Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library

Commvault: Practical Cyber Resilience, Data Leak Impact, and Policy Trade‑offs

Truth in IT
11/11/2025
1
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Ransomware Payment Bans, Oracle’s Breach, and the Realities of Cyber Resilience

This episode of the Continuous Compliance Podcast brings Commvault’s Darren Thompson (Field CTO, EMEA) and Jakob Lewandowski (Associate General Counsel, EMEA) into a timely discussion on ransomware, the alleged Oracle breach, and the UK’s proposal to ban ransom payments across public sector and critical infrastructure. Their analysis goes beyond headlines to unpack operational, legal, and policy trade-offs that matter to IT and security leaders.

Why it matters: Ransomware is now a systemic operational risk. Payment bans may change attacker incentives, but only if organizations can reliably recover without paying. The conversation surfaces what readiness actually entails—and the unintended consequences regulators must anticipate.

Oracle’s Alleged Breach: Between Statements and Reality

Thompson notes the reported Oracle incident is “still in flux,” with the truth likely sitting between the vendor’s disclosures and the attackers’ claims. Early signs suggest a traditional (non-cloud) environment may be affected, but the blast radius is uncertain. The larger lesson: even well-resourced enterprises face situational ambiguity during active incidents, complicating communications and recovery decision-making.

On paying ransoms, Thompson’s position is clear: organizations should plan well enough never to face the pay-or-don’t-pay dilemma. In practice, many lack the tested, auditable, minimum-viable-company recovery capabilities to avoid considering payment. He supports Oracle’s stance not to pay but emphasizes that stance only works when recovery and containment plans are robust and proven.

The UK’s Proposed Ransomware Payment Ban

Policy intent: break the payment cycle

Lewandowski frames ransom as an economic system: attack, negotiate, pay, launder, reinvest in more attacks. The UK proposal aims to disrupt that system at the negotiation/payment nodes for public sector and critical national infrastructure, which the government describes as “world leading.” The expectation is that criminal focus will shift away from banned domains, reducing attack frequency and impact in those sectors—though attacks will likely move elsewhere geographically or sectorally.

Compliance and legal realities

Lewandowski stresses: paying a ransom is not regulatory compliance. It does not fulfill notification duties or mitigate liability. Organizations must document decision-making, engage trusted experts, coordinate with law enforcement, and check anti-money-laundering, sanctions, and export-control constraints if payment is contemplated. In jurisdictions with “do not negotiate” policies, enforcement and transparency gaps complicate oversight—another reason regulators are seeking stronger reporting and control mechanisms.

The Hard Case: PII/PHI Extortion and the “Do Not Pay” Stance

What if attackers threaten to leak sensitive citizen data and the ransom is “affordable”? Both speakers maintain a principled “do not pay” position. Thompson cautions that bans only work if victims are prepared—encryption, clear roles, tested playbooks, and rapid recovery are prerequisites. Without readiness, a ban forces organizations into long, painful restores while managing public fallout. Lewandowski highlights that long-term deterrence depends on breaking the payment cycle, even when immediate incentives pull in the opposite direction.

Unintended Consequences Policymakers Must Consider

  • Attack displacement: Criminals may target non-covered sectors or geographies.
  • Underground payments: Bans risk driving negotiations and payments off the books through intermediaries.
  • Delayed reporting and reduced cooperation: Fear of penalties may suppress timely engagement with authorities.
  • Perception of “punishing victims”: Added burdens on already-impacted organizations can create political and practical pushback.
  • One-size-fits-all risk: The impact of disrupting a hospital differs from a library; context-sensitive exceptions may be necessary.

Data Exfiltration: Managing Harm When Control Is Lost

Thompson underscores a persistent blind spot: once data is exfiltrated, downstream use is opaque. The harm profile varies by data type and transparency. Payment rarely guarantees deletion or containment. Practically, post-breach priorities include rapid, clear disclosure; targeted guidance to affected individuals; credential resets; and identity/financial monitoring support. Over time, programs should mature data classification to prioritize protections on high-impact data (e.g., sensitive IP, clinical data) while maintaining strong baselines across the estate.

Resilience Over Blocking-and-Tackling Alone

Prevention and detection remain essential, but neither eliminates the need for recovery at scale. Thompson argues that many organizations perform checkbox exercises rather than realistic, high-stress testing of catastrophic scenarios. Resilience maturity should include:

  • Clear definition of minimum viable company and application/data dependencies.
  • Proven recovery architectures and immutable, isolated backups.
  • Rigorous, scenario-based exercises with executives and operators.
  • Data classification and encryption aligned to business impact tiers.
  • Documented, rehearsed incident response with legal, comms, and law enforcement touchpoints.

Regulatory Evolution: Balance Deterrence and Practicality

Lewandowski expects consultation feedback to split across two themes: raising baseline resilience and recovery capabilities, and tightening controls on negotiations and payments to increase visibility and deterrence. The fine line: avoid creating the optics—and reality—of punishing victims while still cutting off the economic lifeblood of ransomware. Calibrated policy, strong reporting frameworks, and sector-specific readiness programs will be critical to implementation success.

Key Takeaways

  • “Do not pay” only works if you can restore minimum viable operations quickly—invest in tested recovery, immutable backups, and clear playbooks.
  • Ransom payments are not compliance; document decisions, involve trusted experts, and coordinate with law enforcement.
  • Expect displacement effects from payment bans; regulators should anticipate underground payments and reporting friction.
  • Classify and encrypt data by business impact; focus highest protections on the most damaging data types.
  • Run realistic, exec-level resilience exercises—tabletop alone is insufficient for real-world recovery pressure.

Conclusion: What This Means for IT Leaders

Ransomware is as much an economic and operational problem as it is a technical one. Payment bans can curb attacker returns, but only if organizations—and especially public sector entities—are prepared to recover without paying. For IT leaders, the mandate is clear: shift from checkbox prevention to demonstrable resilience. Build recovery muscle memory, classify and protect high-impact data, document decision pathways, and align executives around tested playbooks. The organizations that operationalize resilience—not just security—will be best positioned to weather policy shifts and the next inevitable incident.

Categories:
  • » Cybersecurity Webinars » Backup & Recovery
  • » Data Management » Data Storage
  • » Cybersecurity Webinars » Data Security
  • » Cybersecurity Webinars » Identity & Access Management (IAM)
Channels:
News:
Events:
Tags:
  • commvault
  • cleanroom
  • backup
  • security
  • data
  • protection
  • compliance
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Commvault: Practical Cyber Resilience, Data Leak Impact, and Policy Trade‑offs

              Upcoming Webinar Calendar

              • 11/12/2025
                12:00 PM
                11/12/2025
                Zendesk Customer Spotlight [Pure Insurance]: How to Scale Employee Service from IT to HR
                https://www.truthinit.com/index.php/channel/1545/zendesk-customer-spotlight-pure-insurance-how-to-scale-employee-service-from-it-to-hr/
              • 11/12/2025
                10:00 PM
                11/12/2025
                Transforming AI Buzz into Real Business Value with Druva
                https://www.truthinit.com/index.php/channel/1555/transforming-ai-buzz-into-real-business-value-with-druva/
              • 11/13/2025
                05:00 AM
                11/13/2025
                Transforming AI Buzz into Tangible Business Value with Druva
                https://www.truthinit.com/index.php/channel/1554/transforming-ai-buzz-into-tangible-business-value-with-druva/
              • 11/13/2025
                12:30 PM
                11/13/2025
                Insights from a Certified CMMC Assessor: Sidestepping Common Assessment Pitfalls
                https://www.truthinit.com/index.php/channel/1536/insights-from-a-certified-cmmc-assessor-sidestepping-common-assessment-pitfalls/
              • 11/13/2025
                01:00 PM
                11/13/2025
                Advancements in Click Fraud Defense: Insights from LinkedIn and HUMAN for Budget and Campaign Protection
                https://www.truthinit.com/index.php/channel/1583/advancements-in-click-fraud-defense-insights-from-linkedin-and-human-for-budget-and-campaign-protection/
              • 11/13/2025
                01:00 PM
                11/13/2025
                Partner Sales Dialogue: Transform AI Trends into Tangible Business Value with Druva
                https://www.truthinit.com/index.php/channel/1556/partner-sales-dialogue-transform-ai-trends-into-tangible-business-value-with-druva/
              • 11/18/2025
                01:00 PM
                11/18/2025
                HUMAN Dialogue: Fostering Trust Amidst Agentic Commerce Dynamics
                https://www.truthinit.com/index.php/channel/1582/human-dialogue-fostering-trust-amidst-agentic-commerce-dynamics/
              • 11/18/2025
                01:00 PM
                11/18/2025
                Microsoft Advanced Group Policy Management (AGPM) End of Life: Your Practical Migration Playbook
                https://www.truthinit.com/index.php/channel/1579/microsoft-advanced-group-policy-management-agpm-end-of-life-your-practical-migration-playbook/
              • 11/20/2025
                05:00 AM
                11/20/2025
                Druva: Prove you can outsmart ransomware in this virtual cyber recovery simulation!
                https://www.truthinit.com/index.php/channel/1619/untitled-channel/
              • 11/20/2025
                11:00 AM
                11/20/2025
                Trend Micro Webinar: Smarter Decision Making via Network Intelligence
                https://www.truthinit.com/index.php/channel/1372/unlocking-network-intelligence-for-smarter-risk-decisions/
              • 11/20/2025
                12:00 PM
                11/20/2025
                360View: Budget Optimization: Doing More with Less
                https://www.truthinit.com/index.php/channel/932/360view-budget-optimization-doing-more-with-less/
              • 11/20/2025
                12:00 PM
                11/20/2025
                CMMC Certification: Next Steps for Continuous Monitoring and Management
                https://www.truthinit.com/index.php/channel/1558/cmmc-certification-next-steps-for-continuous-monitoring-and-management/
              • 11/20/2025
                01:00 PM
                11/20/2025
                Rethinking Hybrid Access: Securing Users, Vendors, and Infrastructure in the Zero Trust Era
                https://www.truthinit.com/index.php/channel/1612/rethinking-hybrid-access-securing-users-vendors-and-infrastructure-in-the-zero-trust-era/
              • 12/04/2025
                12:00 PM
                12/04/2025
                CMMC Level 2 Assessment Insights: Expectations from an OSC and C3PAO Assessor
                https://www.truthinit.com/index.php/channel/1557/cmmc-level-2-assessment-insights-expectations-from-an-osc-and-c3pao-assessor/
              • 12/09/2025
                01:00 PM
                12/09/2025
                Energize Your Connections with Netskope and Presidio Collaboration
                https://www.truthinit.com/index.php/channel/1553/energize-your-connections-with-netskope-and-presidio-collaboration/
              • 12/10/2025
                01:00 PM
                12/10/2025
                The Next Generation of Managed Data Security Services
                https://www.truthinit.com/index.php/channel/1620/cyera-the-next-generation-of-managed-data-security-services/
              • 12/10/2025
                10:00 PM
                12/10/2025
                Enhancing Revenue Opportunities: Bridging Gaps with Druva’s Microsoft Expansion in APAC
                https://www.truthinit.com/index.php/channel/1624/enhancing-revenue-opportunities-bridging-gaps-with-druvas-microsoft-expansion-in-apac/
              • 12/11/2025
                05:00 AM
                12/11/2025
                Maximize Revenue Potential: Address Gaps with Druva’s Microsoft Expansion
                https://www.truthinit.com/index.php/channel/1625/maximize-revenue-potential-address-gaps-with-druvas-microsoft-expansion/
              • 12/11/2025
                12:00 PM
                12/11/2025
                Secureframe: Addressing the Top 5 Compliance Challenges for Startup Leaders and Solutions
                https://www.truthinit.com/index.php/channel/1526/addressing-the-top-5-compliance-challenges-for-startup-leaders-and-solutions/
              • 12/11/2025
                01:00 PM
                12/11/2025
                Enhance Revenue Streams: Address Gaps with Druva's Microsoft Expansion Solutions.
                https://www.truthinit.com/index.php/channel/1623/enhance-revenue-streams-address-gaps-with-druvas-microsoft-expansion-solutions/
              • 12/18/2025
                12:00 PM
                12/18/2025
                360View: 2026 IT Predictions & Emerging Trends
                https://www.truthinit.com/index.php/channel/933/360view-2026-it-predictions-emerging-trends/

              Upcoming Spotlight Events

              • Nov
                18

                Microsoft Advanced Group Policy Management (AGPM) End of Life: Your Practical Migration Playbook

                11/18/202501:00 PM ET
                • Nov
                  20

                  Rethinking Hybrid Access: Securing Users, Vendors, and Infrastructure in the Zero Trust Era

                  11/20/202501:00 PM ET
                  • Dec
                    10

                    The Next Generation of Managed Data Security Services

                    12/10/202501:00 PM ET
                    More events

                    Upcoming Industry Events

                    • Nov
                      12

                      Zendesk Customer Spotlight [Pure Insurance]: How to Scale Employee Service from IT to HR

                      11/12/202512:00 PM ET
                      • Nov
                        12

                        Transforming AI Buzz into Real Business Value with Druva

                        11/12/202510:00 PM ET
                        • Nov
                          13

                          Transforming AI Buzz into Tangible Business Value with Druva

                          11/13/202505:00 AM ET
                          More events

                          Upcoming 360 View Events

                          • Nov
                            20

                            360View: Budget Optimization: Doing More with Less

                            11/20/202512:00 PM ET
                            • Dec
                              18

                              360View: 2026 IT Predictions & Emerging Trends

                              12/18/202512:00 PM ET
                              More events

                              Recent Spotlight Events

                              • Oct
                                22

                                Cut Ticket Resolution Time in Half with Smarter IT Documentation

                                10/22/202501:00 PM ET
                                • Oct
                                  15

                                  Managing Human Risk in an AI-Driven Threat Landscape: Are Your Defenses Evolving Fast Enough?

                                  10/15/202501:00 PM ET
                                  • Sep
                                    16

                                    KnowBe4: Beyond DMARC: Closing Critical Gaps in Your Email Security Shield

                                    09/16/202501:00 PM ET
                                    More events

                                    Recent Industry Events

                                    • Oct
                                      30

                                      Rethinking Secure Access Beyond VPN and NAC for a Zero Trust Era

                                      10/30/202512:00 PM ET
                                      • Oct
                                        30

                                        Rethink secure access solutions in a zero trust landscape beyond VPN and NAC.

                                        10/30/202506:00 AM ET
                                        • Oct
                                          29

                                          Practical Strategies for Platform Engineering in the AI Era

                                          10/29/202512:00 PM ET
                                          More events
                                          Truth in IT
                                          • Sponsor
                                          • About Us
                                          • Terms of Service
                                          • Privacy Policy
                                          • Contact Us
                                          • Preference Management
                                          Desktop version
                                          Standard version