossa série STRIVE sobre soberania digital, Commvault’s Alex Zinin and Osmium Data Group’s Max Mortillaro challenged one of the biggest misconceptions in the industry: Digital sovereignty isn’t a feature you buy – it’s a business problem you have to understand before you can solve.

This conversation picks up where that one left off. This time, I sat down with Thomas Maurer, EMEA Global Black Belt for Sovereign Cloud at Microsoft, to explore what happens after an organization decides sovereignty matters. How do executive teams move from broad concerns about regulation, jurisdiction, or geopolitical uncertainty into practical architectural decisions?

The answer, it turns out, is rarely as straightforward as choosing a cloud provider or selecting the right deployment model. It’s about asking better questions before making technical decisions.

Watch the episódio completo.

Pontos principais

  • Every organization defines digital sovereignty differently – and that’s exactly where the conversation should begin.
  • Sovereignty isn’t solved by technology alone. Legal, operational, architectural, and business considerations all shape the outcome.
  • Cloud and on-premises aren’t competing strategies. For many organizations, the future is a carefully designed combination of both.
  • Risk management – not fear – should drive sovereignty decisions.
  • Uma boa arquitetura começa com a compreensão dos requisitos de negócios, e não com a escolha da infraestrutura.

A soberania tem significados diferentes para diferentes organizações

One of the first observations Thomas made was also one of the most important.

There is no universal definition for digital sovereignty. For one organization, it may simply mean meeting regulatory requirements or keeping data within a specific geography. For another, it may involve operational independence, business continuity, or preparing for geopolitical disruption. That difference matters because it changes the conversation entirely.

Too often, organizations assume there’s a standard sovereignty blueprint waiting to be implemented. In reality, the first challenge isn’t selecting technology – it’s understanding what problem the organization is actually trying to solve.

Only then does architecture begin to make sense.

A tecnologia deve seguir a estratégia

One theme that kept surfacing throughout our discussion was the temptation to jump straight into technical design.

It’s understandable. Architects naturally think about infrastructure, workloads, connectivity, and deployment models. But Thomas emphasized that the most successful projects begin somewhere else.

They begin by listening.

What concerns are driving the initiative? Is the objective regulatory compliance? Business continuity? Data residency? Operational control? Protection against geopolitical disruption?

Different answers lead to different architectures.

That may sound obvious, but it’s surprising how often organizations begin evaluating solutions before they’ve aligned on the business outcome they’re trying to achieve.

Antevisão: Comece pelo risco, não pelas suposições

One of the most practical moments in our conversation comes when Thomas and I discuss why sovereignty initiatives should begin with a risk assessment – not an architectural diagram.

Every organization has a different risk appetite. A Formula 1 team, a government agency, and a global manufacturer won’t make the same decisions, nor should they. The key is understanding which risks matter most to your business, what trade-offs you’re willing to make, and then designing an architecture that supports those decisions.

As Thomas points out, there is no perfect solution – only informed trade-offs. The earlier organizations adopt that mindset, the stronger their sovereignty strategy will be.

‘Cloud or On-Premises?’ Is the Wrong Question to Ask

One of the more interesting parts of the conversation challenged another common assumption – that organizations must choose between public cloud and private infrastructure.

Thomas described a very different reality.

Many organizations aren’t replacing one with the other. They’re designing environments where workloads can move between them based on business need, regulatory requirements, or resilience considerations.

That flexibility changes how we should think about architecture. Instead of asking whether cloud or on-premises is better, the more useful question becomes:

“Where does this workload belong today – and could that answer change tomorrow?”

When sovereignty becomes part of the design process, workload mobility becomes just as important as workload placement.

A arquitetura é apenas uma parte da equação

Another takeaway I appreciate is Thomas’s reminder that architecture alone doesn’t solve sovereignty.

  • Os contratos são importantes.
  • Os marcos legais são importantes.
  • Os processos operacionais são importantes.
  • As pessoas responsáveis pela gestão do meio ambiente são importantes.

None of those disciplines can operate in isolation. Sovereignty requires legal, security, compliance, and infrastructure teams to work together from the beginning – not hand projects off to one another after decisions have already been made.

That’s a familiar pattern for anyone working in cyber resilience. The strongest outcomes rarely come from individual teams. They come from coordinated ones.

O risco deve orientar todas as decisões

Toward the end of our discussion, the conversation naturally shifted toward risk. For me, this is where sovereignty starts to feel much more familiar. Every resilience project begins by asking what the organization is trying to protect, what threats matter most, and how much risk it’s willing to accept.

Digital sovereignty is no different.

Rather than searching for a perfect solution, organizations need to identify the specific sovereignty scenarios they’re concerned about and then determine which architectural, operational, or contractual controls best address those risks.

That shift – from feature comparison to risk management – is what ultimately leads to better decisions.

Por que essa conversa é importante

Digital sovereignty continues to evolve rapidly. New regulations will emerge. Technology will change. Geopolitical realities will continue to shift.

That means sovereignty isn’t something organizations solve once. It’s something they regularly evaluate as business priorities and external risks evolve.

The organizations that succeed won’t necessarily have the most restrictive architectures. They’ll have the clearest understanding of their business objectives, the discipline to assess risk thoughtfully, and the flexibility to adapt as those risks change.

Ultimately, digital sovereignty isn’t something organizations can buy off a shelf. It’s an exercise in understanding risk, managing dependencies, and making informed trade-offs long before those decisions are tested.

Assista ao episódio completo

Neste episódio do STRIVE, Thomas e eu discutimos:

  • Por que a soberania tem significados diferentes para diferentes organizações.
  • Como os executivos devem abordar a estratégia de soberania.
  • Public cloud versus private cloud – and why it’s often not an either/or decision.
  • Por que a gestão de riscos deve orientar as escolhas arquitetônicas.
  • O papel da resiliência no planejamento da soberania moderna.

Assista agora

Perguntas frequentes

Q: Does digital sovereignty mean keeping everything on-premises?

A: No. Many organizations adopt hybrid approaches that balance cloud capabilities with specific sovereignty requirements.

Q: Where should sovereignty projects begin?

A: Start by defining the business problem and understanding the risks you’re trying to mitigate before evaluating technology.

Q: Is sovereignty purely a technical issue?

A: No. It requires collaboration between legal, compliance, security, operations, and architecture teams.

Q: How does sovereignty relate to resilience?

A: Both disciplines focus on maintaining operational continuity by reducing exposure to risks that could disrupt the business.

Q: What’s one big mistake organizations make in regard to digital sovereignty?

A: Jumping into architectural decisions before agreeing on what sovereignty means for their organization.

Q: What should executives ask first in terms of planning for digital sovereignty?

A: “What problem are we trying to solve?” Everything else follows from that answer.

Darren Thomsoné vice-presidente e diretor de tecnologia da Commvault para a região da EMEA.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Pontos principais

  • Terraform manages desired state – it provisions and configures infrastructure from code.
  • Cloud Rewind captures actual deployed state – it helps restore environments to a known-good point in time.
  • Os arquivos de estado do Terraform e o histórico do Git não são ferramentas de recuperação; eles não registram o que estava realmente em execução.
  • Cloud Rewind ajuda a recuperar a infraestrutura, independentemente de as alterações terem sido feitas por meio de IaC, do console ou de intervenção manual.
  • Juntos, o Terraform e o Cloud Rewind ajudam a proporcionar às equipes uma estratégia completa de operações de cloud : crie rapidamente, recupere-se ainda mais rápido.

If your team runs Terraform, you already know how powerful IaC can be. You define what you want, apply it, and your cloud environment materializes. Change management becomes repeatable. Provisioning becomes predictable.

But there is a gap between provisioning infrastructure and recovering it – and it matters most when something goes wrong at 2 a.m.

Terraform and Cloud Rewind address different parts of the cloud lifecycle. Understanding the difference helps you avoid a dangerous assumption: that your IaC tooling doubles as a recovery plan.

Como o Terraform e o Cloud Rewind diferem

Terraform is a provisioning tool. It defines and manages desired state. When you revert a Terraform change, you are re-applying a previous desired configuration – not restoring the actual deployed environment that was running before the incident.

That distinction matters. Terraform state is not a historical recovery snapshot.

Cloud Rewind captures actual cloud configuration state and stores point-in-time snapshots. When something breaks, you do not rebuild from code and hope the environment comes back intact. You restore a known-good environment – the one that was actually running – regardless of how the change that caused the problem was introduced.

Terraform Design  Cloud Rewind Design 
Gerenciamento do estado desejado  Recuperação do estado real 
Provisionamento de infraestrutura  Recovery da infraestrutura 
Aplica as alterações  Reverte alterações 
Fonte de verdade = código  Fonte de verdade = ambiente implantado 
Visão prospectiva  Retrospectivo 
Compilar e atualizar  Recuperação e reconstrução 
Ajuda a recuperar a configuração desejada  Ajuda a restaurar o estado de implantação a partir de um momento específico capturado 

Onde o Terraform atinge seu limite

Mesmo os ambientes de IaC mais maduros enfrentam situações de recuperação em que a reconstrução a partir do código não é suficiente. Considere o seguinte:

  • Uma alteração na infraestrutura que deu errado e já havia sido implantada em produção.
  • Exclusão acidental de recursos d cloud .
  • Desvio na infraestrutura causado por alterações manuais ou fora da banda.
  • Alterações feitas fora do Terraform que não se refletem no código ou no estado.
  • A necessidade de restaurar a infraestrutura exatamente como estava em um determinado momento.
Terraform does not maintain historical cloud state. It re-applies a desired configuration – it does not restore what was actually deployed and running. “Rewind to 2:15 PM yesterday” is not a Terraform feature. It is a Cloud Rewind feature.

Uma recuperação que dependa da disponibilidade, precisão e integridade do código do Terraform, dos arquivos de estado e do histórico de versões é uma recuperação que acarreta um risco real. Em um incidente real, essas condições não são garantidas.

Duas ferramentas, uma estratégia completa

Terraform helps you automate infrastructure creation and change management. Cloud Rewind helps you recover infrastructure quickly and consistently when deployments fail, resources are deleted, infrastructure drifts, or your team needs to restore a known-good environment.

They complement each other. Terraform is designed to make your cloud environment repeatable. Cloud Rewind is designed to make it recoverable.

Build with Terraform.Recupere com o Cloud Rewind.

Perguntas frequentes

Q: Does Terraform provide point-in-time recovery?

A: No. Terraform re-applies a desired configuration from code. It does not maintain historical snapshots of your deployed cloud environment. If the change that caused an incident is not captured in your Terraform state or Git history – for example, a console change or infrastructure drift – Terraform cannot help you restore it.

Q: What happens when changes are made outside Terraform?

A: Console changes, manual interventions, and out-of-band configurations are common in real environments. Terraform does not track them. Cloud Rewind captures actual deployed state – regardless of how a change was introduced – so you can restore a known-good environment even when your IaC does not reflect what was running.

Q: Is Cloud Rewind a replacement for Terraform?

A: No. They solve different problems. Terraform is your provisioning and change management tool. Cloud Rewind is your recovery tool. Most teams that use one can benefit from both – they cover different parts of the cloud operations lifecycle.

Q: What kinds of incidents does Cloud Rewind address?

A: Cloud Rewind is designed for scenarios where rebuilding from code is not enough: failed deployments already in production, accidental resource deletion, infrastructure drift, and cases where teams need to restore an environment to a specific historical point in time.

Q: Does Cloud Rewind require teams to stop using Terraform?

A: No. Cloud Rewind works alongside your existing IaC workflows. Teams continue to use Terraform for provisioning and change management and use Cloud Rewind when they need to recover from a real incident.

Cailin Pitcheré gerente sênior de marketing de portfólio na Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Pontos principais 
  • Commvault integrates frontier AI vulnerability discovery into its risk-based security program rather than relying on AI as a standalone solution.
  • Every AI-generated finding is reviewed and validated by humans before remediation decisions are made.
  • Frontier AI complements established security practices such as static analysis, dynamic analysis, and penetration testing by expanding code coverage and identifying more complex exploit scenarios.
  • Commvault maintains strict governance over source code, vendor access, and vulnerability handling.
  • Commvault is investing in scalable vulnerability management processes in order to respond efficiently as AI increases the volume of potential security findings.

Across the security industry, AI and large language models are being applied to vulnerability discovery – helping teams evaluate more code, explore more attack paths, and identify exploitable conditions faster than manual review alone.  

This is not a niche experiment. It is a shift in how thorough a security evaluation can be, and it is changing what customers reasonably expect from their software vendors. 

Customers are regularly asking their software vendors: Do you test your own products against the same methods a threat actor might use? Are the processes behind that testing rigorous enough to keep pace? These are the right questions to ask. 

Our Approach: Strong Processes, no Single Tool

Commvault’s security posture is built on strong, repeatable processes rather than dependence on any single tool, model, or vendor.  

Vulnerability management follows an established, risk-based framework: Findings are assessed for practical exploitability, prioritized by severity and exposure, and remediated through our standard development lifecycle. That framework applies the same way regardless of whether a finding comes from a penetration test, an external researcher, or AI. 

AI vulnerability discovery is integrated into this framework as an additional capability, not a separate program running on its own rules. Candidate findings generated through AI methods are treated as inputs that require human confirmation of exploitability before any remediation action is taken. That step helps prevent two failure modes at once: under-prioritizing genuine risk and burning cycles on false positives. 

AI Alongside Established Security Practices

AI methods do not replace the disciplines that have always defined responsible vulnerability management. Static analysis, dynamic analysis, penetration testing, and established scanning tools remain essential parts of our program.  

What AI adds is coverage depth: the ability to evaluate a broader set of code paths, model more complex exploit conditions, and surface findings that require contextual understanding rather than simple pattern matching. 

Our vulnerability program is tool-agnostic and model-agnostic by design. We are not dependent on any single vendor or model, and new approaches can be added as they prove out, without re-architecting how findings are governed or remediated. The advantage isn’t which model we use but whether the process behind it is disciplined enough to act on what that model finds. 

Governance and Controls

Every AI scan we run operates under the same governance principles: 

  • AI models are vetted before used. Any vendor and tooling access is governed by formal NDA and engagement terms.
  • Findings are processed through the same security engineering review pipeline used for every other vulnerability source.
  • No AI-generated finding is acted upon without human triage and exploitability confirmation.
From Candidate Finding to Confirmed Fix

Findings generated through AI are treated as candidates, not confirmed vulnerabilities. Each one is assessed by engineers and product security experts for practical exploitability in realistic customer environments.  

Severity ratings are assigned based on exposure, exploitability, and impact – not on how the finding was discovered. Confirmed vulnerabilities move through the same remediation timelines and escalation paths as any other source, with priority set by severity and exposure. 

First Patch Tuesday Disclosures – August 2026

Our inaugural Patch Tuesday, published August 11, 2026, includes the following disclosures: 

CVE ID  Severity  Resumo 
CVE-2026-13737  Crítico  CommServe contained an allowlist bypass affecting command execution authorization.  
CVE-2026-13738  Crítico  CommServe contained an authorization bypass affecting a limited set of command execution operations.  
CVE-2026-13739  Alta  A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) related to the handling of arbitrary target URLs. 

 

Full technical advisories, including affected versions and remediation guidance, are available on our Security Advisories page. Read more about the move to a monthly cadence in Bringing  Trust to CVE Disclosures.  

Why Operational Readiness Matters More Than Any Single Tool

As AI vulnerability discovery becomes standard practice across the industry, the volume of potential findings that security teams need to evaluate will keep rising. The question that matters for any enterprise software vendor isn’t which AI model they use. It’s whether their vulnerability management process is mature enough, and scalable enough, to handle that throughput without creating a backlog that increases customer exposure. 

We pair our investment in AI with an equal investment in the process infrastructure needed to act on what it finds: triage capacity, severity prioritization, remediation tracking, and coordinated disclosure practices. Our investment is only as valuable as the response capability behind it. 

Perguntas frequentes

Q: What is Commvault doing with frontier AI security testing? 
A: We actively evaluate our products using AI methods as part of our structured security engineering program. We are being thoughtful about testing different models and harnesses so that we find any potential vulnerabilities previously undiscovered by humans and or existing testing. That work follows the same vulnerability management process as every other form of testing. This is underway today – it isn’t a roadmap item. 
Q: How is Commvault preparing for AI vulnerability discovery? 
A: We built a program that is model-agnostic and tool-agnostic by design. Our goal is to make sure our security engineering practice can incorporate the best available methods across a range of AI tooling, inside one consistent governance and risk management framework. 
Q: Is Commvault using these models safely? 
A: Yes. All AI scans are thoroughly vetted. Any vendor and tool access is governed by formal NDA and engagement terms, and every AI-generated finding requires human confirmation of exploitability before any remediation action is taken. 
Q: How is Commvault scaling vulnerability management for the AI era? 
A: Our focus is on making sure the response process scales with discovery volume and discovery pace. As AI increases the number of potential findings our teams need to review, we’re investing in risk-based triage, consistent remediation service level agreements, and the operational infrastructure needed to act on higher discovery throughput within accelerated timeframes to decrease exposure for customers. 

Bill O’Connell is Chief Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

When frontier AI models started making headlines, most of the discussion centered on one question: What happens when attackers gain access to them? 

It’s a fair question.  

Models capable of discovering vulnerabilities faster, chaining exploits together, and operating at unprecedented speed naturally raise concerns for every CISO.  

But after spending time talking with customers over the past several months – and in my conversation with Tim Zonca, Commvault’s VP of Portfolio Marketing, in this episode of STRIVE – I think there’s an even more important question emerging. 

What happens to resilience itself? 

Because while frontier AI will undoubtedly accelerate cyber threats, it’s also accelerating something else: Enterprise complexity. 

Watch the episódio completo. 

 Pontos principais 

  • Frontier AI isn’t just accelerating cyberattacks – it’s accelerating enterprise complexity.  
  • Vulnerability management isn’t disappearing, but the speed and scale of discovery are changing dramatically.  
  • AI systems introduce entirely new recovery dependencies, including agents, vector databases, embeddings, and distributed state.  
  • Organizations need a coherent understanding of their environments before they can recover them.  
  • The next generation of resilience will depend on trusted systems of record that explain what happened, why it happened, and how to recover confidently.  
The Conversation Has Changed 

One thing Tim and I discuss early in the episode is how differently organizations are reacting to frontier AI. 

  • Some see an entirely new class of cybersecurity challenge. 
  • Others view it as simply the next evolution of vulnerability management. 

What’s interesting is that neither perspective is necessarily wrong. 

The processes organizations use to identify, prioritize, and remediate vulnerabilities remain familiar. But the pace at which AI can discover those vulnerabilities – and uncover entirely new chains of attack – is unlike anything we’ve seen before.  

That’s the shift. 

The work isn’t fundamentally different. The speed is. 

When AI Changes the Shape of Recovery 

Most conversations about AI focus on security and prevention: 

  • How do we secure models? 
  • How do we protect prompts? 
  • How do we defend against AI-assisted attacks? 

Those are important questions. But resilience introduces a different one: What exactly are we recovering? 

Traditional enterprise applications already involve complicated relationships between infrastructure, applications, and data. AI expands that picture considerably. Now there are agents operating across multiple systems. Vector databases. Embeddings. Models interacting with different data sources simultaneously. It’s become far more than a traditional application stack.  

Recovery is no longer about restoring an application. It’s about restoring an ecosystem. 

Sneak Peek: Check This Out 

In this moment from our STRIVE discussion, Tim and I discuss the growing complexity of AI stacks, what coherent recovery is (and why it matters), and how Commvault is helping our customers with full AI-stack recovery. 

Why Coherency Matters 

One idea that keeps surfacing throughout our conversation is coherence. 

For years, organizations have worked to map application dependencies, understand infrastructure relationships, and identify critical services. AI makes that challenge significantly more difficult. 

Applications no longer interact with a single database or service. They may depend on multiple models, agents, data stores, and orchestration layers – all changing dynamically. 

Understanding those relationships isn’t just an architectural exercise anymore. 

It’s a recovery requirement. 

Because if you don’t understand what makes up the system, it’s difficult to know whether you’ve actually recovered it. 

A New System of Record 

Another concept from Tim that I found compelling is the idea of a system of record for the AI era. Historically, systems of record gave organizations confidence in business data. Customer records lived in CRM platforms. Financial records lived in ERP systems. 

AI changes that expectation. 

Organizations increasingly need trusted visibility into how data is used, what agents interact with it, why decisions are made, and whether restored environments represent a known-good state.  

That doesn’t replace resilience. It strengthens it. Because confidence in recovery depends on confidence in what you’re recovering. 

AI Can Also Help Solve the Problem 

As organizations struggle to understand increasingly distributed environments, AI becomes a powerful tool for discovery, classification, and policy recommendation.  

Rather than manually identifying relationships across sprawling environments, organizations can use AI to help identify dependencies, recommend protection policies, and continuously update those relationships as environments evolve. 

That’s an important shift. 

The same technology that’s adding to organizational complexity may also become one of the best tools for managing it. 

Por que essa conversa é importante 

Frontier AI isn’t simply introducing another cybersecurity challenge. It’s forcing organizations to rethink resilience itself. 

Recovery is becoming less about individual systems and more about restoring trusted business operations across increasingly intelligent environments. That means resilience strategies must evolve alongside the technologies they’re protecting. 

Organizations that prepare for that shift won’t just recover faster. They’ll recover with greater confidence. 

Assista ao episódio completo 

In this conversation, Tim and I explore: 

  • How frontier AI is changing enterprise risk.  
  • Why vulnerability management is entering a new phase.  
  • What AI means for modern recovery architectures.  
  • The role of coherent recovery across AI-enabled environments.  
  • Why trusted systems of record will become increasingly important.  

Assista agora sobre. 


Perguntas frequentes 

Q: What are frontier AI models? 
A: Frontier AI models are the latest generation of highly capable AI systems designed to solve increasingly complex reasoning and cybersecurity tasks. 
Q: Why are organizations concerned about them? 
A: They dramatically accelerate vulnerability discovery, exploit chaining, and security research, increasing both defensive and offensive capabilities. 
Q: How does AI change cyber resilience? 
A: AI introduces new dependencies – including agents, models, vector databases, and distributed states – that make recovery more complex. 
Q: What is a coherent recovery strategy? 
A: It’s an approach that restores not only data, but also the applications, infrastructure, dependencies, and AI components required for trusted business operations. 
Q: What is a system of record in the AI era? 
A: It’s a trusted source that helps organizations understand what happened, why it happened, and whether recovered systems represent a known-good state. 
Q: What should organizations do now? 
A: Begin mapping AI dependencies, understand how AI changes recovery requirements, and develop resilience strategies that account for increasingly intelligent application environments. 

Chris Mierzwa is Senior Director of Portfolio Marketing at Commvault. 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Proteção Unificada de Dados | Recuperação após Ataque de Ransomware | Cleanroom Recovery | Cargas de Trabalho Híbridas

Como unificar a proteção de dados em todas as cargas de trabalho híbridas

Commvault® Cloud helps organizations discover, govern, and unify workload protection, allowing teams to rebuild critical services quickly after a cyber incident.


You’re the VP of IT Operations. It’s 2:00 a.m. on a Saturday. Your SecOps team just confirmed ransomware has encrypted files across three regions. Your last backup job completed successfully – but when your team attempts to restore the ERP system, the application fails to start.

The backup was marked successful. The data was present. But the dependencies, transaction logs, and service relationships were never captured in a consistent, recoverable state. Recovery isn’t just about data – it’s about rebuilding services.

This scenario plays out across hybrid environments every day. Modern enterprises run on interconnected cloud-native services, Kubernetes clusters, hybrid databases, and SaaS platforms – none of which recover cleanly from a simple file restore. Fragmented protection strategies designed for a simpler era leave organizations exposed at exactly the moment resilience matters most.

A Commvault Cloud is an AI-enabled platform designed to help organizations discover, govern, and unify data protection across cloud-native, hybrid, and on-premises workloads – from a single control plane. Capabilities such as AI-enabled workload discovery, Cleanroom Recovery, do Cleanpoint Identification, Threat Scan, and Command Center orchestration help teams validar recovery readiness and rebuild critical services in a controlled sequence after a cyber incident. 

45%

of organizations are repeat ransomware victims – meaning fast recovery without clean validation reinfects as often as it restores. 
ESG Research — Zero Trust and Ransomware Protection Report 

What Is Unified Data Protection – and Why Does It Matter? 

Unified data protection is a backup and recovery approach that helps organizations govern the broadest range of workloads – including cloud databases, Kubernetes, SaaS, hypervisors, and on-premises systems – from a single control plane, rather than managing separate tools and policies for each environment.Commvault Cloud Unityfoi projetado para dar suporte a essa abordagem, ajudando as equipes a reduzir a complexidade operacional e manter uma proteção consistente em ambientes híbridos e multicloud.

Fragmented data protection strategies can create invisible gaps: inconsistent policies across environments, coverage blind spots that surface only during recovery, and manual overhead that scales poorly as workloads diversify. When ransomware strikes or an outage occurs, teams may discover too late that critical workloads were not protected consistently. A unified approach is designed to help address this by bringing all workloads under a centralized policy engine – so protection status, retention schedules, and recovery workflows are governed from one place.

  • Commvault Cloud workload coverage: Unified protection across cloud databases (AWS RDS, Azure SQL, SAP HANA, Oracle), hypervisors (VMware, Hyper-V), Kubernetes (AKS, EKS, GKE), SaaS (Microsoft 365, Salesforce, Google Workspace), and on-premises infrastructure.
  • Unified control plane: All workloads managed from a single AI-enabled Command Center –helping reduce fragmented policy sets and manual operational overhead.
  • AI-enabled discovery and tagging: Automated workload inventory and classification can help teams identify coverage gaps and bring unprotected resources under policy.
  • TCO analysis: Real-time visibility into protected status and cost drivers can support budget governance across cloud, hybrid, and on-premises environments.

Como o Commvault Cloud ajuda você a identificar e gerenciar a proteção de cargas de trabalho?

Effective data protection depends on knowing what you have before an incident occurs – not discovering gaps during recovery. Commvault Cloud is designed to help organizations continuously discover, classify, and apply backup policies across hybrid and multi-cloud assets, so coverage stays current as environments change.

Commvault Cloud begins with AI-enabled discovery –automatically inventorying cloud-native and hybrid assets, identifying resources without policy coverage, and bringing workloads under centralized governance in Command Center. Policies can be applied consistently across accounts, regions, and clouds, with real-time visibility into protected status and cost. Because environments change continuously – new workloads deployed, configurations updated, cloud resources spun up – discovery is designed to run as an ongoing process rather than a one-time assessment, helping teams maintain accurate coverage without manual audits.

  • AI-enabled discovery: Continuously inventories cloud-native and hybrid assets, identifies coverage gaps, and brings new workloads under centralized policies.
  • Centralized policy engine: Command Center applies consistent retention schedules, backup frequency, and copy policies across multi-cloud, hybrid, and on-premises workloads from a single interface.
  • Commvault Threat Scan: Continuously monitors backup data for anomalies, encryption activity, and malware indicators so security teams can act before recovery begins.
  • Cross-region and cross-cloud copies: Backup copies can be created across regions and cloud providers to support compliance, data residency requirements, and resilience posture.

Why Do Fragmented Tools Fail at Recovery Time?

89% of organizations operate in environments environments with more than one cloud, including hybrid cloud and multi-cloud set ups, yet most recovery failures don’t stem from a lack of backup jobs – they stem from protection that wasn’t built for the environment being recovered. Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.Workloads spread across cloud databases, SaaS platforms, Kubernetes clusters, and on-premises systems each have different backup requirements, and point tools designed for one environment rarely translate cleanly to another.

Recovery failures surface the gap between a backup that ran and a service that actually restarts. Crash-consistent snapshots may restore raw data while leaving transaction logs, service dependencies, and cluster configurations in an inconsistent state – meaning the application cannot start even when the data is present. Unified data protection can help address this by ensuring workloads are protected in a way that reflects how they operate, and by validating recovery readiness before an incident forces the question.

Commvault Cloud supports security leaders who require audit-ready recoverability, IT teams managing hybrid and multi-cloud environments, and cloud and compliance stakeholders responsible for protecting and validating critical workloads. Commvault was recognized in the IDC MarketScape: Worldwide Cyber-Recovery 2025 Vendor Assessment for strengths in cyber recovery architecture, security ecosystem integration, and workload breadth.

  • Continuous backup monitoring: Threat Scan monitors backup data for malware indicators, encryption activity, and anomalous behavior –with alerts integrated into SIEM and SOC tools for coordinated incident response.
  • Commvault Cleanroom: Designed to stage restoration in an isolated environment so teams can validate data integrity and confirm systems are threat-free before returning to production – reducing reinfection risk.
  • Cleanpoint Identification: Designed to help pinpoint when data may have become compromised, providing more precise selection of a verified recovery point and supporting minimization of data loss.
  • Orchestrated service recovery: Command Center workflows can restore dependent services in sequence – helping reduce the manual coordination burden during high-pressure recovery events.
  • Scalable on-premises protection: HyperScale supports on-premises protection for hybrid environments, with streamlined onboarding and management through Command Center.

Microsoft Azure (nuvem)

Descoberta, classificação e backup com reconhecimento de aplicativos no Azure SQL, nas VMs do Azure, no Azure Blob e nas cargas de trabalho hospedadas no Azure.

Microsoft Entra ID (Identidade)

Identity-based access governance integration – connects classification-based controls to Entra ID-managed users and AI service principals for policy enforcement.

AWS (Nuvem)

Application-aware protection across AWS-hosted workloads including RDS, EC2, and EKS – via native API integrations.

Okta (Identidade)

Identity-based access policy integration –connects Commvault access governance to Okta-managed identities for role-based enforcement.

Google Cloud (Nuvem)

Descoberta e backup com reconhecimento de aplicativos no Google Cloud Storage, GKE (Google Kubernetes Engine) e cargas de trabalho conectadas.

ServiceNow (ITSM)

Integration for incident and audit workflows – connects Commvault threat scan events and recovery actions to ServiceNow ticketing for compliance reporting.

Como funciona


Discover and protect

AI-enabled discovery inventories cloud-native, hybrid, and on-premises assets to identificar unprotected workloads. Command Center applies centralized policies – including backup frequency and retention – across environments, with cross-region and cross-cloud copies to support resilience and compliance. 


Monitor and detect

Threat Scan monitors backup data for anomalies, encryption activity, and malware indicators. Alerts integrate with SIEM and SOC tools, helping teams isolate affected data and plan a response before recovery begins. 


Validate and recover

Cleanpoint Identification helps pinpoint when data may have been compromised and surfaces viable recovery points. Cleanroom Recovery stages restoration in an isolated environment for validation before production restore, while Command Center orchestrates service recovery in the correct sequence to support controlled, reinfection-resistant recovery.


Before unified data protection, the most dangerous moment in incident response was often the restore itself – when teams discovered coverage gaps they didn’t know existed. With Commvault Cloud, teams can move from reactive gap discovery to proactive governance: understanding which workloads are protected, at what policy level, and whether recovery points have been validated. That shift – from hoping a backup worked to demonstrating that it can – can make the difference between a measured recovery and an extended outage.

Pronto para unificar a proteção em todas as cargas de trabalho híbridas?

Veja como o Commvault Cloud pode ajudar sua equipe a identificar, gerenciar e recuperar todas as cargas de trabalho de forma eficiente.

Perguntas frequentes

O que é proteção unificada de dados?

A proteção unificada de dados é uma abordagem para gerenciar Backup and Recovery em cargas de trabalho nativas da nuvem, multicloud e locais a partir de um único plano de controle. O Commvault Cloud oferece suporte a isso ao aplicar políticas e cobertura consistentes em todos os ambientes — ajudando as equipes a reduzir a complexidade operacional e a manter a visibilidade do status da proteção.

Por que estratégias fragmentadas de backup falham na hora da recuperação?

Estratégias de backup fragmentadas podem gerar políticas inconsistentes, lacunas ocultas na cobertura e sobrecarga de trabalho manual que não se adapta bem a ambientes híbridos.

O Commvault Cloud resolve isso com um plano de controle unificado, políticas centralizadas e descoberta habilitada por IA – ajudando as organizações a identificar e sanar essas lacunas antes que elas afetem a Recovery.

Como o Commvault Cloud oferece proteção de dados para cargas de trabalho híbridas?

O Commvault Cloud oferece proteção unificada de dados em ambientes de nuvem, SaaS, Kubernetes e locais por meio de uma única plataforma com tecnologia de IA. O Command Center, a descoberta com tecnologia de IA e o Cleanroom Recovery atuam em conjunto para centralizar políticas, identificar lacunas de cobertura e ajudar a validar os dados antes da restauração em produção — proporcionando um processo de recuperação mais controlado.

O que é a Cleanroom Recovery e como ela funciona?

O Cleanroom Recovery oferece um ambiente isolado para restaurar e validar dados com segurança antes de sua utilização em produção. Ao combinar a Threat Scan com a validação no nível do aplicativo, ele ajuda sua equipe a reduzir o risco de reinfecção e a realizar a recuperação com maior controle após um incidente cibernético.

Como a proteção unificada de dados atende aos requisitos de RTO e RPO?

O Commvault Cloud ajuda a alinhar a proteção de dados às prioridades de negócios e apoia os objetivos de RTO e RPO. Os fluxos de trabalho de recuperação orquestrados no Command Center e a identificação do Cleanpoint, combinados com um plano de controle unificado, ajudam a reduzir o tempo de inatividade, melhorar a consistência e permitem que as equipes monitorem o status da proteção e resolvam lacunas de forma proativa.

Quais integrações o Commvault Cloud oferece para resposta a ameaças?

O Commvault Cloud se integra nativamente ao Microsoft Azure, Entra ID, AWS, Google Cloud, Okta e ServiceNow. Os sinais do Threat Scan são encaminhados para ferramentas SIEM e SOC, e as ações de recuperação se conectam a plataformas de ITSM, como o ServiceNow, para acompanhamento de incidentes e geração de relatórios de auditoria.

Recursos relacionados

Resumo da solução

Proteção de dados segura e resiliente

Descubra como a proteção de dados moderna combina backups imutáveis, resiliência contra ransomware e Recovery rápida para as operações de negócios.
Leia o resumoabout Proteção de dados segura e resiliente
eBook

5 Questions Most Data Protection Providers Won’t Answer

Descubra as perguntas essenciais a serem feitas durante as avaliações de fornecedores para revelar custos ocultos e validar os reais recursos de Recovery.
Obter o livro eletrônicoabout 5 Questions Most Data Protection Providers Won’t Answer

For years, cyber resilience has been defined by technology – security controls, sophisticated detection capabilities, and increasingly robust backup strategies designed to prevent attacks or recover more quickly. Those investments remain essential, but they are no longer enough. 

AI has fundamentally changed the nature of cyberattacks, which now move at a speed that challenges even mature organizations. As the window between compromise and business disruption continues to shrink, resilience is becoming less about preventing every attack and more about keeping the enterprise running when prevention inevitably falls short. 

That shift is at the heart of IDC’s new report, Resilience Operations: The Discipline that Makes Readiness Provable. Based on a survey of more than 500 North American organizations, the report argues that resilience is evolving into a cross-functional operating discipline that connects business priorities with cybersecurity, ITOps, and disaster recovery. More importantly, it reveals several gaps that suggest many organizations are still preparing for a threat landscape that no longer exists. 

Here are the insights that stood out. 

Recovery should begin with business outcomes – not technical ones.

Historically, recovery planning has focused on restoring infrastructure as quickly as possible, with success judged by recovery time objectives, backup completion rates, and application availability. While those measures remain valuable, they don’t necessarily answer the question executives care about most: When can we get the business back online? 

IDC argues that resilience should be anchored to business outcomes rather than technical milestones – restoring the capabilities that allow the organization to serve customers, generate revenue, and meet its obligations. That may sound like semantics, but it changes how recovery priorities are established. Technology becomes the means to an end rather than the end itself. 

Most organizations still haven’t defined what matters most.

Nearly 6 in 10 organizations have not fully defined their minimum viable business (MVB) – the smallest set of functions, systems, processes, and data required to continue operating after a disruption. 

Without a shared understanding of what the business truly depends on, every movement during recovery becomes reactive. By defining your MVB before a crisis, you’ll enable faster decisions, better coordination during recovery, and ultimately a more resilient organization. 

Automation is becoming the dividing line between resilience and recovery debt.

While attackers increasingly automate reconnaissance, exploitation, and lateral movement, many organizations still rely on manual recovery processes. 

That imbalance is becoming increasingly difficult to ignore. AI is compressing attack timelines, but recovery timelines have not kept pace. Organizations that fail to automate these recovery tasks may find themselves spending days assembling and executing plans while the damage has already been done. 

Automated recovery orchestration, clean recovery point identification, and coordinated validation are becoming foundational capabilities for recovering at the speed modern attacks demand. 

Technology isn’t the biggest resilience challenge – organizational alignment is.

Security teams focus on containment, infrastructure teams focus on restoration, business leaders focus on customer impact, and compliance teams focus on regulatory obligations. None of these priorities are inherently wrong, but when they evolve independently, organizations enter a crisis without a shared operating model. 

Enter ResOps. Rather than positioning resilience as an IT responsibility, the report frames it as a discipline that deliberately brings together business, security, infrastructure, and recovery planning. The message is clear: Resilience depends less on individual tools than on creating shared priorities before an incident forces you to make difficult decisions. 

Testing remains one of the strongest indicators of resilience.

IDC found that relatively few organizations conduct frequent tabletop exercises or cyber-range simulations, despite decades of evidence showing that rehearsal consistently improves performance during real incidents. 

Exercises reveal hidden dependencies, expose communication gaps, and allow teams to make decisions without the real consequences. Organizations that repeatedly validate their recovery processes develop a level of confidence beyond planning alone. 

Tomorrow’s resilience challenges are already taking shape.

Ransomware still dominates headlines, but the next resilience challenges have already emerged – from agentic AI and machine identities to post-quantum cryptography. 

These threats remind us that resilience planning can’t focus exclusively on today’s infrastructure. Recovery increasingly involves cloud services, SaaS applications, AI models, machine identities, third-party providers, and distributed digital ecosystems that didn’t exist a decade ago. 

Resilience is becoming measurable.

IDC’s ResOps Maturity Model is invaluable for assessing your organization’s current posture. Rather than treating resilience as something organizations either possess or lack, the framework describes a progression from reactive, siloed operations to mature, adaptive resilience built on governance, automation, and continuous improvement. 

To me, that progression acknowledges an important reality: Resilience is never finished. It’s not about purchasing a platform or completing a project. Organizations become resilient by continually improving how technology, people, and business processes work together under pressure. 

Viewed through that lens, resilience becomes less like insurance and more like operational excellence – a capability that can be assessed, strengthened, and demonstrated over time. 

We’re undergoing a broader shift in how organizations think about resilience.

Resilience conversations are evolving from protecting infrastructure to protecting the business itself. That means recovery planning starts with customers instead of servers, governance becomes as important as technology, and confidence comes from proving capabilities rather than documenting intentions. 

ResOps isn’t really a new framework; rather, it’s a broader recognition that cyber resilience has become an operational discipline. As attacks become faster and more complex, resilience will be measured not by the absence of incidents, but by an organization’s ability to continue serving customers, supporting employees, and maintaining trust despite disruption. 

That’s ultimately what ResOps is designed to prove. 

Rajiv Kottomtharayilé diretor de produtos da Commvault. 

More related posts


Cyber Resilience

Read more about Cyber Resilience

Pontos principais

  • Trust in the age of AI isn’t disappearing – it’s evolving.
  • As organizações precisam verificar a IA continuamente, em vez de confiar nela por padrão.
  • A adoção da IA deve capacitar os funcionários, e não levá-los a recorrer à IA paralela.
  • Zero trust isn’t about distrusting people. It’s about continuously validating identities, devices, and actions.
  • A adoção responsável da IA exige que a tecnologia, a governança e as pessoas trabalhem em conjunto.

When we launched Ready. Or Not., we wanted to create a series that made some of today’s biggest AI conversations easier to understand. By pairing comedian Nathan Macintosh with industry experts, we’re exploring everything from agentic AI and cyber resilience to data management – and adding a little humor along the way.

If you caught our first episode on the oportunidades e os riscos da IA agênica, I think you’ll enjoy this one as well. This time, we’re tackling a topic that’s at the center of every AI conversation: trust.

Nathan sits down with Diana Kelley, Chief Information Security Officer at Protect AI, for a conversation about what it means to trust technology when AI can generate convincing fake content, make decisions, and even imitate people. From deepfakes and hallucinations to zero trust and shadow AI, they explore how organizations can embrace AI without losing confidence in their people and systems.

Assista ao episódio completo no Readiverse.Saí desse episódio me sentindo mais otimista do que esperava. Não porque a IA tenha se tornado, de repente, mais confiável, mas porque Diana nos mostra que a confiança cresce quando as organizações implementam as políticas, as medidas de proteção e a tecnologia adequadas. Aqui estão alguns temas da conversa que colocam a IA sob uma nova perspectiva.

Confiança e tecnologia podem coexistir

Diana believes trust is possible in the AI era, but it’s going to look different. We’ve always built trust through relationships with people. Now, we’re learning how to extend that trust to systems.

That doesn’t mean trusting technology blindly. It means understanding how AI works, recognizing its limitations, and putting the right safeguards in place so people and technology can work together with confidence.

“Trust has to evolve for the new world.”

– Diana Kelley

What resonated with me was the idea that trust and technology don’t have to be at odds with one another. With the right approach, they can strengthen each other.

We’re Getting Smarter About AI

Deepfakes have become one of the most talked about AI risks, and it’s easy to understand why. AI can now generate convincing voices, images, and videos that make us question what’s real. But Diana pointed out that while AI is getting more sophisticated, people are getting smarter. We’re more likely to question an unexpected phone call, take a closer look at a social media post, or pause at something that doesn’t feel quite right.

Organizations are becoming savvier, too. As AI gets better at impersonation, businesses are investing in new ways to continuously verify identities and validate information. My takeaway is this: Technology will continue to improve, but so will our ability to recognize it and respond responsibly.

“Is today a good day to start a deepfake?”

– Nathan Macintosh

A IA responsável é boa para os negócios

Diana shared an example that will probably sound familiar to many organizations. An employee she calls “Karen in Finance” starts using AI because it helps her complete a task in minutes instead of hours. Karen isn’t trying to work around company policy – she’s trying to be more productive.

Employees use AI because they see real value in it, and that’s an opportunity for organizations. When employees have access to approved AI tools, supported by clear policies and practical guidance, they can work more efficiently while helping protect company data and systems.

Prévia: Adoção mais inteligente da IA

The goal isn’t to stop employees from using AI. It’s to make sure they’re using it the right way. Diana explains how organizations can encourage AI adoption without creating unnecessary risk.

A abordagem “Zero Trust” é mais importante do que nunca

“When you understand how things work, then you can start to understand how to manage them.”

– Diana Kelley

Zero trust is one of those concepts that’s much easier to understand with an analogy. Diana has a great one. She describes it as moving through a building. Just because you’ve been allowed through the front door doesn’t mean every other door automatically opens for you. Each time you access a new room, there’s another quick check to confirm you’re supposed to be there.

That’s essentially how zero trust works. Instead of assuming a person or device is trustworthy after a single login, organizations continuously verify identities, devices, and actions as technology becomes more connected. Most of those checks happen quietly behind the scenes.

One of the things I appreciated about Diana’s explanation is that zero trust doesn’t feel like another security buzzword. It feels like a practical way to think about trust in a world where AI and digital identities are becoming part of everyday business.

A confiança tem a ver com as pessoas

At the end of the day, technology doesn’t create trust – people do. People define the policies, processes, and ethical boundaries that guide how AI is used, while technology helps verify that those guardrails are working as intended. It’s that partnership between people and technology that makes responsible AI possible.

Trust extends beyond our own organizations. Businesses need confidence in the partners they work with, the systems they connect to, and the technologies they adopt. That’s why transparency, shared standards, and continuous verification are becoming just as important as innovation itself. The more AI becomes part of everyday business, the more trust becomes everyone’s responsibility.

Olhando para o futuro

AI will continue to evolve, and so will the way we interact with it. The organizations that succeed won’t be the ones that trust AI blindly or avoid it altogether. They’ll be the ones that build strong policies, adopt the right technologies, and continuously verify the systems they rely on.

Trust isn’t something we lose as technology advances. It’s something we intentionally build and evolve. That’s exactly the kind of conversation we hope to continue with every episode of Ready. Or Not.

Assista ao episódio completo no Readiverse.

Perguntas frequentes

Q: What is digital trust?

A: Digital trust is the confidence that people, systems, and organizations are who they claim to be and are acting in expected, secure ways. It combines technology, governance, and verification to help organizations interact safely.

Q: What are deepfakes?

A: Deepfakes are AI-generated images, videos, or audio recordings designed to closely imitate real people. While they have legitimate uses, they can also be used to impersonate individuals or commit fraud.

Q: What is zero trust?

A: Zero trust is a security model based on continuous verification rather than automatic trust. Instead of assuming a user or device is trustworthy after one login, organizations continuously validate identities and actions.

Q: What is shadow AI?

A: Shadow AI refers to employees using AI tools that haven’t been approved or governed by their organization. While often well-intentioned, it can introduce security, privacy, and compliance risks.

Q: Why shouldn’t organizations simply block AI tools?

A: Employees typically adopt AI because it helps them work more efficiently. Rather than banning AI outright, organizations should provide approved tools, establish clear policies, and educate employees on responsible use.

Q: What’s the biggest takeaway from this episode?

A: Trust isn’t disappearing because of AI – it’s evolving. Organizations that combine people, policies, and technology with continuous verification will be better positioned to adopt AI confidently and responsibly.

Katherine Demacopoulosé diretora sênior de Estratégia e Programas de Conteúdo Global da Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Our Chief Products Officer, Rajiv Kottomtharayil, recently wrote about a big shift that is taking place across industries. Frontier AI models are compressing the time between vulnerability discovery and exploitation.  

This shift is prompting organizations everywhere to re-examine their vulnerability management processes. We’re doing the same at Commvault. That’s why, starting August 11, we’re changing the rhythm of how we disclose vulnerabilities.  What’s ChangingWe are raising the bar for security, transparency, and customer trust. On August 11, and on the second Tuesday of each month after that, we’re introducing Patch Tuesdays: a scheduled monthly release where we share security advisories and vulnerability patches.  

Patch Tuesdays are a hallmark of leading technology companies, because they provide customers with a predictable security rhythm.  This matters even more as the pace of vulnerability discovery accelerates. Of course, if there is an urgent vulnerability that must be reported off cycle, we will not hesitate to follow our well-established processes.  

Where You Can Find Up-to-Date Resources  

On the second Tuesday of each month, you’ll find new information pertaining to CVEs on our Security Advisories page. You also can find the official publications at MITRE’s CVE site. 

On the Commvault Security Center, you’ll find our vulnerability management program and other security-by-design thought leadership.   

For compliance certifications, audit reports, and documentation on how Commvault protects customer data, visit the Commvault Trust Center. You can subscribe to updates from the Trust Center at the link in the upper righthand corner of the page. 

Bill O’Connell is Chief  Security Officer at Commvault. 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

For decades, technology leaders have been trying to eliminate silos. Entire modernization programs have been built around connecting applications, consolidating platforms, and giving organizations a more complete view of their data.

Those efforts have delivered enormous value, but they also have shaped the way we think about resilience. When something goes wrong, we instinctively look for technical fragmentation. However, we’ve found the greater challenge lies elsewhere.

The most significant silos affecting cyber resilience today aren’t found in databases or applications but in organizational structures. They exist between security and infrastructure teams, between IT and the business, and between the people responsible for responding to an attack and those responsible for keeping the organization operating.

IDC’s latest research on ResOps, Resilience Operations: The Discipline that Makes Readiness Provable, suggests these organizational boundaries have become one of the defining obstacles to effective recovery. That’s a timely observation because cyberattacks have evolved in ways that can make those boundaries increasingly difficult to maintain.

Modern Attacks Don’t Follow Your Org Chart

A modern cyberattack rarely affects a single technology domain. A ransomware incident might begin with compromised identities, spread through cloud infrastructure, encrypt critical workloads, disrupt customer-facing applications, impact third-party services, and trigger regulatory Relatórioing requirements – all within a matter of hours. Every stage involves different teams, different tools, and different priorities.

Yet many organizations still prepare for recovery as though these responsibilities can be managed independently.

Security teams naturally focus on containing threats and preserving evidence. Infrastructure teams prioritize restoring systems and minimizing downtime. Business leaders concentrate on customers, revenue, and operational continuity. Communications teams think about reputation, while legal and compliance teams focus on regulatory obligations.

Each perspective is entirely reasonable. The problem arises when those priorities have never been reconciled before an incident occurs.

In the middle of a crisis, recovery requires decision-making under pressure. Which applications should return first? Which data can safely be restored? How much risk is acceptable before customer services resume? Who has the authority to make those decisions?

Without alignment, organizations often discover that the greatest delays aren’t caused by technology but by uncertainty – the kind that could be mitigated by better preparation.

Resilience Begins with a Shared Definition of What Matters

The Relatório places emphasis on establishing your minimum viable business (MVB). At first glance, it appears to be another recovery planning exercise, but its real value lies in the conversations it forces organizations to have.

Defining an MVB requires business leaders, security teams, infrastructure specialists, and application owners to agree on a deceptively simple question: What absolutely must continue operating if everything else stops?

That discussion changes the nature of resilience planning. Recovery priorities are no longer determined by whichever application owner argues most convincingly during an incident. Instead, they are established in advance, grounded in business outcomes, and supported by technical dependencies that everyone understands.

Perhaps more importantly, MVB creates a common language. Business leaders begin talking about critical capabilities rather than individual systems. Technology teams begin mapping infrastructure to customer outcomes rather than technical architectures. Security teams gain greater clarity about which assets deserve the highest levels of protection during recovery.

That shared understanding is precisely what many organizations have been missing.

Technology Can Automate Recovery – But it Can’t Create Alignment

The Relatório doesn’t argue that organizations need yet another platform. It argues they need a way of working that aligns people, processes, and technology around a single operational objective. This is where ResOps – a cross-functional discipline – proves its mettle.

Technology can help automate recovery, but it cannot resolve disagreements about business priorities. It cannot decide which customer services matter most. And it cannot replace the governance needed to coordinate multiple teams during a high-pressure event.

Those are leadership challenges, and they are best addressed by investing time in answering the difficult questions together, long before an attack forces your hand.

The Strongest Organizations Don’t Eliminate Silos – They Connect Them

Cyberattacks will continue evolving. AI will continue compressing attack timelines. New technologies will introduce new dependencies, and new threats will emerge alongside them. None of that changes the fundamental requirement for resilience.

Organizations don’t recover because individual teams perform brilliantly in isolation, but because those teams already know how to work together.

That may ultimately be the most important insight from IDC’s research. Resilience isn’t simply the product of better technology or more sophisticated security controls. It is the result of shared priorities, clear governance, and a tested operating model that brings the right people together before an incident occurs.

Vidya Shankaran is Field CTO at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Learn about our advances through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

By Sustainability Team

As AI adoption accelerates, cyber threats are becoming more sophisticated, and data regulations are expanding. Resilience is no longer simply a defensive posture – it is a business imperative and competitive advantage.

That belief is at the center of Commvault’s FY26 Sustainability Report, which is now available. This year’s report reflects the progress we’ve made across the areas that matter most to our business, our customers, our people, and the communities where we live and work.

Anchored by our updated materiality assessment, the report highlights how we are advancing sustainability through the lens of cyber resilience, responsible innovation, environmental efficiency, strong governance, and a culture of belonging and respect.

Cyber resilience remains foundational to our work. As organizations rethink what it means to be ready for disruption, Commvault continues to unify data security, identity resilience, and cyber recovery to help customers detect threats faster, operate more efficiently, and recover with greater confidence. We also are integrating AI and automation designed to support smarter, more secure, and more resilient operations.

That same focus on resilience extends to our environmental commitments. Our solutions help customers optimize data storage and movement, which can help reduce energy expenditure in data centers. For Commvault, responsible innovation means building solutions that support both operational strength and more efficient use of resources.

The report also reflects the people and principles behind our progress. Strong governance, a modern Code of Ethics, and continued investment in our talent help create the foundation for trusted partnerships and long-term value. These commitments are deeply connected: Strong governance enables responsible innovation, responsible innovation helps strengthen the security and efficiency our customers depend on, and that trust is sustained by the people who bring our mission to life every day.

We invite you to read Commvault’s FY26 Sustainability Report as both a record of our progress and a look forward to the priorities that will shape our next chapter.

 

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

A few years ago, digital sovereignty was largely viewed as a compliance conversation. If you stored data in the right geography, met the right regulatory requirements, and satisfied a handful of audit questions, you could generally move on.

That’s no longer the case.

Today, sovereignty has become a board-level discussion. Governments are rewriting policies. Regulators are increasing scrutiny. And business leaders are starting to recognize that sovereignty isn’t just about where data resides – it’s about how organizations continue operating when geopolitical, legal, or operational assumptions suddenly change.

In the first episode of our STRIVE series on digital sovereignty, I sat down with Max Mortillaro, co-founder and Chief Research Officer at Osmium Data Group. Together, we unpack what sovereignty actually means, why the conversation has accelerated so quickly, and where organizations are most likely to get it wrong.

Watch the episódio completo.

Pontos principais

  • Digital sovereignty is no longer just a compliance issue – it has become a resilience and business continuity concern.
  • Data location is only one piece of the puzzle. Jurisdiction, operations, technology dependencies, and governance all matter.
  • Many organizations focus on technical controls before understanding the business problem they’re trying to solve.
  • Geopolitical uncertainty is accelerating sovereignty initiatives, particularly across Europe.
  • There is no such thing as a perfectly sovereign environment. Every organization must make informed trade-offs between risk, cost, and operational requirements.

Why Data Location Isn’t the Whole Story

One of the most common misconceptions around digital sovereignty is that it begins and ends with geography. If data is stored in a local data center, the thinking goes, the sovereignty problem has been solved.

It’s an understandable assumption. After all, many of the early conversations around sovereignty focused heavily on data residency requirements and where information could legally be stored.

But as Max points out during our discussion, that’s only one dimension of a much larger challenge. Sovereignty isn’t simply about where a data center sits. It’s also about who operates it, which laws apply to it, who has access to it, and what dependencies exist behind the scenes.

A cloud service may be physically located within a specific country, but that doesn’t necessarily mean it’s insulated from legal, operational, or technological influence originating elsewhere.

That’s where the conversation becomes significantly more complex.

The Hidden Dependencies Most Organizations Overlook

When organizations first begin exploring sovereignty, they often approach it as a technology project. They evaluate hosting locations. They assess replication strategies. They examine where workloads should run.

Those conversations are important, but they can also create a false sense of confidence.

As Max explains, modern technology environments are built on layers of dependencies that aren’t always visible. A service may appear local on the surface but it may be relying on infrastructure, management systems, telemetry services, or operational controls that exist elsewhere.

That’s why sovereignty isn’t simply a question of location. It’s a question of influence.

Who ultimately controls the service? Which legal jurisdiction applies when disputes arise? What happens if geopolitical tensions introduce new restrictions, regulations, or limitations on access?

These aren’t hypothetical questions anymore. They’re becoming part of real-world risk assessments.

Sneak Peek: Sovereignty Is More Than a Technical Problem

In this segment from the conversation, Max explains why organizations often start sovereignty discussions in the wrong place – and why understanding the legal, operational, and business objectives must come before any technology decisions.

Why Europe Is Driving the Conversation

One of the most interesting parts of our discussion focuses on why sovereignty has become such a dominant topic across Europe.

The answer isn’t just regulation; it’s dependency.

European organizations have become increasingly aware that many of the technologies they rely on every day are owned, operated, or governed outside of their direct control. For years, that reality was largely accepted as part of the global technology ecosystem.

Today, that assumption is being reevaluated.

Geopolitical tensions, evolving regulations, and increasing concern around strategic autonomy have pushed sovereignty higher on the priority list for governments and enterprises alike. What was once considered an edge case has become a mainstream business concern.

The result is a growing recognition that resilience isn’t only about recovering from technical failures. It’s also about understanding and managing external dependencies before they become business disruptions.

Sovereignty and Resilience Are the Same Conversation

One of the themes that you’ll see repeatedly surfacing throughout the discussion is how closely sovereignty and resilience are connected.

At first glance, they may seem like separate disciplines. One focuses on governance, regulation, and control. The other focuses on recovery, continuity, and operational readiness.

In practice, they’re deeply intertwined.

If a business cannot access critical systems because of a geopolitical event, regulatory restriction, or third-party dependency, the outcome isn’t very different from other disruptions organizations spend years preparing for.

The business still needs to operate. Customers still need to be served. Recovery still needs to happen.

That’s why I increasingly view sovereignty through the same lens as cyber resilience. Both are fundamentally about reducing exposure to events that could disrupt operations and preparing the organization to continue functioning when those events occur.

Start With the Business Problem

Perhaps the most practical advice Max shares is also the simplest.

Before evaluating sovereign cloud offerings, before engaging vendors, and before debating technical architectures, organizations should first understand what problem they’re trying to solve.

That means understanding:

  • Which business processes are most critical.
  • Which data assets matter most.
  • Which regulatory requirements apply.
  • Which risks are truly being mitigated.

Only after those questions are answered does it make sense to evaluate technology options.

Too often, organizations start with solutions and work backward toward the problem. Sovereignty requires the opposite approach. The strategy should come first.

The architecture follows.

Why There Is No Perfect Answer

One of the realities leaders need to accept is that there is no such thing as a perfectly sovereign environment.

Every organization operates within a network of dependencies. Every technology choice introduces trade-offs. Every risk decision involves balancing operational requirements, compliance obligations, cost considerations, and business outcomes.

The goal isn’t perfection. The goal is understanding those trade-offs well enough to make informed decisions.

Organizations that approach sovereignty as a binary yes-or-no question often find themselves frustrated. Organizations that approach it as a risk-management exercise tend to make better progress.

Por que essa conversa é importante

Digital sovereignty is moving quickly from a niche compliance topic to a strategic business issue.

Boards are asking questions. Regulators are increasing scrutiny. Customers are becoming more aware of where their data lives and who controls it.

At the same time, geopolitical uncertainty continues to reshape how organizations think about risk.

That doesn’t mean every company needs a radical sovereignty transformation tomorrow.

But it does mean that the organizations that start building a clear strategy today will be in a much stronger position than those who wait until the conversation becomes unavoidable.

Sovereignty isn’t a technology decision masquerading as a business problem. It’s a business problem that requires legal, operational, and technical decisions working together.

Assista ao episódio completo

In this installment, Max and I explore:

  • What digital sovereignty actually means.
  • Why data location alone isn’t enough.
  • The legal and operational dimensions organizations often overlook.
  • How geopolitical developments are influencing sovereignty strategies.
  • Why sovereignty and resilience are becoming inseparable.

Assista agora

Perguntas frequentes

Q: What is digital sovereignty? 

A: Digital sovereignty refers to an organization’s ability to maintain control over its data, technology, operations, and governance within specific legal and jurisdictional boundaries.

Q: Is digital sovereignty the same as data residency? 

A: No. Data residency is one component of sovereignty, but sovereignty also includes legal jurisdiction, operational control, technology dependencies, and governance.

Q: Why has digital sovereignty become more important recently? 

A: Growing geopolitical uncertainty, evolving regulations, and increasing concern about technology dependencies have accelerated interest in sovereignty initiatives.

Q: What is the biggest mistake organizations make? 

A: Treating sovereignty as a purely technical challenge instead of a broader business risk and resilience issue.

Q: How does sovereignty relate to cyber resilience? 

A: Both disciplines focus on maintaining operational continuity in the face of disruptions, whether those disruptions are technical, legal, geopolitical, or regulatory.

Q: Where should organizations begin? 

A: Start by understanding the business outcomes you’re trying to protect, the risks you’re trying to mitigate, and the data and processes that are most critical to your operations.

Alex Zinin is VP/GM of Managed Service Providers at Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Pontos principais

  • The role of the backup administrator is evolving from managing infrastructure to delivering business resilience and recovery confidence.
  • Modern ResOps (resilience operations) focus on recovery readiness, continuous validation, governance, and business outcomes – not just successful backup jobs.
  • Autonomous Resilience is Commvault’s vision for the next evolution of ResOps, wSaiba mais no SHIFT 2025 AI helps resilience teams reduce operational overhead through intent-driven, governed workflows while maintaining human oversight, approvals, and auditability.
  • By helping reduce repetitive operational work, AI enables resilience teams to spend more time improving cyber recovery, governance, and recovery readiness.
  • The future of resilience will be measured by confidence in recovery – not simply the successful completion of protection activities.

The Operational Shift at 8 a.m.

For an enterprise backup administrator, the morning routine has long followed a predictable, high-stress pattern. You log in at 8 a.m. to face a wall of dashboards. TSaiba mais no SHIFT 2025 are thousands of completed protection activities, but your eyes naturally scan for the exceptions – a handful of failed workloads, replication delays, and capacity alerts warning that critical storage resources are nearing their thresholds.As you begin sorting through the day’s priorities, the reality of modern infrastructure closes in. A virtualization administrator submits a request: Dozens of new workloads were provisioned overnight, and leadership needs to know whether they are automatically covered by existing protection policies.Moments later, the compliance team requests a detailed history of protection success and retention validation to prepare for an upcoming audit. Then, the security operations center (SOC) calls. An anomaly has been detected on a critical system, and they need confirmation that recovery copies remain isolated, immutable, and uncompromised.Before you can finish your first cup of coffee, leadership asks a simple but devastating question: “If we were hit by ransomware right now, how consistently and confidently could we recover?”

Ten years ago, a successful backup administrator was an infrastructure gatekeeper. Success was binary and infrastructure-centric: Did the jobs finish within the required time window? Was the data successfully protected? If the dashboard was green, the job was done.Today, that paradigm is entirely broken. The modern enterprise does not care whether data protection jobs completed successfully. It cares whether the business can survive a catastrophic disruption.Success is no longer measured by the completion of a background data protection process. It is measured by an organization’s ability to withstand ransomware, infrastructure failures, cloud outages, insider threats, and compliance events without losing data or operational momentum.The role has fundamentally evolved from infrastructure management to enterprise resilience. Yet many organizations still force administrators to spend their days managing operational tasks instead of architecting recovery confidence.Commvault is working to redesign the administrator experience to help break this cycle, enabling a shift from reactive backup management toward comprehensive ResOps.

The Drag of the Modern Administrator’s Daily Reality

To understand why this shift is necessary, one must first recognize the enormous operational burden carried by administrators every day. Consider the volume of tactical work required to maintain a modern enterprise protection environment:

  • Job and infrastructure monitoring: Reviewing overnight activities, distinguishing transient issues from legitimate failures, and validating infrastructure health across a rapidly changing hybrid environment.
  • Troubleshooting and issue resolution: Spending hours reviewing diagnostic information and operational telemetry to determine why processes stalled, services became unavailable, or critical workloads failed unexpectedly.
  • Resource optimization and performance management: Continuously identifying storage constraints, network bottlenecks, or infrastructure limitations that impact protection and recovery objectives, then manually expanding capacity as requirements grow.
  • Workload discovery and lifecycle management: Automatically discovering, classifying, and assigning appropriate protection policies to newly deployed applications, cloud services, databases, and infrastructure resources.
  • Capacity and storage management: Monitoring consumption trends, forecasting growth, and responding to unexpected increases before they threaten recovery objectives.
  • Audit and compliance support: Collecting reports, validation records, and historical evidence across multiple systems to demonstrate compliance with retention and governance requirements.

Every hour spent troubleshooting an operational issue or assembling compliance evidence is an hour taken away from strategic resilience planning. This is wSaiba mais no SHIFT 2025 resilience teams lose time. The challenge is the operational overhead required to keep protection systems synchronized with a constantly evolving hybrid cloud environment.

The Structural Shift: From Backup Operations to ResOps

As organizational risk profiles increasingly center around cyber resilience and business continuity, the very mindset of data protection must evolve.

Old Mindset: Backup Operations

“I need my protection jobs to finish successfully.” 

New Mindset: ResOps

“I need confidence that we can recover immediately.” 

This evolution fundamentally changes the questions administrators must answer.

Backup Operations  ResOps
Did the workload complete protection last night? Are our critical applications verified as recoverable?
How much storage capacity remains? What is our verified recovery readiness posture?
Are recovery copies synchronized? Are our recovery environments protected and isolated?
Can we restore a single file? Can we recover an entire business service during a cyber event?

In this new model, recovery – not backup – becomes the primary operational metric. 

An organization can achieve near-perfect protection success rates while remaining dangerously unprepared for a ransomware attack due to compromised credentials, hidden dependencies, configuration drift, or unverified recovery processes.ResOps assumes disruption is inevitable. The focus shifts toward continuous validation, proactive risk identification, threat awareness, and deterministic recovery orchestration.At Commvault, we see this evolution leading toward Autonomous Resilience, wSaiba mais no SHIFT 2025 AI helps resilience teams move from manual operations toward intent-driven, governed outcomes.

How Commvault is Redesigning the Experience Around Outcomes

Commvault is addressing these realities by working to redesign the administrator experience. Rather than requiring users to organize their work around infrastructure configurations, protection policies, storage resources, and system assignments, Commvault is shifting the experience toward outcomes that matter to the business.

  • Unified management and risk-driven visibility: Rather than navigating multiple interfaces to manage different environments, administrators gain visibility into their entire estate through a unified resilience experience.The focus extends beyond operational status. The platform highlights risk exposure, protection gaps, emerging threats, unprotected workloads, and configuration drift that could impact recovery readiness.
  • Policy simplification and intelligent automation: Traditional environments often require administrators to manage hundreds of static schedules and policies. Commvault is designed to replace this complexity with intent-based protection plans.

    Administrators define business outcomes, while the platform can automatically orchestrate the infrastructure, optimize workflows, and manage protection activities behind the scenes.

  • Continuous validation and clean recovery environments: True resilience requires confidence not only in protected data but also in the ability to restore it safely.

    Commvault can integrate automated recovery validation directly into operations. This includes the ability to orchestrate isolated recovery environments wSaiba mais no SHIFT 2025 systems can be restored, validated, and inspected before production restoration occurs.

  • Threat-aware operations and intelligent detection: Modern resilience requires more than monitoring activity counts. By applying advanced analytics and machine learning to operational telemetry, the platform establishes historical baselines and detects abnormal behavior.

    When suspicious activity occurs, administrators receive contextual explanations, probable causes, impact assessments, and recommended actions – not just generic alerts.

A Day in the Life: The Outcome-Driven Workflow

To understand the potential impact of this transformation, consider an illustrative day for an administrator within an outcome-focused resilience platform. The scenario below shows how these capabilities are intended to work together.

8 a.m. – Establishing Recovery Readiness

Instead of searching through thousands of activities and alerts, you open a resilience dashboard displaying a comprehensive Recovery Readiness Score across the environment. The platform highlights a scaling concern. Recently deployed workloads have increased demand beyond recommended operational limits.Rather than manually expanding infrastructure and coordinating resources, the platform automatically recommends a corrective action: “Additional infrastructure capacity is recommended to maintain recovery objectives. Approve?” 

A single approval initiates the adjustment.

11:30 a.m. – Automated Audit Resolution

The compliance team requests evidence of protection activity and policy compliance for a previous reporting period. Rather than manually compiling reports and spreadsheets, the administrator generates a compliance package containing validation records, policy compliance evidence, and supporting documentation within minutes.Time is spent improving resilience – not producing paperwork.

2 p.m. – Threat Detection and Autonomous Response

A critical anomaly is detected. A workload exhibits behavior that significantly deviates from normal historical patterns.Instead of issuing a generic warning, the platform automatically correlates the event with known behaviors, evaluates potential causes, assesses business impact, and identifies clean recovery points.If a cyberattack is suspected, the platform highlights affected recovery data, isolates impacted assets, validates clean recovery options, and prepares recommended recovery actions.The administrator is no longer investigating what happened. The platform is helping determine what to do next.

The Power of Intent: Why Embedded Intelligence Changes Everything

The engine powering this transformation is the move from manual task execution to autonomous, intent-driven operations.Commvault’s conversational and AI-driven capabilities are designed to support the operational model that this transformation requires:

  1. An administrator expresses intent.
  2. The platform gathers context.
  3. Recommendations are generated.
  4. Actions are executed with appropriate oversight.
  5. Outcomes are validated.
  6. Activities are documented automatically for governance and audit purposes.

This fundamentally changes the relationship between administrators and the underlying technology. The goal is no longer to manage systems. The goal is to direct outcomes.

From Diagnostics to Actionable Root Cause

When infrastructure issues occur, administrators traditionally have spent hours reviewing diagnostic information, searching for symptoms, and piecing together dependencies. Embedded intelligence continuously monitors infrastructure health, operational telemetry, and service activity patterns. When an issue arises, diagnostic information can be analyzed automatically, probable causes identified, and remediation recommendations generated without requiring manual investigation.

Multi-Workload Dependency Correlation

Modern environments are interconnected ecosystems. A single infrastructure issue can generate hundreds of downstream failures. Rather than forcing administrators to investigate each event individually, the platform automatically correlates failures and identifies shared infrastructure dependencies, common services, or connectivity issues contributing to broader disruption.

Proactive Resource Forecasting

Instead of waiting for operational failures, the platform continuously analyzes historical workload patterns, growth trends, and infrastructure utilization. Expected changes are separated from abnormal behavior, allowing resilience teams to proactively address capacity and performance concerns before they impact recovery readiness.

The Rise of the Resilience Engineer

The data protection industry is undergoing a profound transformation. The title of backup administrator is rapidly becoming an artifact of a previous era – one in which data protection was viewed primarily as an operational task supported by infrastructure checklists.Tomorrow’s successful professional is a resilience engineer. They collaborate with security teams to design cyber recovery strategies. They work alongside compliance leaders to automate governance requirements. They provide executives with measurable confidence in the organization’s ability to recover from disruption. Their value is no longer defined by how effectively they manage operational complexity, but by how effectively they reduce business risk and accelerate recovery.Commvault is not simply enhancing an existing backup platform. It is helping build the operational framework for the next generation of resilience leadership. By helping reduce administrative overhead, simplify operations, and align the experience around recovery readiness and continuous validation, Commvault is enabling administrators to focus on what matters most: helping the business remain resilient. 

The future of enterprise availability is no longer about managing backups. It is about delivering autonomous resilience. 

Continue the Conversation

The conversation around Autonomous Resilience is just beginning. At SHIFT 2026 in Nashville this November, we’ll explore how AI is reshaping ResOps and what it means for the next generation of resilience engineers. Register Saiba mais no SHIFT 2025.

Perguntas frequentes

Q: Why is the role of the backup administrator changing?

A: Enterprise resilience is no longer measured by successful backup jobs alone. Organizations increasingly judge resilience by their ability to recover confidently from ransomware, cloud outages, infrastructure failures, and other disruptions. As a result, backup administrators are taking on a broader role that spans cyber resilience, governance, recovery readiness, and business continuity.

Q: What is ResOps (resilience operations)?

A: ResOps reflects the shift from managing backup infrastructure to managing recovery readiness. It brings together data protection, cyber recovery, governance, continuous validation, and operational visibility into a single discipline focused on helping organizations recover with confidence.

Q: What is Autonomous Resilience?

A: Autonomous Resilience is Commvault’s vision for the next evolution of ResOps. It applies AI to help resilience teams reduce operational overhead through intent-driven, governed workflows that gather context, recommend actions, execute approved tasks, validate outcomes, and maintain auditability throughout the recovery process.

Q: How will AI change the day-to-day work of resilience teams?

A: AI can help reduce repetitive operational work such as reviewing backup activity, investigating failed workloads, collecting compliance evidence, assessing recovery readiness, identifying clean recovery points, and recommending recovery actions – all while operating within established governance controls. This allows administrators to spend more time improving resilience strategy and less time performing routine operational tasks.

Q: Does Autonomous Resilience replace backup administrators?

A: No. Autonomous Resilience is designed to augment resilience professionals, not replace them. Administrators remain responsible for oversight, approvals, governance, and decision-making while AI helps reduce operational overhead and supports day-to-day resilience operations.

Q: Why is this important now?

A: Hybrid infrastructure, cyber threats, AI adoption, and increasing operational complexity are changing what organizations expect from backup and recovery teams. The role is evolving from managing infrastructure to delivering resilience, making recovery readiness, governance, and operational confidence more important than ever.

Rajiv Kottomtharayilé diretor de produtos da Commvault.

More related posts


Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio
person-escalator-crocus-888×500

Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery

Read more about Your Modern Playbook for Identity Resilience: Rapid Response and Clean Recovery
Thumbnail_Blog-Architect-for-tomorrow-2026

Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience

Read more about Architect for Tomorrow: Unified Data Protection as the Foundation for Resilience