A New Era of Cyber Resilience with Commvault Cloud
Organizations need to operate continuously, especially with the shift to cloud-first strategies. Commvault Cloud aims to solve the challenges of this shift, particularly in security. Michael Fasulo introduced Commvault Cloud, a cyber resilience platform designed for cloud-first enterprises. This platform addresses challenges like ransomware, hybrid/multi-cloud complexity, and regulatory compliance. Commvault offers a unified platform that incorporates a zero-trust foundation, AI-driven data protection features, and various cloud-first capabilities, including threat detection, anomaly detection, and cyber resilience testing. The platform offers flexibility in deployment, supporting on-premises, SaaS, and appliance models to meet the diverse needs of customers.
Commvault’s platform emphasizes a proactive approach to cyber resilience. It utilizes a zero-trust architecture, featuring CIS-level hardened images, multi-factor authentication (MFA), and least privilege access. A key aspect is the Commvault Risk Analysis product, which provides in-depth data discovery, classification, and remediation capabilities, including integration with Microsoft Purview. The platform also focuses on operational recovery through end-to-end portability, enabling workload transformation. To further enhance security, Commvault offers ThreatWise, which deploys deception technology to lure and analyze threats. This is complemented by integrations with various SIM and SOAR platforms for centralized threat response.
To educate customers, Commvault has launched “Minutes of the Meltdown” for executives and “Recovery Range” for hands-on keyboard experience during simulated cyber attacks. Recovery Range allows teams to test their response to various threats and validate the effectiveness of the Commvault Cloud platform. This includes features like anomaly detection and automated exclusion of threats during recovery. The platform also offers the option for custom dashboards and extensive reporting capabilities, allowing customers to tailor the view of their security posture to their specific needs.
Presented by Michael Fasulo – Senior Director Portfolio Marketing, Commvault. Recorded live in Millbrae, California, on June 4, 2025, as part of Cloud Field Day 23. Watch the entire presentation at https://techfieldday.com/appearance/commvault-presents-at-cloud-field-day-23/ or https://techfieldday.com/event/cfd23/ for more information.
Transcript
My name's Tim Zha. I'm with Commvault. I'm our Vice President of Portfolio Marketing, and Commvault is a cyber resilience company.
We're focused on serving the cloud first enterprises, uh, in particular helping them fight through outages and and attacks. And you're gonna see a lot of our technology over the course of the next couple hours to introduce a few people. You're gonna hear from, um, those that will aren't necessarily presenting but may chime in as they're, uh, either online or surely In the closed door session, we have Sammy Keating.
She's online, she's our analyst and influencer, uh, director. We have Matt Barman the room. He is our senior Director of analysts and influencer relations.
Uh, Thomas Bryant runs technical marketing for us here at Commvault, and, uh, he'll probably be chiming in as well. And then Michael, uh, thanks for popping up the agenda slide. Michael Falo, you'll hear from, first, he's gonna cover Commvault Cloud and how it helps organizations solve their resilience challenges, uh, you know, across their cloud estates.
Then we're gonna hear from Je Joshi. He's here in the room with us. He's going to be presenting on especially how organizations can make their massive data sets, uh, highly resilient.
And then we'll wrap it up with Govin Ranga, and he'll be going through Cloud Rewind and how, uh, that helps companies, uh, help keep their, uh, data resilient regardless to the clouds that it lives in. So we're happy to be here over the course of the next couple hours. Thanks for having us.
And Michael, I'm gonna pass it over to you. You know, challenges, um, I sure I don't need to explain this to many folks, but you know, first and foremost, ransomware is everywhere, and it costs organizations tons of money. Secondly, you know, hybrid and multi-cloud complexity further complicate how we take organizations, uh, data and keep it safe and recoverable.
Um, resilience related, compliance mandates and regulatory continually change, making it really hard and stressful, uh, to keep up with all the latest things that are coming out of the EU and the US governments. And I would say the, and the accelerated pace of, you know, cloud native development, along with the massive data sets that we're seeing from, uh, AI workloads is certainly a challenge in protecting organizational critical data. Um, so these, these are really daunting tasks that, you know, everyone's having to, you know, anticipate as things continue to move along.
And unfortunately, the current approaches to resiliency only adds more complexity and cost. And in order to achieve the kind of resilience that organizations need, you know, we built a unified platform so organizations can avoid having to string together, you know, loosely coupled, uh, products, cyber resiliency tools, and even data protection tools. So, you know, if I'm a AWS customer or an Azure customer, you know, having to figure out how to get all of the right discovery, dependency, mapping, storage, uh, backup and security tools altogether, you know, that could certainly be a Dalton task.
And if you add, you know, uh, another region to this, to the landscape, adding another cloud or even private cloud, you know, complexity and cost continue to mount. So, again, we are the only ones that I know of that really provide these unified, uh, resilience across all your data, all your clouds, and all the time. And what that ends up delivering is speed scale and the simplicity to a cloud first approach, uh, for resiliency.
So what does that actually look like in in CommonWell cloud? Uh, this is a relatively good snapshot of, you know, everything that we do from a, uh, software standpoint, and we'll talk about some of the other things that kind of hang off the side. But at the end of the day, like this is a pretty simplified view of, of what we're delivering.
And I'll start from the bottom and work my way up. So it all starts with a zero trust, secure by design, you know, foundation. And that's where we deliver, uh, scalable comprehensive data protection foundation across, uh, cloud native, uh, SaaS, hybrid and Edge.
And on top of that, you can see we have this AI layer that we've trained on, you know, the deep expertise that we have in the data protection space. And this allows us to drive smart defaults, um, prioritization, uh, a cutting edge user experience. And that drives a lot of the simplicity that I had just mentioned, along with, you know, operating with natural language.
And these use cases sit on top of that. So these use cases are focused on direct detection, uh, isolated recovery environments, uh, leading AWS recovery and comprehensive application recovery, which we're gonna see in depth, uh, a little bit later when I hand this over to my colleagues. Now, on top of that, we have these platform services and we measure them against the highest standards, uh, globally.
Dora NIS, uh, soc. And I would also say that we have the trifecta that, you know, in our back pocket with, you know, Phipps one 40 dash three, uh, FedRAMP high and even state gov. So, you know, we have these certifications that we really hold our product and our platform to the highest standards.
And if that wasn't enough, we have several cloud first capabilities that further drive resiliency, and that would include data security scanning, remediation, threat hunting. We have a plethora of anomaly detection, um, cyber resilience testing. So all of these things really prepare our customers to be able to recover regardless of where their data may live, whether it's cloud on-prem, or even at the edge.
And we find that we needing customers where they are from an infrastructure standpoint, uh, isn't always enough. So we have a rich API set, we have bidirectional third party, uh, security integrations that allow us to kind of share these signals. Uh, and Tim was alluding to this, uh, as he was answering some of those questions earlier.
So, you know, having these integrations with platforms like Wiz, uh, Microsoft Sentinel, uh, Palo Exor and Splunk allow organizations to really take all this rich telemetry and respond to threats, uh, as they arise. So high level, uh, we laid out what the architecture and how the platform functions. I always like to provide just a little bit more context on how that actually unfolds so that we can apply to like, the real challenges that we have today.
And, you know, with the punch boxes that I did show, uh, I know we were concentrating today on cyber resiliency, but you know, we have a lot of stuff that's vector the banging, and we define vector the bang as it, you know, everything that happens, kind of a boil breach. Um, so we'll kind of talk about those first, and then we'll venture into, you know, the right of banging things that are happening, you know, as they're unfolding. So again, as I mentioned before, we start with that zero trust architecture, and that's really the, the heart of the CommonWell cloud platform.
And, you know, those capabilities start with ci IS level foreign images, uh, MFA multi personal authorization, uh, passwordless, uh, fi O2 with UB keys, you know, primo access management and RA. So you all the things you would really expect. Uh, when it comes to cloud specifically though, on top of those things, um, you know, when we talk about IM roles or permissions, you know, we really focus on least privilege.
So when you look at all the templates and things that we deliver as part of our recommendations, you know, we, we try to make it as frictionless as possible to provide those things. So everything very least privileged, if you're only doing backups, you know, everything is going to be very focused on just those things. So you can segment all the controls and operations that you would have.
And of course, if we're in the cloud, you know, having cloud-based kss like Azure alt, um, you know, for kms provides like flexibility and choice. So as customers are kind of, um, you know, going through their digital transformation, you know, that optionality and flexibility, flexibility is super, super important. So then we kind of get into like what's on the slide, the, the operational combined aspects.
So when we talk about minimizing the attack surfaces, you know, that requires discovery. Again, we're kind of talking about that earlier. And for us, like our Commvault risk analysis product allows us to do that deep understanding of structured and unstructured data discovery, uh, classification and remediation so that we can truly understand, you know, what sensitive data we have in the environment.
And, uh, risk analysis is one of those unique capabilities within our platform that actually allows us to function on my data in addition to backup data. So, uh, you could actually run risk analysis on your live footprint. Uh, it'll give you all the deep telemetry, and then obviously you drive some other actions from there.
And we haven't stopped there. You know, I look at risk analysis as a product that sure, we're bucking about it from the left bank, but we could also look at it from the right of back mode. We actually have to provide evidence.
So because it has that deep understanding of what was on the machine and the sensitivity level, if we ever needed to understand like what might have been ex infiltrated from an environment, uh, you know, we could use its rich telemetry and detailss to provide that information. So, so of these capabilities that we're gonna talk about today are kind of a full suite. And, you know, risk analysis, again, is another unique part of our portfolio where, you know, we have deep integrations with even Microsoft purview.
So if you're using purview for kind of your, your Microsoft estate and you know your multicloud, and you need to have, you know, deeper insights into, you know, what's going on in the other pieces of your estate, you know, those deep integrations allow us to kind of provide that full powerhouse of discovery and data understanding. Now, as Kim was mentioning, you know, operational recovery didn't go away, uh, because, you know, cyber threats have taken the limelight. Uh, this is still a pretty critical component that people need to, uh, consider.
So, you know, our deep breadth and depth of supportability for workloads, uh, and recovery from classical failures like infrastructure, uh, natural disasters, uh, you were talking about laptop before and, you know, there's still, you know, honest mistakes that people make. Um, you know, question here to recover From that. Michael.
Uh, yeah, one question. Uh, you're talking about this analyze, uh, that are happening post factum. So basically after you did, uh, the data collection and move this data away from the original infrastructure, you analyze it, uh, on the repository, or you analyze it at the infrastructure that is in production live, where, where is happening with the Convault solution?
It, it can happen in either location. Mm-hmm. So our, our data classification can absolutely happen on a live system.
So it doesn't require a backup to do it, or you could choose to backup that data first and then perform the analysis. Correct. Okay.
Thank you very much. You got it. Perfect.
So getting back to operational recovery, one of the other big things we do provide as part of our platform is what we call end-to-end portability. So, uh, we're able to transform workloads on the fly and, you know, from VMware to in Azure, or you can make it an EC2 instance. Uh, you could lift and ship databases from, you know, a physical SQL server into, uh, a PAs instance or RDS.
So we provide a lot of that flexibility on the fly just in case you're in one of those scenarios where maybe the intended destination was also compromised and you need to put it somewhere completely different. Uh, having that flexibility allows you to really pivot, uh, in the event that, you know, a situation may arise. But we eventually get to that, that bang as I was talking about before.
So really that, that breach, and that's where things kind of get uncomfortable and all the unknowns come up. So we talk about, you know, how do we deliver these deeper insights? And, and better yet, like how do we divert even threat actors from interfacing with like live assets?
So, uh, a portion of our portfolio, uh, combo threat wise allows us to deploy, uh, deception technology. So we could deploy like these fake cloud assets that allow threat actors to interface with them. And because, uh, these decoys exist and they can be interacted with, uh, weaker record all the information, if they're dropping like threat payloads on them, we can collect those threat payloads and threat wise allows us to take those payloads and detonate them into a sandbox.
So like a safe environment. And with that, with that information, you can now, you know, better approach with super high fidelity information on how to remediate and, you know, stop the breach from occurring or reoccurring and clean up back doors. So, you know, all of these things are kind of working in concert to provide you with just these additional layers as you walk through incident response, all these additional layers of, you know, how this happened, uh, what happened, and then eventually you know how to recover cleanly so that you know, this doesn't happen again, and you can get your business back up and running.
And, you know, as Tim mentioned before, you know, the ability for us to take these signals and use these integrations and open APIs to, uh, send them into centralized locations like any of these Simmons SOAR platforms that we integrate with, um, it allows everyone to kind of use that as a single layer of information to respond accordingly. So, MI Michael, um, the cyber detection service that you offer is at, uh, your infrastructure level or as at the customer's infrastructure level? I mean, I, I guess where in the stack are you doing this detection?
Yeah, so it's happening at both levels. Um, you know, our anomaly detection happens agentlessly. So, uh, if we're protecting your assets, um, even before you even run a backup, uh, we can detect if there's file anomalies and we'll go through that, uh, actual scenario, uh, during the demo.
Um, so there's several layers of, of anomalies. Uh, I think there's about a dozen or so. So some of them are like pre-up live on the file system.
Uh, some of them are backup related. Some of them are just monitoring how the machine is bonding, and if it's, if it's, if it has a CPU overload or there's an excessive amount of, uh, memory usage. Uh, those things kind of give us some indicators.
And the reason why that's important is because when we, when we marry those indicators, uh, together with other indicators in the environment, you can get a better picture on, you know, is this, is this, uh, a user that logged in at a weird hour just to go do something non maliciously? Or is there actually something bad happening into the environment? So, so that's anomalies.
There's honeypots, uh, there's the decoys that I was just talking about. So there's a lot of different layers that we have that provide us that higher fidelity clearer picture on, on what's happening in the environment and in the estate. And we use traditional machine learning to really make sure that we cut down on a lot of the false positives that, you know, a lot of these detection systems in the past were kind of played with.
So I know gen AI is usually the hottest topic, but you know, there's still very much, um, classical use cases where traditional machine learning is still deployed and very much the right tool to make sure that, you know, as we're using these technologies to understand and try to reduce the blast radius as much as we can, when we talk about the right side of bang, you know, all of this left side of bang uh, capabilities is super important to get early detection, faster response. And then, you know, we are doing that in concert with other tools in the environment, there should be less stuff that we have to do. I guess my question, uh, is, are you, are you plugged into cloud IO infrastructure to try to understand threat activity while normal batch or normal, uh, IO activity goes on?
Are you, uh, do we, are you required to have lumio, is your storage for Nope. Your applications? Or is it just, uh, an adjunct solution that, that, that you have available?
So you, uh, you're, you, you're not actually plugged into cloud IO APIs? Uh, for certain, in, for certain indicators we are, um, in, in certain cases we would be able to detect the, like let's just say you have an EC2 instance, you know, these anomalies that I'm talking about, which just naturally happen. Uh, and because we're looking at the telemetry of the EC2 instance and the compute cycles, and we understand, you know, how that looks in a normal sense as we're collecting information over a long period of time when those, there's those spikes in things, uh, we do detect that.
So you in other cases, in other cases, if you get in like cloud watch activities and other things, uh, you know, we could react to those types of scenarios too. So you're looking at telemetry, uh, to really ascertain, to try to ascertain what's going on using signatures or telemetry signatures to determine threat vectors and that sort of thing. Yep, that's correct.
I Got you. Awesome. So, um, so that, that kind of covers the canary files, the, the anomalies.
Uh, we also have threat scanning capabilities that allows us to, uh, look at the backup data, uh, and make sure that it's clean with malware. And we do entropy scoring and other things in there too. Uh, we have ya rules capabilities as an example too.
So, you know, again, there's this multifaceted multi-layer approach that we've taken, uh, that you could deploy to really get that really high fidelity understanding on, you know, is something really happening in the environment that that requires my attention or, you know, is, is someone just doing some work, uh, at an anomalous hour that's, you know, genuine and true. And then as I mentioned before, um, we, we don't only do this by ourselves with just our platform, right? We have these integrations, uh, darktrace, Sarah, uh, Netskope.
So again, you know, this wider view of just beyond backup needs to occur because the, again, the, the faster we we operate in this space, the less we should have to do on the recovery end. So reducing that blast radius down to, uh, you know, as minimal as possible to get a business backup and running to minimum viability is super, super important. So, and then of course we get, go ahead.
So on an earlier slide, you had, uh, continuous cyber recovery testing as a cloud first capability. Where does that play into this here? Yeah, so I'll get to that in just a second.
Um, okay. And after I cover that, if, uh, if it's not satisfactory, let me know and I'll dive deep into it and then we'll also see that part in the demo. Okay, cool.
Uh, so, so we're getting to my favorite part, right when that's really recovery and, and this is where like these things all work in concert together. So again, you know, I try to look at things in pairs of threes. You know, we talk about our air gap protect, we talk about auto recovery, and then we talk about clean recovery.
And that's where, you know, these three things combine where air gap protectors are immutable and indelible cloud storage offering. Uh, and, you know, we provide that as service to our customers so they don't have to think about it not sitting in their tenancy. And, you know, it provides a next level, uh, set of, uh, protection against compromise.
Uh, the auto recovery or the orchestration layer allows me to remove like click ops and, uh, human errors and allows to set policies that, you know, we can automate the recovery, um, so that we can provide really predictable results. And then, you know, clean room recovery really provides that cloud-based IRE. And really what that does is it provides us this safe location so we can consistently and constantly test recoveries without actually impacting production.
So this is, again, another service that we deliver completely in our tendency to allow people to, you know, stand up a isolated control plane, and then we can go through, you know, an IRE to provide, uh, recovery testing. And because this is all event driven, it happens at scale and at low cost. So we're not in a scenario where, you know, you're constantly paying these massive bills, we're doing things at low cost instead of all costs.
And for us, you know, next gen recovery can also occur today with capabilities like LUMIO and Cloud Rewind, which, you know, um, actually, and Govin will cover just a little bit later. Uh, sorry, I I have a question here. Uh, you have a plenty solution presented here to, uh, to, to conduct all the journey of the data you want to, you want to protect the backend of the solution recite in your cloud, or it's reciting on the on premises environment of the customer where it is.
Yeah. 'cause it, it's a lot of stuff there, you know, and Yeah. And who managing that?
Yep. So, uh, we give customers the freedom of choice. Um, you could deploy these solutions as on-prem software, very traditional.
Um, and you know, we've been in business for, you know, over two decades. So we have a large prop printer customers that are still using our on-prem deployment software, and they're managing infrastructure and tin and software. Uh, we have our SaaS offering.
So we offer these capabilities completely a SaaS. So that's our Convault cloud SaaS product, uh, what used to be called metallic. Uh, so you can consume it that way and you get the SaaS based experience.
So, um, if you're not interested in, you know, managing infrastructure and you know, what you're seeing here, 'cause again, you know, even when we look at the architecture, there's a lot there. Uh, and it's not that you need all of it. Um, you know, your situations may arise when you only need certain components of that.
Uh, but we do provide that as an option. And then, you know, if you do want the appliance form factor, we also, uh, provide this as an appliance. And then there's cloud-based images and other things that I was mentioning before that kind of ease the burden if you're somewhere in between.
Um, and then if you, you could start on-prem and you could go move to, you know, cloud-hosted, um, scenarios too. So we provide a lot of that optionality and flexibility, uh, to, to meet your needs of today and even tomorrow, you know, as your, as your environment goes through digital transformation. So, uh, lots of flexibility there.
Great question. Alright, so basically, uh, you can arrive to the model where you keep everything in your data center and there is no connection to the hybrid, any cloud or hybrid or any, let's keep, because some of the customers have this, uh, let's say, um, closed environment without internal access and they can use that, uh, software of yours with all the models presented here to, uh, get the same quality both on-prem as well on the cloud, right? So one way or another, that's, That's absolutely true.
That's absolutely true. And in fact, we have many customers that use our product to facilitate that movement. Um, so as I was mentioning before, like that, any, to any portability, you know, let's say they were in cloud and for whatever reason they needed to retract back to on-prem, um, we would be able to transform, you know, their cloud-based estate back to on-prem.
That's the angle that they wanted to go to, and vice versa. Or if they wanted to move from, you know, traditional VMware into something like, uh, OpenShift virtualization as an example, um, you know, those all become possibilities and they use our product to facilitate that because when you're doing these types of movements, there's a lot of risk there. Um, so I know we've been talking about risk from a, a general standpoint, but even these data movements and these transformations are relatively risky.
Uh, you know, we take, we, we remove a lot of that risk from the equation as folks are kind of moving around, uh, because we know that, you know, there's gonna be retraction. Sometimes you find that there's cloud-based, uh, services that you know you can innovate fast with, and then you bring it on-prem. So, you know, not only do we support that, we, we also provide a vehicle to deliver that outcome to them too.
Let me add some something, uh, to the ALS question. Um, let me be explicit. Uh, some of your, um, competitors are moving everything on the cloud, and I'm talking from a cloud service providers point of view and basing all of this stuff on, uh, data serenity.
Uh, now is it in your path, I, I know that maybe you cannot answer, but I interested in, uh, having some kind of hybrid model or all on premises model or only cloud model that is the point that I'm looking for about the Yeah. Competitors. Yeah, absolutely.
So, so the product is flexible enough for all of those scenarios. And even if you have edge and robo based locations, um, you know, there's, there's capabilities within the platform that also allows that to happen frictionlessly too. So, um, you know, I know it wasn't a focus to, you know, really talk about the platform, but, uh, that optionality flexibility, flexibility and modality and, and how the product functions, uh, supports all those scenarios.
'cause again, you know, our, our traditional customer base and our, you know, modern customer base, you know, require different things and they may be moving from or shifting to some gradient level between, you know, those two extremes that you mentioned before. So, um, you know, many of our customers go through that. So not only can they exist in that, not only can the product facilitate the deployment and function within those environments, um, they, they, they certainly strive in them, and that's what the product was mainly built to do.
And that's why, you know, having broad breadth and daf uh, you know, us being very close to the hyperscalers, you know, using cloud native and event-driven architectures allows to do that, not only, uh, just from a core standpoint, but also to do it at scale with security and cost in mind. 'cause again, we, we don't wanna be operating at all costs. Thank you.
So, So just to be clear, all your functionality is available that clean, uh, cloud only on-prem only or an hybrid solution, right? Is that that's what you're saying, all this functionality on this chart. That's perfect.
And, and just to chime in here, I think, um, one of the things I hear across both your questions is, I think the trend that we see is, and this should be an obvious one only, like people just want their stuff in the cloud, but when, when the optionality comes in place where they want to be able to dock, you know, edge devices on-prem devices is usually because they have some sort of high risk sensitive data. Maybe there's legislation of what can or can't leave a country or a region. And, um, but even so, we're seeing those people say, but like, but we want the brain up in the cloud.
Um, so so you manage that part. So I, they, that's like the prevalent thing that we see. So even though Michael's saying, Hey, you could still have that, you know, that brain or control plane like on-prem if you want, usually it's more of like the data for residency, um, legislation.
Yeah, definitely. But the, the, the thing is here, uh, it's what you want, uh, and what you can do because if, if I understand all those models, it's pretty vast amount of, um, infrastructure to be in place, manage, you know, somebody needs to take it in the operation. And on the first slide, you wrote that 60% of companies, uh, use more than 25, uh, SaaS, uh, applications, right?
And it gives another seven, right? The, the, the thing is that we, from one site, we make the infrastructure, uh, maybe more resilient, but from second site, we add another seven or eight or 10 systems to support that. And why I'm asking if you can do it on-prem, because when you install it on-prem, all of those models you need to manage by yourself.
Do you have any service that you, for example, manage those infrastructure at the customer and on-prem, because of the compliance issue, they cannot move to the cloud Only if it's our, if it's our solution. Okay. So yeah, You don't have appliance like bring the appliance and you just like, okay, I pay you some back and you manage that stuff on my side.
Yeah. And the, the typical customer of ours consolidates down from multiple data protection or resilience solutions to Commvault. Mm-hmm.
And so, um, you know, the average is, is about three, but I've talked to plenty of customers where it's over a dozen. Uh, or if you, you said, I was actually just talking to a customer at one of our cabs, and they're coming down from 25 different systems. Wow.
And, and so to have some of that flexibility where it's like, Hey, but these we're covering something that might be more traditional, we need to be able to dock those. And so yes, there are these three workloads or these three data centers or whatever it is, but they still want that kind of centrality and kind of a, frankly, like a central resilience policy engine. Final question, I will stop myself a little bit.
Uh, just, uh, if you, if you, you, you can hand pick this functions, right? So I don't necessarily need to have all functions to use your software, still can use a little bit of a discovery, I don't know, maybe a AI threat scan and stuff like that. I don't need to take all of them, Correct?
That's right. Okay. That's right.
Yeah. There's, there's lots of different, different modules and I didn't want to get into that complexity, but yeah, when you, when you look at some of the boxes, uh, toward the bottom, these are, these are not just products, like some of them are baked into the, the platform itself. Um, so again, based on your use cases, you, you, you pick and choose what you need based on the outcomes that you wanna drive.
And, you know, we, we talk about outcomes a lot because you know that that's really what's driving people to solve these particular challenges that they're most played with. Uh, and there's certainly other things that we're not talking about today that, you know, become part of that plugged in type, uh, modality so that, you know, people can really address the concerns of their organization that are usually distinct. So, uh, yeah, you don't have to get the full boat.
Uh, I know there's a lot on the slide and it, and it looks like it's, it's complicated, but, you know, many of these things are just called out because they're facets of the product that are driving a particular outcome, which ends up leading to, you know, how do I get the fastest, uh, cleanest, uh, recovery, uh, you know, I'm looking for threats or if I'm testing Brings up, uh, oh, go ahead. Yeah, I, I wanna talk for once, so I, that's, sorry. Uh, but my, my question is about, um, as a customer be on a journey to adopt all of the features that, that we're seeing on the slide here that like, they may be starting the very far left, they're just in the 3, 2, 1 stage.
How complex or simple is it to start adopting those features over time rather than going from the far left? Everything in there is, is it easy to deploy the platform and pick and choose features you want now and enable them as you go? Or do they have to have a complete roadmap and strategy to adopt it over, over the long term before they can even start adopting, or, Yeah, yeah.
So I, I think in the conversations that I've had with lots of customers and partners, uh, you know, if we're sitting on the operational side, which is usually a, a very classic and, and traditional approach, it's like, all right, how do I all walk run to get to the rest of this, right? So those conversations usually end up with, uh, you know, some level of discovery, like, well, what keeps you up at night and where are you most concerned? And then we provide those recommendations.
And then what happens is as you start to, to plug those concerns, you may start to see additional concerns crop up as, okay, now that we solved, you know, how do I make sure my backups are clean? I wanna start testing them in a very frictionless way, you know, what do I need to actually do that so that if I do get hit with some type of breach, how am I gonna respond effectively and cleanly without having to worry and scramble and, and I can do that and provide predictability to my board or my C-suite or whatnot. So, you know, a lot of times when I engage in those conversations, it, it usually is a crawl, walk, run approach, but it starts with what are you most concerned with?
Um, you know, and then, you know, we, I have abstract conversations with some, some, you know, folks that have like ultra high sensitive data, and the first thing out of their mouth is, you know, how do I, how do I protect my long term threats? But then, you know, we, we go through that particular kind of talk track about, you know, what solutions we have on our product to protect against those types of threats, and then we kind of walk backwards from there. So, um, you know, for me, it, it's always that roll walk on approach and really understanding what customers are most concerned with.
Um, I, I try not to take or make any assumptions, uh, for the most part when we have those conversations, because I've seen a wide swat of concerns kind of come my way and we make recommendations based on what we have in the portfolio. Hey Michael, um, thank you so much for this. I think that this has been a great walkthrough of the platform and, and your capabilities.
You've talked a little bit about how you've integrated AI across this landscape. Can you talk a little bit about how the attack fronts, um, are shifting given, um, the new tools that, that actors have with ai? And are you doing anything to address that?
Yeah, so, um, we've had like traditional machine learning, uh, in the product for, for quite some time, uh, I would probably say about a half a decade or so. Um, and we use very traditional models to do forecasting and prediction, uh, so that we could like load balance resources and making sure that we adhere to SLAs that are set as part of the policies. Um, when we, when we start to think about AI and gen AI based threats, um, we look at it from a couple different facets, but most of them are, uh, grounded on data, right?
Like the data that are feeding these systems, do you understand what's being fed in? Uh, and, and sure there's like post filters and things, but you know, when I was talking about really doing data discovery and classification and understanding and remediation, you know, those are, those are the first, those are the first recommendations we always make. Like, take an inventory, understand, you know, what your data footprint looks like, and then, you know, react accordingly based on policies.
And we find that users, um, sometimes are, are oversharing and training, and that sensitive data gets in there just 'cause they didn't know, right? Like, it, it wasn't malicious, it was just done by accident. So, you know, we kind of stress these tools to provide, uh, that wider scope of understanding.
Uh, but it's usually grounded in, in data. And, and those are like very similar lines when we have these quantum conversations, right? Like, you, you, you don't need p qc for every single thing that's happening in the environment.
There's a pretty, uh, small data footprint usually, uh, that it would apply to. So we kind of talk about what that, that those data characteristics look like, and then we apply those capabilities to, you know, just that data footprint. And for everything else, you know, we have traditional methods that we apply to, so there's a lot of similarities between them.
But, you know, when we talk about AI threats, um, you know, it's usually grounded in, in, you know, what does the data look like? Uh, do you understand that data and is it being used in the right way? Uh, and we have compliance tools and other things that we have in the product that we didn't talk about, uh, that kind of further aid, uh, in that particular case.
But, you know, if you go back to the example I was making with risk analysis and purview earlier, again, these are all like really understanding the data that may go into these systems and that may expose you. Uh, and we do have remediation capabilities, so, uh, you know, we could do some data masking, uh, we can obfuscate the data, uh, that's getting served up into these systems. So we do play some additional roles in there, but again, it's all very data focused.
Okay. I have, thank you. So, sorry, um, I have a quick question, Paula here.
Um, one thing, so I'm kind of hearing a lot about threat detection, and one thing I was curious about is, are there ways to stimulate like a disaster recovery event or maybe like chaos testing to actually validate the resiliency? 'cause for me, that's something I would be interested in. Um, that's something I get hit with a lot is like, are we sure we're safe?
Like we have all these things, but is it actually going to work? Yeah. Um, I will talk in a little bit once I get to the demo about how we're actually educating customers to go through that in a live scenario, uh, where we're actually doing, uh, like red teaming, uh, to provide, you know, customers that experience and how the portfolio, um, you know, operates in, in such a scenario.
And we'll talk about mission recover recoverable in, in just a couple minutes. Cool. Thank you.
Hey, Michael. Um, here I've got a broad question. I sit in the cyber team as an enterprise architect, and when I look at that slide, I see three different stakeholder groups, the data team, um, the cyber defense team, and then you've got the resiliency team each with their own different KPIs and needs and idly.
They get along, but they've got different needs. So how do you work with organizations, uh, to actually build something that came up, which is a central resilience policy? Um, Yeah, so, so as I was mentioning before, um, you know, have, building that single source of truth has really been a ground, really has that grounding effect, uh, in these multi persona, uh, scenarios.
So, you know, as, as we're sharing things that are happening inside the product, uh, where this, where this used, where that scenario actually shines is, you know, when we build a lot of the bi-directional, uh, integrations with our security tool tools, uh, within the ecosystem, um, you know, as an example, we're sending alerts into, you know, Sentinel and maybe you have a ticketing system in ServiceNow. By us having like those deep integrations, you're, you're unifying the information that everyone's using to understand how they're gonna go about these things and how these tools all interact with each other. Because when you go through incident response, or even if you're trying to, you know, protect an environment or secure an environment like these, these capabilities, uh, all talking to each other is super important.
So, you know, when I, when I mentioned ServiceNow, you know, the ServiceNow integration that we have allows the Convault admin to have some idea that there was a ServiceNow ticket that was created for this particular incident. We have the information coming out of Sentinel, you know, within our platform. So we really meet customers where they are, and we're not forcing them to go into Commvault as an example, or we're not forcing the Commvault, you know, backup admin into these other applications and try to figure out, you know, what that source of truth is.
Um, we allow all of that data sharing across these integrations that we've built so that everyone kind of has that single pane to operate against. And we found that as a, as a unification function. And then obviously there's a whole, um, you know, awareness and, um, enablement aspect through this, which, you know, I'll cover in just a second.
And, you know, we found that there's some good byproducts that actually happen from, you know, really asking these hard questions and having people go through simulation. And we find that that like completes the full circle of not only having like these, these technical grounding, but also information and enablement grounding, uh, on these capabilities to kind of provide that full circle. Another, another quick question, and this may get covered in the demo, if so, cool.
But, um, as someone who's heavy in DevOps engineering, another thing I'm wondering is what does like the alerting look like when something is going on that would be cool to know, because I'm always battling alarm, alarm fatigue, so I kinda wondering what that's like. Yep. I'll, uh, I'll certainly show that to you, uh, at a high level in the demo and then, uh, you know, if we need to click in, we can certainly connect afterwards.
Uh, you know, this is, this is the stuff I love to talk about so we can do some show and tell. Nice. Yeah.
'cause I think, if I remember correctly, I believe I saw you all at reinvent last year and you had like the whole clean room set up. And so reminding me, I meant to follow up with you all 'cause I was interested in a product and so this may be later in the presentation as well. One thing I was curious about and now remembering to follow back up on is, you know, what is a good way to just try to like, get hands on with it to see if it's a product that makes sense for you and learn it.
Yeah. Cool. Yep.
Cool. Alright. Uh, I'm, I'm getting pinged on on my timing.
So, um, I keep talking about enablement and awareness and uh, this is one of the things that we launched and minutes the meltdown, uh, is, is to raise awareness of the last minute uncertainty that happens during an event. And when we launched Midst The Meltdown, it was primarily focused on C-suites and execs and IT role, and it forces them to role play through a breach scenario. And why that's important is it kind of surfaces not only emotion, but you know, the things that maybe you don't really think about as part of the breach.
So, you know, you have your CIO, you got your CIO, you got legal in there, and as everyone's kind of going through that role play, you start to think like, am I really prepared? Have we thought about this? So there's lots of thought provoking, uh, aspects of the exercise.
And one of the best side effects that we could have ever had out of minutes of meltdown was execs started to think about, well, now that I understand this, are the folks with hands on keyboard actually prepared for this? So it's great that the executives have an understanding and alignment, but what about the people that are actually gonna be orchestrating and doing these things? So what we did was we released Recovery Range, and this is where we have, um, hands-on keyboard folks go through Mission Recoverable, and we did the pilot at RSA and the teams loved it.
So again, you're in a group of four, uh, it's a live event, uh, you're in a live environment, uh, there's, there's simulated things kind of going on. So there's unpredictability, uncertainty, just like you would have in the real world. And we have folks go through a live cyber attack, uh, that gets orchestrated at the very beginning, and then we walk people through using Combo Cloud to properly recover and bring their business back to minimum viability.
So, um, I know I'm kind of showing it on the, on the right side, but again, you know, recovery range was really for us to deliver the hands on keyboard experience. That becomes the, the, the, the next evolution of what we did with Minutes to Mel Down. So enable the C-Suite and execs on, you know, what incident response may look like, what is, what happens during a breach, all the hot seat things.
And then recovery Range became the answer for all the people that are gonna be hands on keyboard. How do you actually go through this? So, uh, instead of continuing to talk about it, let me show you and walk you through a demo of an abbreviated version.
Is this attack like prescripted, like, so that it really shows how well Commvault can respond and react to it? Or is it something where, you know, the customer testing it out can maybe inject their own criteria into what's happening so that they can kind of test the limits of what your solution's able to recover from or detect? Yeah, so with SIM based, um, we do have the capability to, uh, customize like what goes on.
So we found that, uh, like certain verticals are more concerned with certain attack patterns and uh, different risks, right? It's not just about, hey, you, you encrypt some files, right? There's that, there's data exfiltration risks and you know, I talked about Quantum before, so you know, there's, there's a propensity for us to, um, you know, continue to customize this.
So what I'm gonna show you today is like the, the one hour abbreviated version in like eight minutes. So we're gonna go through this, that like light. Michael.
Yeah. Can I just chime in for a second? Sure.
So the other thing I wanna say about the recovery range is that while it, it is a fairly prescriptive attack, and these are based off of real world attacks and we have a library of about many of them that we can do, what they actually do each time is slightly different. So no two attacks, no two recovery ranges are exactly the same. And, and that's, we find that's really important too because you, when a, a real cyber attack happens, it's unpredictable, you don't know what it's gonna hit, is it gonna hit in accounting first or where's it going to move laterally versus elevating credentials.
So everyone is actually very much unique, even if it's using the same sort of attack vectors. Yeah, and I, I'll actually show that to you as we go through the demo. So let me, lemme start this.
Um, so this is kind of the setup though. This is, this is the customer site. Um, this is your site, you got laptops, you got desktops.
Um, and the part that, you know, Thomas was just alluding to that I mentioned before is, you know, we have a bunch of desktops and we, we can turn on user emulation. And what this will do is this will add some unpredictability into the entire scenario. So you have different users logging in and they're actually gonna be doing different things.
They'll be sending email, they'll be rolling, building Word docs, they'll be IMing each other. So from a standpoint of unpredictability, we can inject that not only from the attack side, but also from the setup side. So in this scenario, we have tech bit, uh, we have our front end store.
This runs our entire, uh, environment and that's what we're gonna see compromised. So in this particular case now as the, the the, uh, red team user, it's gonna go through and it's gonna run this attack pattern. It's gonna do all of these things and then we'll actually see it running in real time.
So you're gonna see all kinds of exfiltration, there'll be PowerShell execution. Um, and then what's good about all of those things is it generates a lot of logs. And we get to look at how those logs are gonna be, not only from an operating standpoint, but also from a bult standpoint.
So here the actual, uh, threat is, is going through. So we can see that, you know, there was a breach, there was lateral movement, and now there's gonna be some exfiltration and encryption occurring. So again, this is gonna happen across all the different labs that people have access to.
Uh, and then there's gonna be some variation in them. So now that the threat payload was launched, uh, it started encrypting our files, our web servers are down, and now we're gonna have to figure out how we're gonna recover. And again, you can see we're starting to see these signals.
You can see that there's all variability between all these different desktops. So again, it, it's not a, a very static thing that's happening. So when we pop into Convault, again, lots of rich, uh, events and alerts are getting generated.
You can see that we're seeing an irregularity in the file activity being detected on the machine. So this is not being generated from a backup. This, this irregularity is being generated from activity that's happening on the live file system, and we're notifying the user that that's happening on the live file system.
So again, there's, there's no backup be involved in that particular case. So you can see we we're generating a plethora of, uh, file irregularities happening on the machine. These are all, uh, events and alerts and they're happening across all the machines and we have detection time and everything else.
When we look at our threat indicators dashboard, which is kind of the sum up, now, we're actually seeing deeper information about, you know, what is being indicated on these particular machines. So as I mentioned before, we have Simmons, so, uh, connectivity in this particular case, we're moving the data into Splunk. This is what the environment is using for all of its, uh, events.
So you can see we have a squid proxy and it's generating logs and they're seeing information there. You can see that this is being generated from Windows event log, there's some, you know, Robocop happening. Uh, so it's not just Commvault stuff.
So again, everything's kind of getting aggregated and it's building that, you know, common layer of information. We're seeing some more cisson logs of things that are happening. Someone's scheduling some tasks, probably putting some back doors.
We could see some payload information. So again, we're not just trying to say that there's telemetry coming from Commvault in this experience. There's gonna be telemetry coming from everywhere and signals.
So now we're actually getting into, you know, what we're sending directly into Splunk. So now, you know, someone sitting in this interface is now seeing, you know, rich signals from the operating system. They're seeing signals from Squid proxy and they're seeing signals from Compart.
So there's something happening and you can see that file irregularity is happening across. Uh, Michael can you, can you stop the demo? Yeah.
So are you, have you cloned the customer environment and then this is all happening in sort of a, a simulated, uh, test sandbox kind of environment? Or, or are you trying, or are you pretty much simulating all the security aspects and all the problems without having, uh, to use the, you know, a copy of the customer's environment? I'm just trying to understand how this mission recoverable thing Yeah.
Uh, works, I guess. Yeah, so it's not a direct clone of our customers. So, you know, recovery range is really a, you know, mock environment of, you know, what we see a lot of our customers, uh, most concerned with.
So it's a representation, uh, but again, you know, in recovery range, there, there is that randomness in there that provides that unpredictability. Now it, it, it's not impossible for us to say, Hey, we can go build a complete AWS environment and then, you know, go through this. Like, that's all possible.
But right now it's a representation of, you know, what we've compiled from our customer base based on their most concern and how these pieces operate. And so this role play is happening in the, in, in, in a cloud environment, or is this on-prem or? No, this is in an, this is an event that we host.
This is a, this is a guided event that we host. Alright, so, uh, for those familiar with Commvault, we're gonna go take a look at the machines, we'll go do a recovery. And because we have detected anomalies on the machine, we will automatically exclude those anomalies, um, from the recovery.
So when we go to do the restore, we'll do last known good version, um, we'll unconditionally overwrite whatever is compromised, uh, with last known good. And hopefully, you know, fingers crossed, will will be able to get our file server back up and running. And I can tell the CEO that we restored the website and everything's all good.
Alright. And with the power of video editing, um, the restore is done and, you know, my tech fit one web server is now up and running and operational, so looks all good. Uh, and we haven't recovered, you know, store two, store three and store four.
And what we will do is maybe we wanna have a deeper understanding on what's going on in store two. So we're gonna run our, uh, threat scan job and our threat scan product is the one I was talking about before, which will actually look at entropy scores. It'll look at, um, you know, threat signatures, uh, to really understand, you know, the payloads and things that may be, uh, existing in the system.
Now with that, again, it provides us with this deep telemetry. So you could see the extensions all been changed, uh, to, you know, what looks like a threat payload extension. Uh, and you know, again, threat scan will now flag all those files.
And if we were to go do just a flat recovery, uh, it will automatically exclude them from the recovery. Uh, if we were gonna do a forensic recovery, of course, you know, we could force the system to recover those, uh, so that we could do true forensic analysis. But, uh, by the default action, once we do detect anomalies and threat payloads would be to exclude them, uh, from the recovery.
Now you may have noticed in the upper left hand corner as things are moving, um, you know, my, my store one has went back to, uh, your files are encrypted, so it's obvious we didn't clean up all the infection and that machine was reinfected. So now what we're gonna go do is, is set up a clean room recovery. So we orchestrated the recovery of our, uh, comms serve in an IRE.
So this is not my production commer, this is now a version of my production comms serve, sitting in the clean room. I have a recovery group, as I said before, like we, we orchestrate all these actions and this will allow me to bring my, uh, entire, you know, application back up in the isolated environment. And what I will use this to do is either validate that I can recover at a last known good, I could do further forensics here, or, uh, you know, if this was true, a true disaster scenario where everything is scorched earth, um, you know, I would be able to use this in production with some, you know, changes to the V nets, um, so that it could get exposed accordingly.
So, um, you know, with the click of a button and 10 minutes later I brought up my entire application, you know, all my storefronts, uh, the domain controller and uh, the, the backend. And now with that all recovered, you know, I can go pass that off to my security team to go do that deeper forensics understanding that I know when I just did the base level recovery, you know, there was still something going on and that machine got re-encrypt. So, and then of course that we've been talking about all day, there's flexibility so that, you know, if I wanted to manipulate the size of the machines or if I wanted to repave the images of these machines, let's just say that the, uh, operating system was further compromised, I could, you know, restore that machine and use a gold image of the operating system, uh, and then reattach all of the application discs to that.
Uh, so this is just kind of showing that we have a lot of optionality when we go to recover for these types of, you know, really embedded threats. Uh, we do have, uh, functionality to allow us to recover from those things accordingly. So again, um, this is gonna allow me to kind of restore that in a custom way.
And if I jump back to my production environment, you can see that again. Store one is now showing that I have, uh, more threats. Hopefully, you know, my security team has cleaned the back doors.
I'll go do the recovery again. Now that I know it's not gonna get reinfected again, this will use last known good. So anything that was, that was detected as a threat payload, um, would be Remi.
And now I can successfully bring my, you know, tech fit website back up and my business is back up and running. So this is, uh, in a nutshell, you know, how we're facilitating all of these capabilities across the platform. So, um, you know, we started with detection, uh, of, of, uh, threats in the environment.
We went into a Simmons store where we're forwarding our alerts to really get an understanding of, and hopefully we're unifying all the personas across the state, uh, across the estate to make sure everyone, as they're going through incident response to able to do it. We did a recovery, which was the last known good. However, we didn't clean up all the infections on the machine, so the machine got reinfected.
We then used clean room recovery to set up an IRE so that my forensics team can figure out how to get rid of those back doors and payloads so that when I go to do the production recovery again, um, we'll be able to recover that data accordingly. And then we were able to do the production recovery after we cleaned up everything and everything was all good. And again, as we're going through this and it's generating alerts, all of that is getting forwarded into, um, you know, the SIM platform.
We're providing evidence so that eventually when we do have to do the report out or root cause analysis or notify the S right? We have all of this data. So again, speed round.
I know I covered a, a whole bunch of stuff in a very short period of time. Um, recovery range is an hour long, uh, session. So, uh, there was some stuff that I had to omit just, uh, for brevity and time, but, um, hopefully you kind of understand, um, you know, what we're trying to do by educating a customer by not only telling them what the product is capable of doing, but also going through threat simulation and making sure that, you know, they understand how all these pieces work in concert together.
Uh, providing a solid foundation of information, allowing them to test recovery, to build muscle memory, uh, so that as we go through incident response, it could be better, faster, or more accurate. Great. So quick question, uh, speaking about, uh, educating the customer.
So I noticed, you know, the dashboard tab in the, uh, demo, something I get handed with, uh, a lot. Are you able to create like a custom dashboard so that way, like top level execs can see something quick and simple and kind of see what's going on? Yes, absolutely.
R ei Yes, yes, yes, yes, yes. So, uh, our reporting framework is awesome. Um, so you could, you could use the canned reports that we have in the product.
Uh, we allow you to fully customize the reports in the product, and then we allow you to dump the data that backs the reports as an API. So if you wanted to substantiate the report in Power bi, you can just call that API, it'll already give you that data and you can visualize that data accordingly. Uh, and, you know, you could replace Power BI with any of these other, um, you know, data visualization tools.
You could use Grafana, uh, as an example. That Was my next one. Yep.
Yep. So we make it really easy to go dump that data, uh, into all these other systems and really cater that data to your individual needs. So again, I know I'm, I'm probably, you know, just beating a dead horse here with, you know, saying this, but, you know, the product is really built with a lot of optionality and flexibility, uh, for the vast set of customers that we have.
So, you know, these are all things that we, we remove the, the, the force function of having to live in com, but still harness all of the rich data that we're generating into these other systems. You know, meeting customers wherever they may be, you know, across the landscape, whether they're gonna be in our product or any of these other products. Cool.
Thank you. Awesome. Um, so with that said, uh, I'm gonna bring this back up and, um, you know, again, recovery range that I showed today was a much abbreviated version.
Um, there will be versions of this that will involve both Lumio and Cloud Rewind. And for folks that aren't familiar with Cloud Lumio or Cloud Rewind, I'm gonna pass this over to my colleagues now so that they can provide you with some deeper insights on how they're changing the game on, uh, cloud Native recovery.