26. AI and Cloud Demand a New Approach to Cyber Resilience featuring Commvault – Tech Field Day Podcast Spotlight Series
As companies are exposed to more and more attackers, they’re realizing that cyber resilience is increasingly important. On this episode of the Tech Field Day Podcast, presented by Commvault, Senior Director of Product and Ecosystem Strategy Michael Stempf joins Justin Warren, Karen Lopez, and Stephen Foskett to discuss the growing challenges companies face in today’s cybersecurity landscape. As more organizations transition to a cloud-first operation, they’re recognizing the heightened exposure of their data protection strategies to global compliance mandates like DORA and SCI. Adding to this complexity is the emerging threat of AI, raising important questions about how businesses can adapt and maintain resilience in the face of these evolving risks.
Transcript
As companies are exposed to more and more attackers, they're realizing that cyber resilience is increasingly important. This is especially true as they shift to cloud first operation. And as they realize that, uh, data protection is increasingly exposed to, uh, emerging mandates like Dora and SOCI for global Compliance.
Plus, there's the threat of ai. How are we gonna deal with all that? That's the topic of this episode of the Tech Field Day podcast.
Welcome to the Tech Field Day podcast, where we bring together a group of IT experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day community and is being recorded in association with our presence at an upcoming event. In this case, Commvault Shift, which is October 10th in London Tech Field Day is part of the Futureum Group, and this podcast is published on our sister company site Techstrong tv.
On this episode presented by Commvault, we're heading into Commvault Shift and discussing the changing demands around AI and cloud when it comes to cyber resilience. Before we begin the discussion, let's meet who's on the panel today. Hello, my name's Michael Stem, senior Director, product and Ecosystem Strategy at Commvault.
Hi, I am Justin Warren. I'm the founder and principal analyst here at Pivot nine. Hi, Karen Lopez.
I'm based in Toronto. I'm data chick almost everywhere, and my whole thing, I consider myself a data advocate, And I'm Steven FoST, organizer of the Tech Field Day events. And, uh, I will be at Commvault Shift and the rest of us will also be participating in, in that.
And so you'll be able to see lots of our content online. So let's kick things off by talking about cyber resilience and cloud first and, and what that means. I guess I'm gonna throw this over to you to start off with, Michael, what exactly does it mean to be cyber resilient?
Cyber resilient is a difficult thing. First of all, I, I think the problem is that nobody's really defined what it means to be cyber resilient, and that's a problem, right? For years, we've had common methodology and common terminology about what it is to be, uh, you know, advance in your disaster recovery or your business continuity, uh, strategies.
But, but that hasn't been done yet with cyber. And so the concepts and the ideas is very difficult. So what does it mean to be there?
That's a tough thing, right? Um, I think it is an, uh, right now it's a, it's a constantly moving, uh, concept, but I think first and foremost is that you are able to recover after a cyber attack. And, and, and while that might sound very basic, it is way different than a disaster recovery plan in the same methodologies.
And I think that's because if you look at like a tornado, right? A tornado isn't gonna do malicious things to your infrastructure and a cyber attack that will, right? So when a bad actor comes in, you have to question everything.
Is my network good? Is my data good? Is my ser or my servers good?
Is, is my, uh, you know, my cloud first architecture good? Because all of those are gonna be suspect. So I, I think first and foremost for me right now, what does it mean to be cyber resilient in today's world, especially in a cloud first environment is have I tested and I have, have I prepared to be able to recover after that cyber attack?
Um, one of the things I always like to say is, there's two types of companies in this world, right? One that know that they've been breached, and those that don't know they've been breached. And that's about it.
So that's, cyber resiliency is just so important nowadays. Yeah, I'd agree with that and possibly push it a little bit further and suggest that being resilient is largely about making sure the computers are doing what you want them to do and continue to do that, even though things around them change. We all know that cyber attacks are pretty much just a daily occurrence now, and it's not something that you hope will never happen, and then you'll have to do a big recovery one day.
It's just the way things are all the time now. So basically always be recovering should be what we're doing. That's how you actually become resilient.
It's a little bit like us as humans wandering around in a, a world full of diseases and, um, and animals that might wanna attack us. We, we generally just conduct ourselves in a way that, look, we're always fighting off infections. We're always trying to be sure that we stay away from that bear.
And, uh, that just is how we conduct ourselves through life. Yeah, I'm gonna agree with Justin, and I'm gonna kind of throw in like, I grew up in tornado alley, so that's a great analogy you've used. And while I'm fortunate that my homes were never, you know, hit directly by a tornado, we still suffered repercussions of no power or of a third party.
And the analogy goes to in the cloud, maybe a third party system with hit by the same outage, and can we recover from that? Uh, it also means that I can take the preparedness mindset that I have from living in that fear to how I do everything. Like one of my snarky taglines is we don't need any backups.
No one needs backups. What they need is restores and recovery. And a lot of people are testing backups, but not testing their recovery and also not thinking about, you know, the other processes.
Like, it's great if you can get your database backup online. In fact, that would normally have been my job, but I also need to know, are all the other systems connecting to it now that it's been down? And have I made sure that that restore point that I'm bringing in hasn't also been corrupted?
Like, how do I know, how do I test for that? And those are the types of things of when I make the distinction between cybersecurity and cyber resilience. So Karen, excellent point.
Um, the difference is quite vast when you start talking about Dr. Disaster recovery and CR cyber recovery. And, and I think the funny thing is, is this, for 20 years I've been around data protection for a long time.
I'm old. Um, and for, you know, many, many years we would do quarterly or yearly testing with disaster recovery, yet that only affected less than 1% of all businesses that are out there. And, and, and then you pivot and you look at cyber recovery.
And because of the lack of methodologies and terminologies, best practices, I mean, let's be honest, nobody likes to admit that they get hit by a cyber attack, right? It's a hit against their brand. Um, and that's why I think these eight ks from the SEC are really important.
Now, if you're not, if you're not out there farming that data, it's really important. But, but I, I think that the, the main difference here is we tested for years, and to be honest, we got kinda lazy with it, right? We got so good at disaster recovery.
A lot of my customers simply would flip flop between one site and another every year, every six months, and they'd say, that's my DR test, and we're gonna run in production over here, and then we're gonna run in production over here. And that took care of it. Uh, but with this new chaotic nature of cyber attacks, I don't know how much of my en environment is gonna get hit.
I don't know if it's a destructive hit versus a non-destructive hit. There's so many unknowns that you just can't take this disaster recovery plan or tabletop exercises that you were doing for a DR and transpose that and bring that into the cr because one, it's gonna get you a false sense of hope. Uh, and what you're gonna find is that when, when you finally do get hit by a cyber event, uh, you're just not gonna be ready for it.
And, and it's, and it's gonna play out very badly for you. Yeah. And Michael to, to be kind to our past selves a little bit, um, the environments back then were a lot simpler than they are today.
There's just so many moving parts now. I mean, when you throw in like multiple clouds, onsite environments, pretty much everybody's running some kind of hybrid cloud setup. There are so many moving parts, it's really difficult for any one admin to hold that all in their, in, in their head and understand what exactly would we even need to recover?
What, what is at risk here? And I think we actually do need a lot more tools now than we did back in the day, just to be able to manage the scope and scale of things. It's not something that we can do manually by hand.
We actually need to put in systems and processes that are largely automated just to be able to keep up Agree a hundred percent. Um, traditionally when I would do DR testing, it would be from one site to another. Maybe you had a third site.
Nowadays I'm in AWS I'm in Azure, I have Microsoft 365, I have a colo, I have three on-prem. It's just incredible. So how do I even orchestrate that testing environment?
It, it, it's just, it, it's so complex, it's so expensive, uh, that it's become very difficult to do. One of the things that we did at Commvault to try to eliminate a lot of that is we came up with what's a concept that we call clean room recovery for us, a clean room, um, allows you, uh, a location in the cloud that dynamically scales up for your needs, that allows you to bring back any of your data. We, we have a concept called any to any, which means I can take an AWS EC2 VM and I can restore it to Azure, or I can take an on-prem VM and restore it to Azure or even a, a physical server that's I have on-prem and bring it up to Azure.
So now, instead of having all of these different test environments, I can have one place, Microsoft Azure that I dynamically scale up. First of all, it's it's brand new, so I know it's clean. And that's the important thing.
DR was all about speeds and feeds. Uh, CR is all about cleanliness of the data. So I bring up a brand new environment, I convert all your data into one format that can be read in Microsoft Azure, and then I can do my testing and I take away that complexity and all of that cost.
Without that, we're never gonna fix the real problem. And the real problem today that I see from my customers is the average re uh, uh, the average time it takes to recover from a bad actor. And that's 24 days right now.
That's a long time. And so can repeated chaotic testing is what's going to help eliminate that timeframe. And unless we do, like you said, Justin, eliminate all this complexity in these different environments, we're not gonna get to it.
It's just gonna be too much. So that's where clean room recovery really comes into play. Yeah, that was a big announcement, uh, something that we were really keen on last year, uh, at Commvault Shift.
And, um, I, I think though that, that one of the things that this points to is the fact that most modern enterprises are not data center first anymore. They're cloud first. And most enterprises have maybe even a majority of their applications, or maybe most of you know, most of it, uh, running in the cloud.
And, and many of them are running across various cloud systems. Um, it's complex. They're using various SaaS and platform as a service.
They have all sorts of things out there. And, um, and that helps them to be more agile as businesses. But it certainly doesn't help the IT administrators whose job is to make sure that those systems are cyber ready.
And the fact that it is so difficult to switch from cloud platform to cloud platform has been a big problem. We talk about that a lot, that the only way to, uh, really, uh, move from one, uh, hyperscaler cloud environment to another is if you are basically not using any of the features of the hyperscaler and if you're just treating it like a virtual machine in the cloud. So, uh, you know, Michael, what's your approach or your thought on cloud first enterprises and how this changes the game for cyber resilience?
It's, it's a massive change. Let's, let's take something simple like let's say Oracle, right? Okay, maybe not simple, but let's take Oracle, right?
If I have that on-prem, I can back up the organic items that are have to do with Oracle, right? But then I can also come along with like a file system agent and I can get all the OP options files. So if I ever had to restore Oracle, whether it was physical, virtual in the cloud, doesn't matter, right?
As long as I'm doing like an IAS approach, I can simply restore everything. I have all the option files, which is all my metadata, I restore it and I'm done. The problem is, is when we start getting into cloud first, I don't have access to that underlying infrastructure anymore.
And so getting the concept of, of the options file, um, it it, it's a foreign concept. And so, you know, there, there's literally for some applications, thousands of options that need to be set. And so the problem is, is that we have to stop thinking about restoring just the data because on-prem we could restore the data and we could restore the infrastructure 'cause of that option.
Very simplistic, uh, uh, um, um, example here, but in the cloud, I can't do that. So one of the things we did at, at Commvault is we actually purchased a company, uh, a few months ago called a PIX that allows us to go out and really do infrastructure as code, right? I can go out and I can look at all of these options that are associated to these different applications in a cloud first infrastructure and get all that data.
And that allows me to, on the restore side of it, not only just restore the data, but I can actually rebuild the environment, which is so much more important and so much more time consuming than just bringing that data back. Yeah, that's, that's always been a tricky part of doing system restores. It, it was a lot easier when it was onsite and it lived on one particular piece of hardware because generally you could have two or three different ways of backing it up.
And the really, really simple way just captured everything. That's a lot harder to do in the cloud. And yeah, you're right, Michael, there's a lot of this config and environment setup that isn't really captured by a lot of the backup tools.
You actually really, really need it. Um, if you make changes to that, that drift over time and you haven't got it written down or you, it's not particularly well maintained in some kind of infrastructure as code system, and let's face it, we, we are all human, do the discipline to do that is, is really, really hard. Having a tool that actually knows where all of those config pieces are and all the little bits of glue that turn data into a system, that's what we really need.
And I can also say from my background, I mean, that's even a problem when you're all on one system, right? But for instance, as you're gonna keep those config things, they're gonna use different terminology, different levels of granularity. And if I had to stand up, like you said, if I guaranteed portability across all environments, then I have to use the most simplest, no special features, no special anything.
And we really can't afford to do that as a business because that actually hurts us with other security things, with innovation, with all these things. I think also being able to manage those configuration properties, settings and everything in a standardized way would probably enable a lot of other benefits as well. So things like being able to compare the drift that Justin's talking about, I could compare the configurations of those things to see how, you know, this, how dev test and QA have changed.
There's all kinds of things. Like, I guess I'm a data person, so I get excited when we're talking about system data or metadata or config data. To me, it's all important data to admins as well.
I think, I think that's a great point, and I think both of you hit on this, is that we look, tend to look at this from a user perspective, from an administrative perspective, right? Whether they can do it, not do it whether lazy or just not in the process. But now we're dealing with, uh, compliance issues too, right?
If you look at like Dora Article 12, right? It's specifically saying, you, you gotta take this cloud stuff into consideration. We had a huge customer who had, um, billions of dollars of, uh, retirement money in their stuff in the cloud and because of a clerical error, um, it was all deleted one day, just absolutely gone.
Their backups in the same cloud gone. Uh, but because they thought ahead, uh, they happen to have stuff within Convault Air Gap protect, which is a tertiary copy of data behind somebody else's infrastructure, which normally wouldn't be used in a dr but this was more of a DR aspect. Um, they were able to get that, uh, that, um, data back into their original cloud because they were already following what Dora Article 12 was already talking about, right?
So, so totally agree that we, we've gotta fix not only the human portion, uh, which is tough, uh, but also that compliance portion that goes along with it nowadays. Yeah, it's a big, it's a big challenge. And, and again, we've uh, heard about this from some of the folks that have been brought into some of these events and as well as at our field day events as well.
Um, you know, every jurisdiction has different compliance regulations. And I think one of the biggest challenges with, um, cyber resilience and data protection is that you're kind of holding not just a specific type of data, really all the data, which means that your subject to basically all of the regulations because, you know, it's one of the very few applications that has, um, exposure across literally every department, uh, every data type. And not only that, but of course that makes it a target, a gold mine for someone who would try to exfiltrate data or try to, uh, you know, access some systems that they might not otherwise have access to.
Uh, I know, Karen, in your, in your world, you've done a lot with this. I mean, what, what's your approach when you, when you think about systems that have such a, like a gold mine of data? Well, first of all, I'm all happy 'cause we, someone's used the word gold and data in the same sentence.
So instead of oil, so that's a good thing. Um, but my whole thing is trying to remember, you know, which compliance, uh, level applies to what type of data, the sensitivity levels. Uh, a lot of times I talk about it's really hard to protect data if you don't know you have it.
You don't know what kind it is. And not everyone's in agreement about its sensitivity level where it should reside, where it can't go, where it can go. So I think it's really important, you know, the factor about all this is having good data governance and a lot of the things that we're hearing about that have been recently announced, things that we're talking about today are going to get us along the way towards being able to govern those resources easier and faster.
Yeah. One, one other shift that I think we're starting to see is a move away from tick box compliance towards, um, the underlying reason for why the compliance things exist. Um, it is a little bit tricky in some jurisdictions because unfortunately some of the regulations are written that kind of gear you towards just doing tick box things like, oh, okay, why do we have to go through this process?
It's not actually adding a lot of resilience or a lot of capability, but the underlying reasons for doing it, I think are, are valid. And, and certainly regulators are getting smarter about this. Um, so our customers, I was talking with someone only last week where their approach to things is around data minimization so that they're not actually storing the data and then if they don't have it, they don't have to look after it.
So that reduces their compliance burden. But a lot more of the focus these days is, is on actually achieving the outcome. Not just going through a ch a checkbox exercise, but looking at, well, why do we have this data at all?
What is it for? What kinds of, uh, what, what protections do we need to put in place? Some organizations are just running on what they've always done.
It's like we, we've always had to back this up for seven years. We always needed to retain this at this particular security level. But actually going back and looking at what is the legal requirement for keeping this?
Do we even need to keep it for this long? Do we need to back it up? Do we need to re recover it?
Maybe we don't. Do we need to protect this in ways that we're actually not, and were we to be audited, we'd be exposed. There's a lot more interest in actually going through that process.
And I think that's a good thing for organizations to get on top of right now, because regulators are starting to get pretty pointy because of the number of failures that we're seeing. So if you can get your house in order, you are in great shape, uh, particularly compared to all of your peers. So Justin, I couldn't agree more.
Um, I think it's interesting that if I go back three or four years, I can't remember, I can't remember a time where there was general counsel in the room when talking about data protection. It just never happened, right? And I'm up to almost 50% now, so 50% of the time I'm talking with data protection, cyber resiliency, cyber recovery.
There is somebody from general counsel there, and that just shows the change that's happening, right? And then, you know, Steven, to talk about what you were talking about, how do you even keep up with this many different regulations that are out there, right? It's, it's incredible.
It's changing daily. I mean, um, you know, we, we had Dora, that's what we settled into. Now we have NIST two, we have, we have, uh, NIST in the United States, we have Mitre, we have all these different things.
We have CCPA, how do you keep track of it, right? And so that's really one of the benefits that Convault has is we, we've looked at this and we're like, okay, how, how do we do this first? First of all, we gotta do this without actually looking at customer data because we, we have to be, right?
When dealing with ai, too many people are working with ai and it's just a wild, wild west out there, right? The, the, the amount of data they're looking at and the amount of proprietary information and PPI and all of this is getting incredible. So we actually only look at, uh, the, the, uh, the meta plane, right?
So we're not looking at the actual data of our customers at all, but we can still determine, hey, you've got all of this information in this country. Do you know this country has these regulations on it? These regulations have these 52 controls.
Out of these 52 controls, we can actually do 22 of them. Out of these 22, you're only doing seven. So we can actually drill down and help the customer to be able to better manage their data based upon their government regulations just by looking at, you know, where we backed it up from.
Not even not even scouring the data for any additional information, which, which just makes us a, a, a better utilize utilization tool for the customers, gives them more value add than what they had in the past from a kind of a traditional data protection tool. Now, there's another elephant in the room when it comes to the internet and data protection and the state of everything we are doing everywhere now, and that's ai. And so we have to make sure that we touch on that as well here.
You can't be cyber ready if you aren't considering the, uh, first off, the data that, uh, is used to train ai, the AI based applications, uh, and the ways in which AI can be used to breach your systems and access data. Also, the fact that, uh, makes EN enterprises, uh, share data even more broadly than ever before. Uh, what's the, your approach, uh, from Convault, uh, to the emerging AI era?
So, first and foremost, we, we looked at it holistically and we said, how do we wanna plug AI in here? And what we came up with, uh, it was our responsible a AI model. We can't just go crazy with AI and start scanning everything.
So we have been, um, very adamant that we are only gonna con we are only gonna scan control plane data metadata and not actual data plane, uh, which is the customer's data. We're not gonna look through that. We're not gonna, if the customer wants to do it, we have APIs, we have it available, they can come in, they can utilize us as a great data lake to take all their information they need to into their, uh, AI tools, but we're not gonna be that customer or, or, or that, that tool for them.
We wanna make sure we're, we're, we're helping them in administration in, uh, methodology and how they're dealing with the data, uh, not necessarily scanning the data and actually getting the information off of it. So I can't say enough, the number one thing for us is responsible ai. It's incredibly refreshing to, to hear that from a vendor as well.
Um, there's been a lot of interest, certainly over the last couple of years when chat GPT took off. Everyone seems to be trying to bolt a chat bot into everything. Um, and certainly customers, I think you alluded to this, that customers who are plugging some of these systems into their data are, are scanning it and in some cases inadvertently exposing information to people who probably shouldn't have been able to search for that or, or get a query back from the system to, to look at, for example, HR data.
Uh, but it's, it's good that vendors are, who are looking at this, are doing it in a more pragmatic way and looking carefully at what is the actual value of AI here. There is genuine value here for AI systems. I remember when we used to just call it machine learning.
There are, there are tools and techniques that we can use. Not everything needs to be a chatbot. And if you are judicious about it, if youre careful about where you deploy that you can actually get some really good automation savings.
You can use systems like Commvault to be able to go and look at metadata and find, hey, you know what? This is a kind of personal data that I didn't even realize that we had in this system. I've already got a tool here that's able to assist me to get better at doing things.
I don't need to go out and buy another tool. I just need to use the stuff I've already got that little bit better. I think that's a real opportunity there for Commvault to help its customers to make better use of what they've already purchased.
And that just feels a lot less overwhelming. Well, from my point of view, um, what I want to have happen is, you know, the Commvault metadata or the findings of AI or the results of them, and let's say I'm doing those internal, you know, pattern recognition, machine learning to, to look at my actual data 'cause it's my data and it's still there. And then I want a way to be able to use those pieces together.
And the main problem I've struggled with in the past, the recent past is products will say, well, it has ai, it does this with ai. And then you can't get any more information about where, how, where it's being sent, where it's coming from, what's the transparency of how it's being used. And it's refreshing to me, as Justin said, to to hear that, you know, a vendor has a line that they've drawn.
They can clearly describe it. They can say, here's data, here's the metadata we're looking at, here's the stuff we're not. That all comes into any type of use of data, is understanding what's doing what to what data is really key to governing it and protecting it.
Absolutely. And, and it doesn't mean that it's limited in use when you do that. If you look at some of the key areas that we're investigating and we're getting into, it's things like breach management, right?
It's, it's no longer if it's no longer when it's now, how often are you being breached? So when you're breached, wouldn't it be great to know, hey, you're 36 hours away from your eight K submission. Have you done it?
Here's the information you need to send with the eight K. Hey, you're in these six countries. The machines affected by our blast radius report says it's, it's in these different, uh, geographical regions.
Wouldn't it be great if it's like, these are the different regulations you have to apply for, for here and, and actually notify against, those are things that we can do with responsible AI without ever going into that deeper level and and actually interrogating the customer's data and that, and that's what we want to focus on. 'cause we think there's so much value above and beyond that deep scan into that data that, that we can do operationally that's going to help people recover after that cyber attack. Yeah, I think that's a really great point.
And I think it shows, uh, the many ways in which AI is being used, uh, not just as, uh, providing a chat bot interface, but providing better services across the board to existing applications. And uh, that's something that came up quite a lot at our AI Field Day event as well as here on this podcast in the previous weeks. And it's nice to see companies, uh, approaching it with a sort of an open mind to thinking about the many ways that they could use this technology.
So thank you so much for joining us today on this conversation of, uh, cyber resiliency and the impacts of, uh, cloud first and AI on cyber resiliency. Uh, before we go, I wanna quickly, uh, give the chance for each of you to give us, uh, let us know where we can contact you and continue this conversation. So like I said, you can reach me, Karen Lopez at data check on most the social medias, or is it socials media?
I'd never really know. And, uh, I'll just leave you with a thought that remind your boss that ROI also stands for Risk of Incarceration when it comes to compliance needs. com.
And you can also subscribe to our weekly newsletter, the Crux, where you can hear my thoughts on enterprise data center technologies, uh, every week. com. We have, uh, many great, uh, different ways of getting you the information.
We have a great thing called Minutes to Meltdown, which allows you to do a, uh, uh, a ransomware escape room and, and, and actually engage yourself in what happens during a ransomware attack, as well as more of a deeper level dive into that, which is our cyber recovery, uh, planning workshop. And of course, we will be on site for Commvault Shift coming up on October 9th at 1:00 PM Eastern Time in the United States, uh, and October 10th, uh, in APAC and emea. com/shift to learn more about coming to Commvault Shift.
Thank you for listening to this episode of the Tech Field Day podcast. If you enjoyed this discussion, please subscribe on YouTube or your favorite podcast application so you don't miss an episode. And do consider giving us a rating or a nice review.
This episode was brought to you by Commvault, as well as the Tech Field Day Home IT experts from across the enterprise, part of the Futurum Group. com/podcast or visit us on Techstrong tv. Thanks for listening and we will see you next week.