Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Cyber Resilience & Data Protection with Schuberg Philis

Commvault
07/24/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


We have a fantastic podcast today. I'm lucky to be joined by Ono Vandenberg. He's a Mission Critical Engineer at Schuberthuis, hails from the Netherlands. We got to start with this though. Probably one of the best titles I've ever heard, Mission Critical Engineer. So maybe just to give a little background, what you do day in, day out. And nice to meet you. The title is quite nice, and the fun fact is that we are all mission critical engineers at Schuberthuis. Nowadays, we are almost at 500 colleagues around the various offices that we have in the Netherlands. As a company, we solely focus on mission critical outsourcing of the sole workloads from our customers that are really, truly fundamental for mission critical today. My key role is that I'm currently a lead engineer for our on-prem cloud offering that also entails our crown jewel that is running on technology. It's called DMS, and I have been building that platform and also running it for more than a decade now. And that is a platform used by all our customers to satisfy their data protection, data security requirements, being on-prem workloads or workloads that reside in AWS or in Azure. Soon also Google and Oracle are going to be added as well. And together with my team, I'm responsible for running the show, basically. I was going to say, it's rare to see, and I applaud you all for having a title that is highly descriptive of what you actually do day in and day out. So I like that a lot. It's one of the first things I noticed. So, all right, here's my first question. I was looking, of course, at what you all do, right? I mean, you touch everything. You touch cloud, data and AI, software security. So clearly when you're doing those mission critical things for clients, you're doing them across a very wide swath of technology, but you've been in this business for a while. I think you mentioned 30 years. What is probably the most notable or impactful change you've seen over your career that could be data protection or otherwise, but curious when you look back through today, what's the biggest that you've seen? Ooh, well, that's a good one. I think, first of all, right to the real traction from going to under more distributed on-prem platforms to consolidating everything into the bigger cloud platforms. I think that was one of the really major shifts that we have over the last 30 years. I think of course, for the last few years, it's for sure AI and it's still AI. It's really dominating everything that you see now in our world, basically. I think those two are really the, for me, the most remarkable ones that are also really had an impact on my career as well. And, you know, in all honesty, it's still that you see a pattern from the various solutions, right? So back in the days, you had very large platforms running on mainframes that then going to distributed architecture, including how it's server-based computing, then going into public clouds. And now we also see a lot of traction going back. So customers are really considering pulling out workloads from public clouds or because of cost or because of sovereignty or because of the things that are really happening geopolitically. It's a constant shift basically, and where we all try to adopt as quickly as possible. And never put away the old ties. I mean, I always joke about the thin tie, wide ties, never throw away the ties because just wait around long enough and it'll come back around again. And there'll be that discussion. You mentioned sovereign, such an interesting, interesting topic right now. And to your point, causing a dynamic for people to shift back on-prem or at least have more control in whatever kind of hybrid architecture that may end up, you know, evolving. So curious, that said, in enormous changes in architectures, two large epochs that you mentioned, how much has data protection architecture and thoughts around data protection changed or not changed, if you will, over your career and what do you think the data protection community, the resilience community at large needs to do more of? That's a good question. When I started with Confluent myself around 10 years ago, before that time as well, and I was really touching up on the solutions from different vendors. It was really solely as to be seen as an insurance, right, for really people losing the data because they accidentally deleted a service system that broke or a source system. That really transformed, especially I think over the last 10 years with an intensified amount of such of cyber threats really kicking in. And ransomware, of course, really started to become a really, really big player. Of course, now really accelerating as well, because it's not only us that are adopting AI, it's also the bad guys who are also adopting it. Probably even more so, right? I mean, there's a lot of conversations. They're at the leading edge where our clients may be taking it a little more slowly. They're full steam ahead. Exactly. Exactly. So all these attacks will become way more sophisticated and way more advanced towards the future. And this is also where we, through regulations as well, that resiliency and recovery is really becoming a critical factor for customers. You now also see it's more on the agenda, there's budget available. However, right, it's also from a solution perspective as well that you see companies really transforming from a standard data protection platform or solution, really moving into the security aspect, companies really starting to transform into a security company. Two cool things about data protection is also, is that the solution really manages all the customer's data, right? We basically protect all the data. We touch the data, we have the data and we know where the data resides. And we have the abilities also to actually move data around in a secure way. I think that also opens a lot of possibilities towards the future as well. And you start to look at what AI really needs and that's data. AI really needs data to get better. I think from that perspective, all these vendors are in a quite unique shape, basically, or position to actually excel their solutions towards the future by really starting to embrace these kinds of capabilities on the other hand, and also all the innovations that are currently happening. Right. You kind of took the next one right out of my mouth. I was going to say, you know, as fast as we're all moving, I mean, you know, you're with clients every day. I'm curious if you were to kind of look down the tunnel as to the one thing that you think we as a data protection community need to be working on. And I guess it's also, of course, a message for, you know, clients that are watching this, what would be your advice? What should you be preparing for today with respect to appropriate architecture decisions to be ready for a number of these things that are coming down the pipe, right? Whether it's AI, whether it's move between hyperscalers back, is there one or two things that you're saying, I'd like to see more clients doing this and I don't today? Oh, that's a, that's a cool question. I think from an architectural point of view, it's really to adhere to standards, really optimize your environment from a security point of view, really take into account segregation, all these kinds of things. Also really focus on, on efficiently use all the capabilities that the solutions actually deliver, because especially a Convolt, for example, really offers a lot of capabilities built in, into the platform, quite an active community user as well. I quite often also see that a lot of customers still forget about all these built-in capabilities. For Convolt, for the community, et cetera, is also to really advise customers, hey, really start to leverage all the capabilities that the platform actually is able to. When you mentioned being resilient, especially in the face of cyber anomalies, right, in general, I'll ask a number of folks and say, hey, how often do you see appropriate integration between the data protection platform, right? Convolt and SOC. And as you know, those capabilities have been there for some time, but when you do ask how many people have executed on the integration, so the data protection scene is sending appropriate telemetry to the overall arching security team and monitoring teams. More often than not, that integration does not take place or it takes place loosely and it's, it's not executed where you probably would like to see it from a best practices. So, you know, I look at that. I'm curious your take on this. We do a lot of tabletop. It is amazing when you actually sit down and do one of these with the right level people, how many aha moments there are. So I'm guessing you do those. How are you trying to convince clients to do those, do them more regularly, make them part of their DNA? Because I know that that's been a challenge over the years. That is indeed a true challenge. And I think that indeed all really has to do with the fact that you are historically speaking, right? It was more a focus on the backup administrator to really lecture those people and now all of them with that actual shift going into data security. You really have to really start opening up to have the conversation in a much broader perspective with more people. Also have security teams on board. CTOs, for example, can be the right people to eventually had a messages internally across the various departments to really make sure that all these capabilities and integration indeed that are nowadays available are actually going to be consumed and used in a proper way. And that's not, of course, the easy example is you'll talk to folks and they'll say there's a lack of communication that data protection space versus the security space. But it even goes beyond that. It extends the general counsel. If it's a large company, there's probably a data team that's involved, right? All the things your team is doing on a daily basis. If there's a takeaway, I can only just reiterate, have the conversation start somewhere. I think we're both saying a tabletop exercise is a fantastic conversation starter because almost more than the tabletop, it's what it generates after the tabletop, right? I'd be remissed if I didn't thank you. You've used the community word a couple of times. Thank you for being such an active member of the community for us at Commvault. You clearly don't have a lot of spare time. And so the fact that you take personal time to do that, I hope you get out of it as much as you put into it. But thank you for doing that. And the question I think I have there is, even if folks don't have maybe the time you have to give back, why should they be involved in a community like that? What have you gotten over the years of being this involved? That is for sure that first of all, you are going to meet other people with the same passion for data security, data protection, that are really there also to share knowledge, to help out. I had to really play a role in that, in that perspective. I think as you know, in our world, every day things change, right? And that also is the same for the Commvault solution as well. There's just so much to share as well. And I think by actually sharing information or experience, we can also leverage that information to actually shape the future of the platform itself. And I think that is one of the real cool things about the community and really seeing the community being quite active, that can be really instrumental for the future developments and also for Commvault to actually leverage from a product and product management perspective as well. Also really put in the voice of the community to prioritize new features, enhancements, et cetera. I really like to do it and to share it. Well, your, your feedback over the years has been invaluable. It absolutely helps shape where things are going. You, you are every day with clients and you see it across both the unique geography perspective, right? That that's important. And different verticals. And when you match those two up, that telemetry coming back, you know, for example, to us is fantastic. So thank, thank you for that. The last one, last, hopefully not hard question, but if you were to give any advice to folks coming up in this space, or who maybe have been in it for a while, but maybe you still don't see them executing or doing one thing that you feel is best practice, what would be your advice to the community, data protection community and, and all of the peripheral communities that, that they should be touching on a daily basis? Ooh, that's a difficult one. Keep on doing what you are currently already doing. And that is really to make sure that the data is safe, right? That you are the one that is going to be able to actually bring back the company in case of being the company in a very bad situation due to, for example, a cyber threat or some other thing that is really impacting the availability of the business for the company where you are working for. You know what I like about that? Keep it safe. And there's a lot packed in there, but given the fact that data is only increasing in value, I don't think anybody would debate that, even if you found the most, you know, person who likes to debate anything, it would be hard to say that data's valuable nature is not going in one direction. So do not let your eye off that proverbial ball, right? Exactly. Thank you so much for the time today. Thank you for being so active in the community. Again, I'd be remissed if I didn't mention it again. And the advice, I hope everybody listening pulls away one or two nuggets. Maybe you packed a lot in there. So thank you very much. We really appreciate it. You're welcome. Thank you.

TL;DR

  • Data protection has fundamentally transformed from backup insurance to a frontline security control, driven by ransomware, AI-accelerated threats, and regulatory requirements that now demand board-level attention and budget.
  • Organizations must implement proper segregation, leverage built-in platform security capabilities, and integrate data protection telemetry with SOC operations — capabilities that exist but remain underutilized in most environments.
  • Cloud migration patterns are reversing as workloads move back on-premises due to cost, sovereignty, and geopolitical concerns, requiring data protection strategies that seamlessly span hybrid and multi-cloud architectures.
  • Cross-functional collaboration through tabletop exercises and regular communication between backup, security, legal, and executive teams is essential for comprehensive resilience planning and incident response readiness.

The Evolution from Backup to Cyber Resilience

Onno Van Den Berg traces the fundamental transformation of data protection over his 30-year career, highlighting how the discipline has evolved from simple insurance against accidental deletion to a critical security function. The shift accelerated dramatically over the past decade as ransomware emerged as a dominant threat, forcing organizations to recognize backup and recovery as frontline security controls rather than afterthoughts. This transformation has been further amplified by AI-driven threats, with bad actors adopting artificial intelligence faster than many enterprises, creating increasingly sophisticated attack vectors. Regulatory pressures and compliance requirements have elevated resilience and recovery to board-level concerns, with budget and executive attention now following. The discussion emphasizes that data protection platforms uniquely manage, touch, and understand all customer data across environments, positioning them as strategic assets for both security and emerging AI initiatives that require comprehensive data access.

Architectural Principles for Mission-Critical Protection

Van Den Berg emphasizes the importance of adhering to security standards and implementing proper segregation between production and backup environments as foundational architectural principles. He notes that many customers fail to leverage the full capabilities built into modern data protection platforms, leaving security features unused despite their availability. A critical gap exists in integration between data protection systems and Security Operations Centers, with telemetry and alerting capabilities often not configured despite being readily available. The conversation highlights the need for cross-functional collaboration, bringing together backup administrators, security teams, CTOs, and even general counsel to ensure comprehensive resilience planning. Tabletop exercises emerge as powerful tools for generating these conversations and revealing integration gaps, though they remain underutilized. Van Den Berg advocates for customers to optimize their environments by fully utilizing platform capabilities, implementing proper segmentation, and ensuring that data protection is treated as a security control with appropriate visibility across the organization.

Cloud Migration Patterns and Sovereignty Concerns

The discussion reveals a cyclical pattern in infrastructure architecture over three decades, from mainframes to distributed systems to public cloud consolidation, and now a notable trend of workloads moving back on-premises or to private cloud environments. This reverse migration is driven by three primary factors: cost optimization as cloud expenses scale beyond projections, data sovereignty requirements as regulatory frameworks tighten globally, and geopolitical considerations that make data residency a strategic concern. Van Den Berg observes that organizations are increasingly evaluating which workloads truly benefit from public cloud versus those better served by on-premises or hybrid architectures. This shift requires data protection strategies that seamlessly span multiple environments, supporting workloads across on-premises infrastructure, AWS, Azure, and soon Google Cloud and Oracle Cloud. The ability to securely move data between these environments positions data protection platforms as critical enablers of hybrid and multi-cloud strategies, not just backup repositories.

Chapters

0:00 - Introduction to Mission Critical Engineering
1:38 - 30 Years of IT Evolution
3:41 - Data Protection's Transformation
6:19 - Architectural Best Practices
8:35 - Integration Gaps and Tabletop Exercises
10:19 - Community Engagement Value
12:09 - Advice for Data Protection Professionals

Key Quotes

4:19 "It was really solely as to be seen as an insurance, right, for really people losing the data because they accidentally deleted a service system that broke or a source system. That really transformed, especially I think over the last 10 years with an intensified amount of such of cyber threats really kicking in."
4:42 "It's not only us that are adopting AI, it's also the bad guys who are also adopting it. Probably even more so, right? ..."
5:35 "The solution really manages all the customer's data, right? We basically protect all the data. We touch the data, we have the data and we know where the data resides. And we have the abilities also to actually move data around in a secure way."
7:36 "I quite often also see that a lot of customers still forget about all these built-in capabilities."
12:47 "Keep on doing what you are currently already doing. And that is really to make sure that the data is safe, right? That you are the one that is going to be able to actually bring back the company in case of being the company in a very bad situation."

FAQ

Why is data protection now considered a security function rather than just backup?

The rise of ransomware and sophisticated cyber threats over the past decade has transformed data protection from simple insurance against accidental deletion into a frontline security control. Regulatory requirements now mandate resilience and recovery capabilities, and organizations recognize that backup systems manage all their data, making them critical for both protection and recovery in security incidents.

What architectural changes should organizations prioritize for cyber resilience?

Organizations should implement proper segregation between production and backup environments, adhere to security standards, and fully leverage built-in platform capabilities that often go unused. Critical integration between data protection systems and Security Operations Centers should be configured to provide telemetry and alerting. Cross-functional collaboration through tabletop exercises helps identify gaps and ensure all teams understand their roles in resilience and recovery.


Categories:
  • » Webinar Library » Commvault
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Cloud Security
  • Best Practices
  • Technical Deep Dive
  • Backup & Recovery
  • Cyber Resilience
  • Data Protection Architecture
  • Ransomware Defense
  • AI-Driven Threats
  • Cloud Migration Patterns
  • Data Sovereignty
  • Security Integration
  • Tabletop Exercises
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Cyber Resilience & Data Protection with Schuberg Philis

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    06

                    Mitigating Risks of Sensitive Data Exposure in AI Platforms

                    08/06/202604:00 AM ET
                    • Aug
                      06

                      Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                      08/06/202602:00 PM ET
                      • Aug
                        07

                        Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift

                        08/07/202611:00 AM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Mitigating Risks of Sensitive Data Exposure in AI Platforms
                          https://www.truthinit.com/index.php/channel/2058/mitigating-risks-of-sensitive-data-exposure-in-ai-platforms/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:00 AM
                          08/07/2026
                          Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-evolving-triage-agent-that-learns-each-shift/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverages and Essential Cybersecurity Insights for the Season
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverages-and-essential-cybersecurity-insights-for-the-season/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version