Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Commvault: Cyber Recovery with Threat Intelligence & Cleanrooms

Commvault
06/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hello, everybody. Welcome to the Accelerate Cyber Recovery with Incident Response, Threat Intelligence, and Cleanroom session. My name is Dave Cunningham. I'm part of the product manager team at Commvault. I work on our cybersecurity solutions like our threat detection platform and security integrations, and I'm here with Dinesh. How are you doing, Dinesh? Hey, thanks, David. Hey, everyone. My name is Dinesh Reddy. I'm part of the product management team at Commvault, and I manage our recovery solutions. So let's get started here, and we're going to talk about cyber resilience. So NIST clearly outlines the structure around cyber resilience, the ability to anticipate, withstand, recover, and adapt your organization, bring your business back, bounce back from all different types of threats or disasters. The conversation of cyber resilience becomes very nuanced once you start considering the evolving threat landscape, and we're going to talk a little bit about some of the advanced capabilities that we offer within our platform to not just provide the resilience, provide the intelligence, and the way to be ready to bounce back in the event of a cyber attack. The reality is that even though organizations have a strategy to be prepared for cyber recovery and being cyber resilient, they usually lack the confidence in their strategy, and this is shown in the numbers. More than half of the organizations don't have confidence in their recovery, and they don't have confidence that if something happens to their environment, they'll be able to securely recover their resources. In fact, there's a 97% higher risk of recovery failure because organizations have not regularly tested their cyber recovery plans and processes, and they start seeing gaps in their plans during the cyber incident. They might not even know if their backups are clean or if they are infected. Yeah, and also, I think there's a key part to this that we need to bring out is that 55% of organizations have siloed security and IT technology stacks, and that's a super important problem to call out here because when you're talking about a resiliency solution like Commvault, having it disconnected from a security platform or from the intelligence that a security platform can offer kind of cripples you from being able to recover in an optimal state. So that's an important problem that organizations are facing today as well. Yeah, in fact, this gap between the teams, the silos, adds delays which in turn increases the mean time to recover. Organizations today, I think there's that traditional recovery type of a plan that organizations have been using for quite some time now. I think the traditional recovery plans that a lot of organizations are using don't quite meet the needs of the threat landscape today, how cyber threats are impacting organizations today. And so we really advocate for this concept of cyber recovery plans, the ability to not only test your recoveries but also introduce some sort of threat intelligence as part of that So when you restore blindly back into the environments, there's a potential of reintroducing risk in the environment. The data protection platform is continuously protecting data and at any given time there could be threats protected along with that within the Commvault platform with any data protection platform. And by restoring blindly into the environment, you could be reintroducing the vulnerabilities. And also like rolling back is a concept that we hear quite a bit from organizations. When they have a cyber incident and they want to recover their data, they go back in time and that process of going back in time and recovering from an older snapshot maybe a week ago, it leaves some data behind. It's kind of putting their business at risk of fully recovering. So being able to analyze for threats as part of a recovery test or as part of a cyber recovery plan is super important. Absolutely, I think you're spot on. The big difference between traditional recovery plans and cyber recovery is that in traditional recovery, there is no malice. In a natural disaster, there's no malice. There's no bad actor that is trying to do bad things in your environment. Your site is down, you're just recovering your site and you're not worried if your data is infected or corrupted or encrypted. But cyber recovery is more complex than that. You need to ensure your backups are clean. And then you need to ensure you're able to validate those backups in an isolated environment before you actually bring them into your newly rebuilt production so that there's no reinfection. And that's where our solutions help customers to do this in a streamlined way. So let's kind of get into that a little bit deeper. So let's take a look at just like a high level of the platform, like where the platform comes into play, what we've built into the platform to kind of help customers with these problems. So it starts with the resiliency platform, the Commvault platform. And we offer that immutable layer using our core platform. So the storage in AirGap technologies that we have in the product. And that's super important because first and foremost, we need to protect the data and that data needs to be So we have that out of the box. And then the integration with the recovery response orchestration and security tool sets is also super important. But what we've done here at this middle layer is we've introduced additional technologies that kind of streamline and break down those silos and bring in the threat intelligence as part of the recovery test process. So first and foremost, to get that clean recovery point, right? And we define clean recovery point or clean point detection as the ability to detect if there's threats within the data that's protected. And also be able to get the last known good version of that data, minimizing the rollback of your recovery. So we have signals that we get from our security partners through integrations like with our CrowdStrike and others, as well as built in intelligence that comes right out of the box that our customers don't have to introduce any additional technologies. Those intelligence will provide you with the insight into analyzing your data for malware and encryption threats. And this is the first step in getting to that clean point detection. So I often like to say, you don't know how effectively you can recover until you recover. And you never want to be in a situation where you need to recover and you can't effectively recover. It's really important to consistently test your data, test your ability to recover, also to validate that your data is in a good state. The threat intelligence component of it is super important. It's going to give you that accurate validation that your recoveries, that you not only are able to recover your data, but you can recover it in that accurate state, that good state, that clean state. And you're getting the latest good versions of your files back. So unifying the security tool sets and the resiliency tool sets, the security tool sets with that recovery orchestration is super important. It'll help reduce response times. So let's double click on this concept of synthetic recovery. This is something new that we've launched. And this is something that only we're doing in the market today. So this concept is really simple, where we use the intelligence in our platform. Like I mentioned before, we have malware detection in our platform, utilizing a signature-based engine, machine learning. And we also integrate with Slack tools, like VR rules and hashes for additional intelligence as well. So the first step is to find malware in the backup content. Next step is we use our AI engine to detect encryption. So we have a proprietary model for detecting encryption states within the backup content. And all of this information, we store in our index. And when we do this, we're able to pinpoint which files are impacted by threat and which files aren't. And you can see in this illustration on the left side, I have multiple different data protections, backups that occurred over a period of time. And then as the cycle kind of moved on, we have various threats popping up, files getting impacted, malware getting introduced. And then on the right side, when I actually do my synthetic recovery, we will automatically with one click, we will synthesize or grab all the latest versions of those data across the backups, find the last good ones across the backups and use that for a recovery point. And we quarantine the malware by default. So basically we're providing a clean recovery and we're minimizing the rollback, which is solving some of the problems we talked about earlier. So I'm going to pass it off to Dinesh, and he's going to talk about how we take that clean recovery point and we move this and orchestrate this into the recovery process itself. Thanks, David. So as you mentioned, right now, we have identified a clean point through various threat signals, scanning of backups. The next step would be to validate this data in a secure, isolated environment without actually compromising your production that you're rebuilding. And you should always validate your applications inside an isolated clean room before recovering into your newly rebuilt production so that you minimize the infection. And one of the key steps during this validation process is to repave your servers, right? This is by completely removing your operating system and rebuilding the server from a custom golden image that has been validated and harder, right? So that you always start from a known good state. Once the application has been thoroughly tested and validated inside this isolated clean room, now you're ready to promote this application into the production environment. In the next couple of minutes, we will learn how clean room recovery helps you do this, right? In a streamlined manner. I really like this quote from Mike Tyson, right? So it really resonates with what we are trying to with our solutions, right? He said, everyone has a plan until they're punched in the face, right? And this definitely applies to cyber recovery and resilience. Every organization thinks they have a plan and most organizations might have a plan for a cyber recovery. But however, when they're hit with an incident, right? So within the first five minutes of this cyber event, right? They need to be able to certainly answer questions such as, is the attacker still active, right? What data can we trust? What are the next steps that I need to take, right? So, and of course, having a paper playbook helps here, but the real confidence comes when there is orchestration, right? When you are able to codify the steps that you need to perform, when you have defined it's checks and run this, run the same sequence of steps again and again, every week and build that muscle memory. So that when something happens, you're able to quickly execute each of those steps, right? That's cyber resilience in action, right? And clean room recovery helps solve this, right? This is how clean room recovery works, right? So you have your production environment on the left side, which is your typical production environment. You have your file shares, you have your VMs, you have your database servers, right? And of course, your environment would be a hybrid environment, which is segregated across clouds and on-premises. And then we have the backup infrastructure, which is a Commvault cloud control plane, right? Which orchestrates the process of protecting your applications. A key component of a cyber resilient architecture is to have an offsite copy of your applications data in AirGap Protect, right? This ensures that even if your entire production is completely gone, you have a safe copy of your applications stored away in AirGap Protect, using which you can recover your applications. And if you want to do a recovery testing, or you want to do a forensic analysis, or you are in an cyber event and you're trying to recover, right? The first step is to actually recover your control plane, because during any real cyber incident, even before the applications are infected, the bad actors would destroy your backup infrastructure, your recovery infrastructure, especially if they are deployed within your production environment. And clean room recovery orchestrates the process of recovering the control plane. With just a couple of clicks, we'll be able to recover your control plane and post it within our infrastructure so that you can log into this newly recovered control plane and start recovering your applications into an isolated clean room. And this isolated clean room can be created either in an AWS environment, in an Azure environment, or even in your own on-prem data center, on-prem IRE environment. At its core, clean room recovery is an orchestration platform, right? So it helps orchestrate recovering the control plane. It helps create an on-demand isolated clean room in which you can recover your applications and start validating them before promoting to your production environment. Now let's see how threat detection, clean room work, and how these two synergize to help you recover from a cyber event. So to help you identify threats, to help you recover an infected resources into a clean room for validation in our live demo. In the new installment of clean room recovery, I want to first walk through this dashboard. So we are introducing this new dashboard to give a quick preview on how your environment is recovery ready, right? So it has information like clean room recovery readiness. It shows you how many of your protected resources are actually ready to be recovered into the clean room, how many are not ready, and how many are not configured for clean room recovery. You also show information about why resources are not ready for clean room recovery, because you might not have an ATP backup copy for those resources, or you have selected a different region for clean room, right? And that region does not have an ADP backup. It also shows information about when was the last recovery drill conducted for each of your recovery groups, and it will show you license usage information as well as active clean rooms by region if you have a distributed environment. From here, let's go into recovery groups. A recovery group is a container, right? It's a logical grouping of your resources that you want to recover into a clean room. Let's create a new one. So I'll say add recovery group. I'm going to give it a name, transaction application, because I want my transaction application to be recovery ready. Click next. And now you can add your resources into this group that form your transaction application. There are multiple ways you can add resources. You can add a rule saying that add all resources that are owned by XYZ person or add resources that have a tag XYZ, right? So you can define what those rules are. And based on those rules, the resources will be added into the clean room. Or you can manually select and add resources into into the same recovery group here. So you can see we'll show you all the resources that are protected by Commvault cloud. And you can pick and choose what resources you want to add into the recovery group called transaction application. And one thing that I want to highlight here is that so we have added support for Active Directory forest, right? So now you will be able to add an entire Active Directory forest into a recovery group and then execute recovery into a clean room so that you can validate your end to end applications. I'm selecting an Active Directory forest, a couple of VMs and a couple of Azure file shares. I'm going to add all of this into the recovery group and then execute a recovery into a clean room. Next, review your settings in the summary page. And then as soon as you're done with your creation of a recovery group, the next step in the process is to create a runbook for executing your clean room because so you can just say create and start adding a runbook. This will take you to the next flow of configuring and creating a runbook. I'm going to give a name for it. I want to create a forensic runbook for my transaction application. And as part of this runbook, I want to enable that scanning, right? What this means is if you toggle this option, we will automatically scan the resources that are recovered into the clean room for any malware, right? And it will show up in your runbook status if there's any malware detected. So let's enable that scan and then go further. And here you have an option. If you have pre-created a clean room target or a clean room site, you can just select, use an existing clean room. But if you want us to create a new clean room, you can just opt in for new clean room and then go next. And you can select where you want to create your clean room, either in AWS or Azure. I'm going to select Azure for this demo. Click next. Let me give a name for this clean room, Azure West US clean room. And then click next. And this is where we have simplified the process of creating a clean room, right? We have introduced this option called express configuration. What this does is with a single sign in into your Microsoft account. So we will be able to create all the necessary infrastructure and resources that are required to create an on-demand clean room before recovering the resources into it. So previously you had to pre-create certain resources in your Azure account such as an Azure app, give the necessary roles and permissions, create resource groups and a VNet, and then come back and configure your clean room recovery. But we have taken away all of those prerequisites by introducing this express configuration option. Because once you sign in with your Microsoft account, we'll be able to create everything that is required to successfully execute a clean room recovery. And of course, if you have pre-created some of those resources, you can always opt in for a custom configuration. So let's do an express configuration to show you how easy it is to create an on-demand clean room. So we automatically fetch all the subscriptions that are there inside your Microsoft tenant. I'm going to select this for my clean room recovery purpose and click next. Quick review on all the settings that you have selected and then click create. So as you can see, the system has automatically generated a step-by-step runbook for your clean room recovery purpose. And one of the steps here is deploy clean room. And this runbook gives you a lot of flexibility. You can add and remove steps if you need. So let's say I want to add a step before this or after deploying a clean room, you'll be able to do that. And if you expand the deploy clean room phase, it will show you all the inner steps that we execute as part of this phase. So because you have opted in for deploying a new clean room, we will automatically create the necessary infrastructure such as a resource group, the networking resources, the storage account, all of that before actually recovering the resources into it. And the resources, if you expand the phase three, which is basically recovering your resources, you can see that we have added an Active Directory forest and we have a couple of VMs that have been added for recovery. And one of the steps inside the recovering the VM is repaving. This is an advanced capability that helps you repave your entire virtual machine using a custom hardened golden image before recovering the data into it. This allows you to start from a known state even before the data has been recovered inside the clean room. So now let's execute the runbook, select a backup point or a recovery point that you want to use to recover your applications and then click submit. Now, this starts the clean room recovery process and you can monitor the status right within the runbook page. You don't need to go anywhere else to monitor the status and it will show you at a phase by phase like which phase is being executed and how much has been completed. And let's say there are certain manual steps that you have added and which require acknowledgement. They will be highlighted here saying that there's a one step that is waiting for user input. You'll be able to click here, which will filter the steps to show you which step is waiting for user input. You can say acknowledge and then submit. And this takes the runbook to completion. Right now, the entire clean room recovery has been executed and your resources have been recovered into an on demand clean room that has been created in your Azure subscription. Now you can give access to this clean room to your security operations team or your applications team so that they can validate the resources. And of course, right, so once you're done with your validation and you're ready to like clean up your resources, you can just say reset runbook and this will automatically perform the cleanup operation of all the resources that have been created by us in your Azure subscription. So there are no dangling resources that could cost you. As you can see, right, we have simplified the entire process of creating an on demand clean room and then recovering the resources into it. Now, my colleague, David, will walk you through how easy it is to execute a recovery during a cyber event. When an event has been detected, when a malware has been detected within your environment, how easy it is to detect it and recover that infected resources into a clean room for any kind of analysis. David, over to you. All right, so we're going to take a look at the new threat detection dashboard and take a look at how easy it is to detect threats within your data protection environment to drive the clean recovery into the clean room environment. So you can see right here we have the new dashboard and on the the various different signals that we're detecting within the data protection environment. We scan data on a scheduled basis or you can scan data automatically when there's various anomalies occurring as well as on demand. So there's a very flexible scanning type modes available in the new solution. And when we detect threats, we correlate those insights, including partner insights, into this dashboard to assign risk levels to it. So you can see we have some critical risk resources, high risk resources, medium and low risk resources. Then on the right side, we have the results overview and this is giving you the input or the insights into what data has been looked at and what Commvault has done with that data from a threat perspective. So it's telling you you have a bunch of clean data that we've detected, we've scanned through and data that is impacted. So you can see we have some impact here and we'll dig deeper into this to see how to recover from it. And then below we have operational components of the threat detection platform. So let's go ahead and double click into some of the critical resources to kind of get an idea of what's going on here. So I'm going to click on the tile and you can see I have a bunch of resources here that are in critical status, which means that there's malware detected amongst other things within the data protection and recovery points. I can click on the various different components here. So we have anomalies for this particular system here that are being triggered and this is using Commvault's machine learning. As we're protecting the data, we look at the various different changes that are happening on that system and we will generate the event on the dashboard. Next up we have partner signals. So we have multiple different integrations where we ingest signals from our partners like CrowdStrike, NetScope, and DarkTrace to name a couple or name a few. And these signals are providing an indicator of an attack or kind of like a behavior that's happening on the resource that we map to a recovery point to help the user kind of see if there's an impact on that system. And we'll kind of look at that in more depth a little bit later. And then lastly we have threats and this is using our multi-layer scanning engine, our threat scan engine, where we detect malware using signature-based engine, machine learning, and we have an AI model for detecting encryption. We've also built in Yara and hash support for this new product release to give SOC analysts the ability to inject their own intelligence into the platform to find malware threats. On the right side we have various different actions. So you can mark this resource safe, you can quarantine it, you can disable it from data aging, which preserves the previous data protection jobs from pruning off. So if you ever need to go back in time, those data points will still be there, they'll be intact, they won't prune off, they won't age off, you know, they'll always be there for either forensics or recovery purposes. You can hunt for threats, which is an on-demand scan if you want to inject new intelligence into the platform. We've even introduced APIs for doing hash scanning, so you can use hashes to look for known threats within the data protection environment. And then of course restore. So we'll get to that in a second. Let's dig into a little bit more of the details on what's with this system. So I'm going to click on the resource and this is going to take me to the overview dashboard. So this is the overview of the resource. So I get to see all the signals that are being triggered for this particular system and I can see it on these trending lines. And the trending lines are really good for kind of pinpointing when the issue first started, when the infection first started happening within the data protection jobs. And, you know, this kind of view could be complicated or could be have a learning curve. So what we've done is we've incorporated AI around all of these different signals. So you can use our RLE insights to get a summary of what's going on for this particular resource or even at a global level. And it'll give you all the context around what's been detected and what to do, you know, the recommendations to do. So at a minimum, this is all you really have to do to understand what's the next steps. All right. So moving along, we're going to go to the anomalies tab. All right. If you're continuing your investigation, you want to understand what files are anomalous, you would go to this tab here. And then next we have our threats tab. And this is going to give you an overview of the various malware and encryption that was detected using our multi-layered engine. And once again, just to reiterate, we have the malware engine that utilizes signature-based scanning, machine learning, as well as YARA and hashes. And then we also have an AI encryption model for detecting encryption with high levels of accuracy. And it's trained on what an encrypted file looks like versus what a clean file looks like. So right here, we can click on the one particular threat that was detected and get more details. And once again, like I mentioned before, we use RLE across the interfaces in the dashboard to give you like the context that you need. You can get more details on this threat, including hashes and, you know, in the details of this particular impact. And then lastly, we have partner signals. So I mentioned before that we integrate with several different security partners. We ingest the signals into our platform. These would be indicators of attack or early indicators of malicious behavior happening, potentially malicious behavior happening on those systems. And we map these to the recovery points, as you can see here, these recovery times. And this tells the user that at these particular times, there was some sort of malicious activity that occurred on those systems. And therefore, this signal kind of drives the outcome of you should scan it or if there's other different signals going on that there might be an impact to your recovery point. We also integrate with CrowdStrike NextGen SIM. This is something new. And right here, you can see in the CrowdStrike NextGen SIM that we're sending signals to the SIM platform. And this is great to provide enrichment for the SOC analyst. And you can see one of the insights here is our risk analysis insight. And this is telling the SOC analyst that there was sensitive data discovered on this particular system. Now, this is very important, because if you have threat signals being triggered, as well as sensitive data triggers, that's going to kind of raise the alarms. You really want to take a look at the system to make sure everything is okay. Now, we don't share any sensitive data information. We just provide the information that the system had some policy violations based on how risk analysis is configured. Those policy violations can be customized, as well as specific to certain types of data sets. And then, of course, in addition to the sensitive data discovery, we also send signals, such as any of the threats that were detected from our scanning capabilities. And so, we've sent over some information to the NextGen SIM, so the SOC analyst can get those notifications. All right. So, now let's do a recovery. We'll go back to the system. We'll go to restore. And right here, we have three different restore options. Number one is manual. And this would be if you wanted to select a clean recovery point. You can see here that we're actually detecting the clean recovery points, and we're telling you which ones are impacted by threats with the indicator here, the triangle. And we even break it down, like what kind of threats are in those recovery points. Now, if I did a recovery by clicking the recovery point, as an example, on the 25th, and I did a recovery from there, I could potentially be leaving good data behind because I have two more recovery points after it that even though are infected, maybe not all the data is infected. So, there would be some level of rollback. And that's why we introduced this feature, what we call it our synthetic recovery feature. Our synthetic recovery feature, it composes the recovery point by taking the latest recovery point that's available, understanding what's infected by our scanning technologies, and then going back in time, pulling the good versions of the files across the backup sets to kind of so it minimizes the rollback. We're going to use this option. You can see here, we even give you the information as to how much data is actually being rolled back and how much is coming from the latest update or the latest recovery point. And briefly, I want to mention the forensic option. This is an option wherein you can recover the infected data, and we only allow this recovery to go to clean room or out of place, and you can use this for investigations and forensics. So, right now, we're going to pick the synthetic recovery option. Next, this is where some of the other innovations have come into place. Clean room is fully integrated as a recovery location, so you no longer have to jump through hoops to get your data into the clean room for further investigation. So, I'm going to pick the clean room option, and we're going to do the synthetic recovery to the clean room, and I'm going to pick the existing clean room that Dinesh created in his demo, and we're going to go ahead and restore, and that infected system is going to do a full clean recovery of that system to the clean room so we can do that last step validation in the clean room before you put that data back into production so you have optimal recovery. So, now that we have seen the demo of how the product works, how easy it is to spin up an on-demand clean room, test your cyber recovery readiness, and when you're in a cyber event, how quickly and effectively our threat detection platform will be able to identify what threats are there within your backups and help you recover using minimal data loss, right, using our synthetic recovery. If there is one thing that I want you to remember from this session is this slide. It shows the end-to-end journey from recovery readiness into clean production recovery, all in a single integrated flow, right? We start with readiness. It's all about configuring and setting up regular scanning of your backups and continuously monitoring critical workloads if they are clean or not. So, once that is done, the next step would be to do a recovery testing. Use the clean room functionality to schedule and validate your cyber recovery plans and process so that you uncover any gaps that could be there so that you are prepared when an actual event happens. The KPIs here are simple. You scan your backups, ensure that all your critical workloads are covered, you test frequently, ensure that your cyber plan has been thoroughly vetted and there are no gaps, and then you're ready to move on to the next step. Absolutely. And part of that planning, that planning phase and that readiness phase is, you know, the scanning policies, the scanning plans that you have in place. This is all background operations and we utilize the signals automatically for you. Our anomaly engine, you know, the malware detection encryption engine like we talked about before, and all the SOC tools from their integrations as well as integrated tool sets. These are all things working for you automatically in the background, detecting whether or not there's any threats within your protected data and easily getting to that clean point for that clean point recovery. And we talked about synthetic recovery, which is one of the key capabilities of our product, which is it's not only about getting that clean recovery back, it's also about optimizing that clean recovery in the sense that we're not rolling back to a previous point in time to get your clean data. So it's a fully optimized clean recovery point. And then this is where the magic happens, where now you have your clean synthetic recovery, you can send it over to your clean room for those next operational steps and validation steps. Exactly. And during that process, when you're doing this recovery into the clean room, you can apply additional layers of security to ensure it is truly clean. For example, you'll be able to repay the entire operating system by ripping out the operating system, bringing in a new custom golden image, and then rebuild the server using that image before recovering the data into it. And finally, once all of this validation has been completed and you have a crisp go or no go decision from the security teams, you are ready to move these clean applications from the clean room into a new production environment. The net result is like you have a clean, validated, repaved applications that have been restored with minimal data loss and as efficiently as possible with your new production. All right. So that wraps it up. I hope everybody enjoyed this session and learned something. And we look forward to having further conversations with you, especially our customers and any of you that have any additional questions. So thank you from me and Dinesh.

TL;DR

  • Traditional disaster recovery plans fail in cyber incidents because they assume no malice—cyber recovery must validate backup integrity, avoid reinfection, and account for corrupted or encrypted data.
  • Commvault's synthetic recovery composes clean recovery points by pulling the latest good file versions across backup sets, minimizing rollback while eliminating infected data through multi-layered threat scanning.
  • Cleanroom recovery automates the process of validating applications in isolated AWS, Azure, or on-prem environments, including server repaving with hardened images, before promoting to production.
  • The platform unifies threat intelligence from malware engines, ML anomaly detection, AI encryption models, YARA/hash scanning, and SOC integrations (CrowdStrike, Netskope, Darktrace) to identify clean recovery points.
  • Organizations achieve cyber resilience through continuous scanning, regular cleanroom testing, and codified runbooks that orchestrate the complete recovery workflow—from threat detection to validated production restoration.
  • Over 55% of organizations lack cyber recovery confidence due to untested plans, siloed IT/security teams, and 97% higher failure risk without regular testing—Commvault addresses these gaps with automated orchestration.

Why Traditional DR Fails in Cyber Incidents

The session opens by establishing the gap between traditional disaster recovery and cyber recovery requirements. Dave Cunningham and Dinesh Reddy explain that over 55% of organizations lack confidence in their cyber recovery capabilities, primarily due to siloed IT and security teams, untested recovery processes, and the inability to verify backup integrity. Traditional DR assumes no malice—natural disasters don't encrypt data or leave backdoors. Cyber recovery, by contrast, must account for corrupted, encrypted, or infected backups. The speakers emphasize that 97% higher recovery failure risk exists when organizations don't regularly test their plans, and that blind restoration from backups can reintroduce threats into production environments.

Clean Point Detection and Synthetic Recovery

Commvault's approach to identifying the last known good recovery point combines multiple threat intelligence layers: signature-based malware engines, machine learning anomaly detection, AI-driven encryption models, YARA rules, hash scanning, and signals from integrated SOC tools like CrowdStrike, Netskope, and Darktrace. The platform continuously scans protected data and indexes threat findings, enabling what Commvault calls synthetic recovery—a unique capability that composes a clean recovery point by pulling the latest good versions of files across multiple backup sets. This minimizes rollback while ensuring no infected data is restored. The demonstration shows how the threat detection dashboard correlates anomalies, partner signals, and malware insights to assign risk levels and guide recovery decisions.

Cleanroom Recovery Orchestration

The cleanroom recovery workflow automates the process of validating applications in isolated environments before promoting them to production. Dinesh demonstrates creating recovery groups, defining runbooks with codified steps, and deploying on-demand cleanrooms in AWS, Azure, or on-premises environments. A key innovation is express configuration, which eliminates manual prerequisite setup by automatically provisioning necessary Azure or AWS resources through a single sign-in. The platform orchestrates control plane recovery from air-gapped storage, repaves servers using hardened golden images, recovers applications into the cleanroom, and provides monitoring dashboards for validation. Once security teams confirm applications are clean, the runbook promotes them to rebuilt production, with automated cleanup to avoid lingering cloud costs.

End-to-End Cyber Resilience Workflow

The session concludes by mapping the complete journey from readiness to clean production recovery. Organizations start by configuring continuous backup scanning and monitoring critical workloads. Regular cleanroom testing builds muscle memory and uncovers gaps in recovery plans. When an incident occurs, the threat detection platform identifies compromised systems, synthetic recovery generates optimized clean points, and cleanroom orchestration validates applications in isolation before production promotion. The speakers position this as a unified flow that breaks down IT/security silos, reduces mean time to recover, and provides the confidence that comes from tested, automated, and intelligence-driven recovery processes. They emphasize that cyber resilience requires orchestration, not just backups—codified runbooks that can be executed repeatedly under pressure.

Chapters

0:00 - Introduction to Cyber Resilience
3:04 - Understanding Cyber Recovery Challenges
5:55 - Role of Threat Intelligence
8:36 - Innovations in Cyber Recovery
11:50 - Cleanroom Recovery Explained
14:34 - Integrating Threat Detection
17:11 - Creating Recovery Groups
20:25 - Executing Cleanroom Recovery
23:03 - Monitoring and Validating Recovery
25:48 - Final Thoughts on Resilience

Key Quotes

3:44 "By restoring blindly into the environment, you could be reintroducing the vulnerabilities."
4:41 "The big difference between traditional recovery plans and cyber recovery is that in traditional recovery, there is no malice. In a natural disaster, there's no malice. There's no bad actor that is trying to do bad things in your environment."
8:12 "This concept is really simple, where we use the intelligence in our platform... we're able to pinpoint which files are impacted by threat and which files aren't."
9:21 "We will automatically with one click, we will synthesize or grab all the latest versions of those data across the backups, find the last good ones across the backups and use that for a recovery point. And we quarantine the malware by default."
11:11 "Everyone has a plan until they're punched in the face, right? And this definitely applies to cyber recovery and resilience."
12:17 "The real confidence comes when there is orchestration, right? When you are able to codify the steps that you need to perform, when you have defined it's checks and run this, run the same sequence of steps again and again, every week and build that muscle memory."
14:18 "At its core, clean room recovery is an orchestration platform, right? So it helps orchestrate recovering the control plane. It helps create an on-demand isolated clean room in which you can recover your applications and start validating them before promoting to your production environment."
18:48 "We have introduced this option called express configuration. What this does is with a single sign in into your Microsoft account. So we will be able to create all the necessary infrastructure and resources that are required to create an on-demand clean room."
21:08 "This is an advanced capability that helps you repave your entire virtual machine using a custom hardened golden image before recovering the data into it. This allows you to start from a known state even before the data has been recovered inside the clean room."
28:51 "We have the malware engine that utilizes signature-based scanning, machine learning, as well as YARA and hashes. And then we also have an AI encryption model for detecting encryption with high levels of accuracy."
32:16 "If I did a recovery by clicking the recovery point, as an example, on the 25th, and I did a recovery from there, I could potentially be leaving good data behind because I have two more recovery points after it that even though are infected, maybe not all the data is infected."
36:12 "You can apply additional layers of security to ensure it is truly clean. For example, you'll be able to repay the entire operating system by ripping out the operating system, bringing in a new custom golden image, and then rebuild the server using that image before recovering the data into it."

FAQ

What makes cyber recovery fundamentally different from traditional disaster recovery?

Cyber recovery assumes malice—data may be corrupted, encrypted, or infected with malware. Unlike traditional DR, which focuses on restoring from a clean failure point, cyber recovery requires validating backup integrity, testing in isolation, and ensuring no reinfection occurs when returning to production. Traditional DR doesn't account for adversaries who may have compromised backups or left backdoors in recovered systems.

How does synthetic recovery minimize data loss while ensuring clean restoration?

Synthetic recovery analyzes all backup sets to identify which files are infected and which are clean, then composes a recovery point by pulling the latest good version of each file across the backup chain. This avoids rolling back to an older snapshot (which loses recent data) while still eliminating threats. The platform uses malware scanning, encryption detection, anomaly analysis, and SOC signals to determine file integrity.

Why is cleanroom validation necessary before returning applications to production?

Cleanrooms provide an isolated environment to repave servers with hardened golden images, recover data, and validate applications without risking production reinfection. Security and application teams can test functionality, scan for residual threats, and confirm clean operation before promoting to rebuilt production. This prevents the common mistake of restoring infected backups directly into production, which simply reintroduces the attack.


Categories:
  • » Webinar Library » Commvault
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Security Operations
  • Threat Intelligence
  • Backup & Recovery
  • Technical Deep Dive
  • Demo
  • Cyber Recovery
  • Ransomware Recovery
  • Cleanroom Recovery
  • Synthetic Recovery
  • Backup Validation
  • Incident Response
  • SOC Integration
  • Malware Detection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Commvault: Cyber Recovery with Threat Intelligence & Cleanrooms

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    14

                    Crafting a Championship-Caliber Security Team for Lasting Defense

                    07/14/202601:00 PM ET
                    • Jul
                      14

                      Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                      07/14/202602:00 PM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/14/2026
                          01:00 PM
                          07/14/2026
                          Crafting a Championship-Caliber Security Team for Lasting Defense
                          https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-caliber-security-team-for-lasting-defense/
                        • 07/14/2026
                          02:00 PM
                          07/14/2026
                          Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                          https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
                        • 07/21/2026
                          04:00 AM
                          07/21/2026
                          Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                          https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                        • 07/22/2026
                          06:30 AM
                          07/22/2026
                          Insights and Strategies in Data Protection and Privacy Management
                          https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-in-data-protection-and-privacy-management/
                        • 07/22/2026
                          01:00 PM
                          07/22/2026
                          Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                          https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights from Cyera's Expertise
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version