CommVault - Experts & Thought Leaders
Latest CommVault news & announcements
Commvault, a pioneer in unified resilience at enterprise scale, announces advancements to Cloud Rewind, expanding Microsoft Azure resource coverage for configuration protection and recovery. Through this expansion, Commvault is helping organizations more rapidly restore cloud applications and the resources that support them. Manually rebuilding environments is often slow, complex, and error-prone. According to Absolute Security's 2026 State of Enterprise Cyber Resilience report, 57% of enterprises said recovery from a cyberattack took more than 4.5 days on average. Discovering cloud resources Cloud Rewind addresses this by continuously discovering cloud resources, mapping application dependencies, and orchestrating the recovery and rebuild of cloud applications, including the infrastructure, configurations, and dependencies they need to operate, from a single platform. This expansion broadens Azure protection by 3X – now covering 62% of enterprise-relevant Azure resource types available in the market. Organizations can also validate recovery readiness through application recovery simulations, including within isolated, air-gapped environments, before an incident occurs. “In global logistics, every minute of downtime can disrupt supply chains and impact customer trust. Data is critical, but it needs the right cloud infrastructure to stay actionable,” said Venkata Sudhakar Nagandla, SVP & Global Head-IT Infrastructure & Cloud, Allcargo Group Companies. “With Cloud Rewind, we don’t just recover files — we restore our operational environment in hours, ensuring our customers experience continuity without compromise.” Multiple cloud environments Additional enhancements include: Deeper integration into Commvault backup and recovery: Protection Groups unite application data and cloud configuration into a single, air-gapped recovery experience, so teams can plan and execute recovery from one place instead of stitching together separate tools. More advanced policies for dynamic at-scale protection: Policy-based protection automatically enrols discovered resources by tag, region, and type across multiple cloud environments, using a single workflow, so teams can protect resources at cloud scale instead of onboarding them one at a time. Protected cloud resources “Modern applications depend on interconnected cloud services, infrastructure, and configurations that must be recovered together,” said Pranay Ahlawat, Chief Technology and AI Officer, Commvault. “Cloud Rewind helps organizations recover cloud applications through a unified experience in Commvault Cloud, increasing customers’ confidence in their ability to recover following a cyberattack or outage.” “Many organizations discover their recovery plan is incomplete only after an incident has occurred,” said Melinda Marks, Senior Research Director and Chief Analyst, Omdia. “As applications and their associated cloud resources become more complex, organizations need an effective way to rapidly recover, with restoration capabilities across configurations, dependencies, and multiple cloud platforms.” Cloud Rewind, available today, is delivered as an add-on workload within Commvault Cloud for cloud application protection and app-centric recovery. Expanded Azure protection is targeted for availability in the coming months. Pricing is metered based on protected cloud resources.
Commvault, a pioneer in unified resilience at enterprise scale, announced a new integration with Google Threat Intelligence, Google’s comprehensive threat intelligence platform, that incorporates Google Threat Intelligence data and scanning capabilities into Commvault Threat Scan workflows. Through this collaboration, Commvault can help customers transform global threat intelligence into actionable recovery insights, enabling organizations to identify clean recovery points faster and accelerate recovery following cyberattacks. Recovering data challenge When cyberattacks occur, organizations often face a critical challenge: determining which recovery points are safe to restore. While security teams may quickly identify indicators of compromise (IOCs), recovery teams still need to validate backup data before recovery can begin, delaying recovery efforts when every minute of downtime matters. Google Threat Intelligence Google Threat Intelligence combines Mandiant frontline intelligence, VirusTotal’s crowdsourced intelligence, and Google threat insights gained from protecting billions of users. Integrating Commvault Threat Scan workstreams with Google Threat Intelligence helps customers analyze protected workloads for malware, while also helping organizations identify threats and pinpoint which recovery points are compromised. Commvault Threat Scan customers will also receive actionable threat context from Google Threat Intelligence for threats found in their environment to help with further research and remediation. Introducing new scanning platforms As part of this release, Commvault is also introducing new scanning capabilities that collect file hashes inline during backup operations. File hashes, like individual fingerprints, provide a fast and easy way to quickly check recovery points against threat intelligence indicators so teams can identify clean files to be used for recovery. Commvault’s inline inspection capability allows customers to start with rapid threat intelligence validation and selectively perform deeper malware, encryption, and forensic analysis when additional inspection is required. This layered approach helps organizations accelerate recovery decisions while maintaining confidence in the integrity of restored data. These new threat insights and scanning capabilities strengthen Commvault’s Synthetic Recovery capability, which uses an AI-enabled process to automatically detect threats and surgically remove them during recovery while keeping the “good” data intact. Customers can then make the most complete recovery possible. Authority comments “Businesses need confidence that the data they’re restoring is clean,” said Pranay Ahlawat, Chief Technology and AI Officer at Commvault. “By combining Threat Scan and inline scanning with Google Threat Intelligence, we’re helping customers validate recovery points faster and accelerate clean recovery when it matters most.” “Organizations are looking for ways to strengthen cyber resilience while reducing complexity during incident response and recovery,” said Miton Adhikari, Head of Google Security OEM Partnerships. “Through our collaboration with Commvault, customers will be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed recovery decisions and reduce recovery uncertainty.” This announcement builds upon Commvault’s ongoing collaboration with Google Cloud, including expanded cyber resilience capabilities for Google Cloud environments via Clumio, and support for Google Cloud workloads. Availability The Google Threat Intelligence integration, inline scanning capabilities, and associated Threat Scan enhancements are expected to be available in the coming months.
Commvault, a pioneer in unified resilience at enterprise scale, announces “Commvault Minutes to Recovery” – a scenario-driven cyber resilience simulation that lets participants act as a hacker and run their own attacks using Frontier AI tools. Then, participants are challenged to defend against and recover from an incident under pressure to test their resilience against these AI-driven cyberattacks. The window between vulnerability discovery and active exploitation, once measured in days, has narrowed to 29 minutes in 2025, 65% faster than the year before. As attacks become significantly quicker, organizations need more than recovery plans – they need proven recovery readiness. Real-world conditions Commvault Minutes to Recovery is a hands-on, live simulation that allows security and IT teams to stress test their readiness for Frontier AI threats under real-world conditions. In the first of three chapters, the participants take the role of an attacker and create an AI-driven attack using the common Frontier AI tools deployed by adversaries today. This will give attendees realistic insights into how AI-accelerated attacks behave, how fast they move, how personalized the phishing is, and how quickly backup infrastructure gets targeted. The attendees then flip their roles and need to defend the AI-driven attack by making real-time detection decisions under pressure, with incomplete information and competing priorities. Finally, they take over the role of the recovery expert who will have to bring back the systems and data in a verified clean state without bringing the threat back with it. Cross-functional coordination Moving through these three roles, attendees will develop a firsthand understanding of what each phase demands and where cross-team coordination breaks down under real pressure. This experience will help teams uncover critical technical and operational weaknesses in recovery plans, strengthen cross-functional coordination, and build confidence in their ability to respond effectively when an incident occurs. Available globally as an onsite event and delivered in six languages, Minutes to Recovery is completed in a single two-hour session. The resulting Mean Time to Clean Recovery (MTCR) benchmark provides a practical measure of recovery readiness based on performance under pressure rather than assumptions in a planning document. Partner engagement opportunity “The question organizations need to answer is no longer, ‘Do we have a recovery plan?’ Instead, they should be asking, ‘Can we prove it will work under pressure?’” said Anna Griffin, Chief Market Officer at Commvault. “As AI compresses the time between compromise and impact, resilience becomes a measurable business capability. Minutes to Recovery helps organizations move beyond assumptions and demonstrate their ability to recover cleanly, quickly and with confidence.” Minutes to Recovery will also be available through Commvault’s global partner network, enabling partners to host and engage customers in strategic resilience discussions through a hands-on, outcome-driven experience. For partners, the event provides a turnkey, high-engagement customer experience backed by Commvault’s facilitation infrastructure and the credentialed expertise of the Commvault Global Speaker Bureau. High-engagement customer experience “Most organizations believe they are prepared for a cyberattack until they are forced to respond to one in real time,” said Allen Downs, Vice President of Security and Resiliency, Kyndryl. "As cyberattacks become faster, more sophisticated, and increasingly unpredictable, recovery strategies must evolve to meet this new reality. By leveraging this experience, Kyndryl can help customers strengthen their readiness, validate their resilience, and improve their ability to recover from disruption. Ultimately, resilience is not defined by the plans organizations create, but by the scenarios they have rigorously tested.”
Insights & Opinions from thought leaders at CommVault
Every day, millions of people worldwide use their personal credentials to prove their identity and access a range of services, from databases in their workplace to the banking app on their smartphone. But while this ensures only authorized people have access to certain systems, the use of this personal data opens users up to cyber risks, primarily in the form of identity theft. On Identity Management Day, Source Security spoke to seven IT and cybersecurity experts to discuss their experiences and advice on identity management, including James Brodhurst, Principal Consultant at Resistant AI, who reinforces that: “Securing identities is more important than ever, as fraud and identity theft has impacts for businesses as much as for individuals.” Effective identity management He recommends that businesses and other organizations that use consumer identities as an integral part of operations must address the significant challenges of managing identities and recognize that there is no single solution to all possible cyber threats. Effective identity management is only achieved through a broad range of technologies and data. Businesses have a critical role to play in mitigating cyber threats, as does society as a whole" This is an important first step for organizations to know who they are interacting with, and subsequently distinguish between genuine or illicit actions. “Businesses have a critical role to play in mitigating cyber threats, as does society as a whole. Initiatives such as Identity Management Day serve to increase our collective awareness of the issues and threats we’re facing, and also safeguard sensitive data.” External cyber defenses “Why is identity theft so common?” ponders Andy Swift, Technical Director of Offensive Security at Six Degrees. “Well, the simple answer is stealing account credentials is big business. There is a massive industry out there of people stealing and selling credentials on the dark web. I don't suggest you venture to the marketplaces through which stolen credentials are sold on the dark web, but if you did you'd find lists of credentials with different attributes – whether they've been tested, whether they have access to financial data – that dictate price.” “Most stolen credentials are sold to people looking to launch phishing and onward phishing attacks, giving them access to compromised mailboxes to send emails from. Secondly, there are hackers who want to launch attacks – ransomware, more than likely – from within a network without having to navigate its external cyber defenses while also evading the long wait for brute force attacks, phishing attacks and other noisy activities to pay off.” Access sensitive data Credential stuffing is one of the most common forms of attack and corporate credentials are usually the target" “And thirdly, there are people who want to simply target external administration interfaces they have identified (RDP for example) which they can in turn use to pivot through to internal networks, or even just target the external host directly.” Gregg Mearing, Chief Technology Officer at Node4, adds: “Credential stuffing is one of the most common forms of attack and corporate credentials are usually the target. In 2020 alone there were 193 billion credential stuffing attacks globally. Attacks commonly start with a database of stolen credentials, usually with usernames, emails and passwords – although phishing emails and suspicious websites are also used to steal corporate credentials. Once they have gained entry into the organization's system, the attacker can move laterally, completely unnoticed, to access sensitive data, remove files or plant malware.” Most common threats “Despite the ubiquity of this style of attack and a wide understanding of the importance of password hygiene, 65% of people still reuse passwords across multiple accounts. There can be no doubt that employees are the first line of defense for an organization against a cyber attack. If trained properly, they can act as a human firewall. However, poor cyber hygiene, a lack of best practice when it comes to managing credentials, and a limited understanding of the most common threats can make an organization’s employees its greatest weakness.” Despite the ubiquity of this style of attack and a wide understanding of the importance of password hygiene" Alongside credential stuffing and phishing, Liad Bokovsky, Senior Director of Solutions Engineering at Axway, explains how API attacks are yet another way criminals are executing identity theft: “In fact, last year API attacks increased 348%, and companies affected included some of the largest corporations – Facebook, Instagram, and Microsoft.” Protecting customers’ data “Companies need to do a better job at protecting their customers’ data. In a recent survey, 82% of UK consumers confirmed they would stop doing business with a company if it suffered a data breach that exposed their personal information.” “Thriving and surviving in today’s hyper-connected economy increasingly depends on having sufficient API maturity in place to ensure that anything connecting to an organization’s servers – devices, apps, customers – is managed appropriately to keep APIs, customer data and the company’s reputation safe. This means having technology and processes in place to make sure that API design, implementation, and management are done properly.” Owning smart devices This needs to change and with the UK no longer required to adhere to EU-GDPR legislation" Michael Queenan, CEO, and Co-Founder of Nephos Technologies, explains how the huge volumes of personal data being created every day are putting consumers at risk: “Whether shopping online, setting up a social media account or simply reading a news article, we are regularly being asked for our identifiable information. With 10% of UK homes now owning smart devices – e.g. an Alexa or a Ring doorbell – our data is constantly being collected, even within our own homes. Should it fall into the wrong hands, it could be used for identity theft or fraud.” “This needs to change and with the UK no longer required to adhere to EU-GDPR legislation, it presents an opportunity to rectify how personal data can be shared. Ultimately, I believe individuals should be responsible for their own data and how it is used.” Ensure data privacy “A possible way of achieving this is through identity-centric blockchain, whereby everyone has a national email address associated with their blockchain identity that permits access to their personal data. This would ensure that only you get to decide who has access – your data, your choice!” This would ensure that only you get to decide who has access – your data, your choice" Steve Young, UKI Sales Engineering Director at Commvault also comments on how identity management is vital for meeting data regulations, thereby supporting data management throughout the business: “In the world of data management, you’d be forgiven for thinking that the focus is all on backups and recovery. But while these are absolutely crucial elements, another key aspect of data management is identity management – only through understanding it will businesses be able to drive their data management to the next level. Identity management is necessary to ensure data privacy.” Latest data regulations “Many people will be most familiar with its function as a way to restrict access of employees to certain files and resources that may hold sensitive or classified information. But what is becoming more important today is how identity management also helps prevent cybercriminals entirely outside an organization from gaining unauthorized access to a system and initiating a ransomware attack, for example. Because of this, identity management helps businesses be compliant with the latest data regulations, as it ensures that any customer data collected and stored is kept secure.” So, what solutions should IT leaders be prioritizing to strengthen their identity management measures? Six Degrees’ Andy Swift recommends multi-factor authentication (MFA): “MFA provides great defense against identify theft, but it's also a reactive technology: for it to be effective, an attacker must already have obtained stolen credentials.” Cyber security training Credential-driven attacks are largely exacerbated by a ‘set it and forget it’ approach to identity management" “That's why comprehensive cyber security training and education on best practices is quite possibly more important than any technology could ever be alone. There's no silver bullet when it comes to achieving strong identity management, but the importance of threat awareness and training cannot be overstated.” “We advocate for the best practices that ensure cyber hygiene and protect personal and professional identities and credentials to prevent credential-based attacks from continuing,” concludes Tyler Farrar, CISO at Exabeam. “Credential-driven attacks are largely exacerbated by a ‘set it and forget it’ approach to identity management, but organizations must build a security stack that is consistently monitoring for potential compromise." "Organizations across industries can invest in data-driven behavioral analytics solutions to help detect malicious activity. These analytics tools can immediately flag when a legitimate user account is exhibiting anomalous behavior indicative of credential theft, providing greater insights to SOC analysts about both the compromised and the malicious user, which results in a faster response time.”