Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Okta: Data Resilience Strategy with Druva CTO Stephen Manley

Okta
07/24/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


here at Okta, and joining me today is Stephen Manley, the CTO of Druva. Welcome Stephen. Great to be here. Thanks, we're excited to have you. So one of the best parts about my job is that I get to sit down with customers like you and talk about what's top of mind. We've actually identified a handful of topics and one of them, or the one we're going to talk about today, is the future of data resilience. And so can you tell us a little bit about your role at Druva, what it's like being the CTO, and just introduce folks to who you are. Sure. So let's start, I'll start with what Druva is. So Druva, we're a data security company, we're fully SaaS. So very similar to Okta, our focus is customers have data that they need protected. That might be endpoints, it might be Microsoft 365 and Salesforce, might be in the cloud, it might be on-premises, remote offices, wherever. You've got data everywhere, it's sprawled, and everybody wants it. And bad things will happen. Bad people are trying to get at that data, bad things can happen. And so Druva's job is to say, we protect that data for you so that on the worst day of your life, you're able to get that data back and you're able to get your business up and running again. So that's who Druva is. For me, I'm CTO. So that really means that Druva, I'm in charge of everything from the security team, and then of course, sort of the future architecture of the company. So it's a great job. And I mean, the best part for me is, again, I am meeting 100, 200, 300 plus customers a year. So when you're talking about what they're afraid of, there's a lot of fear out there right now. Yeah. Well, you know, we live in a little bit of an unknown time, it can be a little bit scary. We have, you know, cyber threats, natural disasters, just attacks and things happening all the time. What would you say are some of the fundamental pillars for a truly resilient data strategy? So the first thing that you need to look at when you're building a data resilient strategy is, do you have a protected copy? Because as Allison just pointed out, something bad's going to happen to you. And no matter how much you prepare, no matter how hard you work, no matter how good you are, someone will make a mistake or, you know, given where we live, an earthquake will happen or a bad person will be able to get in, you know, through a mistake or some sort of gap. And so to have data resilience, you need to be able to have a plan that says, when you get compromised, you are going to be able to recover. And so that's the first pillar is, do you have a protected copy that you're confident that you can recover? The second is, and this is increasingly important, it's not always just about having the technology, it's about having your people connected. And so to have a really good data resilient strategy, you need your IT team to be connected to your security team to be connected with your lines of business. Because it's all well and good to say, I have a copy of your data, I'm able to recover. If you don't know what it means to the business, then you're not really recovering them. And given the number of threats that are now security oriented, if you're not tight at the hip with your security team, then you're not really sure what you're recovering from. And then I'd say the third pillar that's absolutely critical is to have, I think, a workforce that understands, you know, that we do live in a dangerous world. So I'm not saying everybody needs to come to work afraid every day, but everybody does have to have a healthy respect for this is why we have securities. So those are really the three pillars. Have a data resiliency solution, data protection solution, make sure that you're tied together across your organization, and make sure you bring your employees along so they know why you're doing what you're doing. Yeah, that's really helpful. You know, at Okta, we say identity is security. And again, it's like, we want to make sure that the right person has the right information at the right time, so they can make the right decision. So it's really helpful to hear that, how you're thinking of it at Druva as well. So if we look back at the evolution of data protection, we have two questions. One, what has been, what would you say have been some of the most significant shifts that have shaped your approach to data resiliency? And then what do you think some of the key drivers were behind, or behind those changes? I'd say probably the two biggest shifts, if you look at it in the market right now, one is the importance of security, and then the other is the importance of cloud. So if you look back five years ago, those of us in the data protection space, security was not top of mind. And if you look at most security teams, they never thought about their data protection infrastructure. But because of the rise in ransomware attacks, and the fact that backups are targeted by ransomware so that you can't recover, and that in fact, backups are the only way you're going to recover from a ransomware attack without paying, all of a sudden security became really, really important. And it changed the way we designed, implemented everything that we focused on. And then cloud is the second, right? The fact is, most data no longer sits in a data center. It sits up in a cloud, whether it's a SaaS application or a cloud-native application. And again, that changes the rules. So those are probably the two biggest changes. And in terms of then the second part of the question, why? So again, security, what we find, and I'm sure you see this at Okta, too, I'd be curious. Early on, we saw a lot of organizations say, well, it's the big companies that are going to get targeted, right? The attackers want to go after the big name New York financial institutions. The reality is, in the last couple of years, we see it's educational institutions, it's hospitals, it's manufacturing companies, because that's an easier target, because they don't have the huge budget and the huge IT staff. So I'm guessing you see kind of a similar thing on the identity side, right? Well, it's interesting to see how companies have vulnerabilities. And so you have to really be thinking about your posture management at all times to make sure that you're as safe as you can be across all different parts of your business, and who you touch, and accounts, and partners, and things like that, as well. Absolutely. Right. And so to me, that's probably the biggest driver in the shift, is that a lot of these concerns, which maybe we used to think were sort of Fortune 50 problems, are now everybody's problems. Yeah. And that's just changed our market completely. Yeah. So it's interesting, because you sit down with your customers a lot, or your team does, or the remit handles that. So we know that organizations, they want to be more proactive, of course. They want to be able to see the future, and anticipate these disruptions, and really minimize their impact. At Okta, we have threat intelligence, and we're trying to be more proactive in getting this information out to our customers and our community, so they can prepare. Now, you probably hear this from your customers, as well, but how do they become more proactive? How do they get there? What are you seeing across your customer base, and what are you guys doing at Druva to get ahead of it, if possible? So there's two things we always tell our customers. The first one is, any solution you have in place for dealing with, say, again, recovering from a ransomware attack, if you haven't tested it, it's not a solution. Yeah, a terrible story, but we met a customer who, when they got hit with ransomware, really struggled to recover, and the CISO was just infuriated, and he said, I cannot understand why this has gone so poorly. We had this entire thing fully documented. It was a 186-page document, and you don't want to be mean, but you say, how many people do you think read that? And so we see that either people are overly rigid, or they don't have a plan at all. And so, get a simple plan that's flexible, and then test it, test it, test it. That's the first thing. The second, in terms of being proactive, and this really ties back to the identity piece, is, assume you're going to get hit, because it'll happen. Something bad will happen. Understanding that mapping between identity and data is critical, because if you get compromised, and the only thing that gets affected is some of your home videos, and maybe some marketing material, your heart's not broken, right? Thank goodness, someone looked at our marketing material. And so understanding who's got access to what is really important, because then you can put a lot more stringent controls on those employees that have access to, let's say, more of the crown jewels in the company. And so, understanding that relationship between identity, information, and application really helps you be proactive in terms of preparing for what's going to hit you. Yeah, having that strategy, and a much shorter documentation process as well. Thank you so much for joining us. Thank you guys so much, and we'll catch you next time.

TL;DR

  • Data resilience requires three pillars: protected data copies for recovery, cross-functional alignment between IT, security, and business teams, and workforce awareness of security practices.
  • The data protection market has fundamentally shifted due to ransomware attacks targeting backup infrastructure and the migration of organizational data to cloud and SaaS environments.
  • Cyber threats have democratized—smaller organizations like hospitals, schools, and manufacturers now face the same risks as Fortune 50 companies but with fewer resources to defend themselves.
  • Proactive resilience depends on regular testing of recovery plans and understanding the relationship between identity, data access, and business-critical information to prioritize protection efforts.

Three Pillars of Data Resilience

Stephen Manley, CTO of Druva, outlines the fundamental requirements for organizations to build truly resilient data strategies in an era of escalating cyber threats and data sprawl. The first pillar is maintaining a protected copy of data that can be confidently recovered when—not if—a compromise occurs, whether from ransomware, human error, or natural disaster. The second pillar emphasizes organizational alignment, requiring IT teams, security teams, and lines of business to work in tight coordination. Without understanding what data means to the business and how security threats manifest, recovery efforts lack context and effectiveness. The third pillar focuses on workforce awareness, ensuring employees understand the rationale behind security measures without creating a culture of fear. This comprehensive approach recognizes that technology alone cannot solve data resilience challenges—people, processes, and cross-functional collaboration are equally critical to organizational preparedness.

Security and Cloud as Market Transformers

The data protection landscape has undergone two fundamental shifts in recent years that have reshaped how organizations approach resilience. First, security has moved from peripheral concern to central focus, driven by the proliferation of ransomware attacks that specifically target backup infrastructure to prevent recovery. This has forced data protection and security teams to collaborate in ways they never did five years ago, fundamentally changing product design and implementation strategies. Second, the migration to cloud environments has altered where data lives and how it must be protected. Most organizational data no longer resides in traditional data centers but exists in SaaS applications like Microsoft 365 and Salesforce, or in cloud-native environments. These shifts have democratized cyber risk—attacks that were once considered Fortune 50 problems now affect educational institutions, hospitals, and manufacturing companies with smaller budgets and IT staffs, making comprehensive data resilience strategies essential for organizations of all sizes.

Chapters

0:00 - Introduction and Druva Overview
2:01 - Three Pillars of Data Resilience
4:06 - Evolution of Data Protection
6:32 - Becoming Proactive in Data Security
8:45 - Closing Remarks

Key Quotes

1:02 "You've got data everywhere, it's sprawled, and everybody wants it. And bad things will happen."
2:33 "When you get compromised, you are going to be able to recover. And so that's the first pillar is, do you have a protected copy that you're confident that you can recover? ..."
4:48 "Because of the rise in ransomware attacks, and the fact that backups are targeted by ransomware so that you can't recover, and that in fact, backups are the only way you're going to recover from a ransomware attack without paying, all of a sudden security became really, really important."
6:16 "A lot of these concerns, which maybe we used to think were sort of Fortune 50 problems, are now everybody's problems."
7:13 "Any solution you have in place for dealing with, say, again, recovering from a ransomware attack, if you haven't tested it, it's not a solution."

FAQ

What makes a data resilience strategy truly effective beyond just having backups?

Effective data resilience requires three components working together: a protected copy of data that can be confidently recovered, tight coordination between IT, security, and business teams who understand what data means to operations, and an aware workforce that understands why security measures exist. Technology alone is insufficient—organizational alignment and regular testing of recovery procedures are equally critical.

How has the ransomware threat changed the relationship between data protection and security teams?

Ransomware has forced data protection and security teams to collaborate closely in ways they never did before. Because ransomware specifically targets backup infrastructure to prevent recovery, and backups are often the only way to recover without paying attackers, security considerations now drive the design and implementation of data protection solutions. What were once separate domains are now tightly integrated.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Cloud Security
  • Identity & Access
  • Executive Briefing
  • Best Practices
  • data resilience
  • ransomware recovery
  • backup security
  • cloud data protection
  • cross-functional security
  • disaster recovery testing
  • identity and data access
  • SaaS data protection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Okta: Data Resilience Strategy with Druva CTO Stephen Manley

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    06

                    Mitigating Risks of Sensitive Data Exposure in AI Platforms

                    08/06/202604:00 AM ET
                    • Aug
                      06

                      Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                      08/06/202602:00 PM ET
                      • Aug
                        07

                        Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift

                        08/07/202611:00 AM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Mitigating Risks of Sensitive Data Exposure in AI Platforms
                          https://www.truthinit.com/index.php/channel/2058/mitigating-risks-of-sensitive-data-exposure-in-ai-platforms/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:00 AM
                          08/07/2026
                          Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-evolving-triage-agent-that-learns-each-shift/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverages and Essential Cybersecurity Insights for the Season
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverages-and-essential-cybersecurity-insights-for-the-season/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version