Transcript
how security and identity and cyber recovery are coming together in a modern era of resilience, but it's also going to serve as a bit of a summary for a lot of the main themes that we've heard over the course of today. And so, one of those key, I would say, common reality that I heard in almost every single presentation throughout today is that AI is accelerating change. It's a common reality across our customer base. And one of the stats that hit me first that represented this is Balaji had something up talking about how there is predicted to be 5x growth of data centers in India alone by 2030. It's one of the big impacts that the speed of AI adoption is having on us. Let me give you another example. As a customer I was talking to last week, they're a financial services institution. They specialize in blockchain assets. They're regulated by the government. So, they have to adhere to a whole bunch of regulatory requirements. And one of the things that their CISO was telling me is that their CEO mandated that every department within the company, at least every main department, by the end of this calendar year, has to have not only an AI application, but an agentic application in production and customer facing by the end of this year. So, so far they have two of them in production. They're about to roll out another four over the course of the next month. And so, they have kind of two more that they need to wrap up by the end of the year. And what was interesting about hearing this strategy that they have in place for securing and governing and protecting these AI workloads, and these are, again, customer facing. And so, they're pretty sophisticated applications. I started asking him about what they're doing from a resilience, cyber recovery, and data security perspective. And he's like, Tim, you know, we are a regulated organization, so we back up everything. I said, all right, so, you know, do you, when you, when you're backing these things up, what about your recovery strategy? Have you prioritized which facets of the AI data you're recovering in what order? Like, for example, are you keeping all the logs of interactions that the agents are having? He's like, we're keeping everything. Like, well, tell me, you know, how do you prioritize this? Like, I can't. What do you mean you can't? So, we don't really know. We just have to adhere to some of these resilience policies because we're a regulated industry, but we don't really have much more of a strategic approach to it beyond that. And so, to me, that's really representative of this impact that AI is having. It's accelerating change. In this case, they're doing significant things with AI in production, but they don't really know strategically how to govern various aspects of this, especially as it relates to some of their resilience policies. And I think that tension is something that we see time and time and time again within our customer base. And so, this impact of reality, I'm sorry, the impact of this reality was apparent in this customer example I just gave you, but it was also apparent in five themes that I've heard throughout the course of today. And so, what I want to do is unpack each of these themes and talk a little bit about what I've heard as the presenters were on stage going through some of the impacts that AI is having on work that many of you are doing. So, one of these is we heard about resilience and AI scale. And the word trust came up a lot, either the word actual, word trust, or just other ways of saying clean, trusted, confident in your data. The second theme is being able to design for breach, expect it. I think we've heard Jill say something along the lines of, you know, it's not a matter of if anymore, it's when. Some people even say like, well, when you find out that you've been breached because you may have bad actors already in your environment. And so, in this case, it's designed for a breach, understand and be confident in your ability to restore minimum viability back to your organization. The third theme that I heard was all around identity. Identity is the first domino to fall and you have to treat it like a tier zero application. So, we'll touch on that. The fourth theme that we heard was around the hidden cost of AI and of kind of cloud and data sprawl and what the hidden risk is behind that. And then the fifth thing that we'll touch on is, like Will just said a moment ago, AI is amplifying everything. And so, you have to build trust into this. So, let's pick these apart and go into some of the themes that emerged. And ultimately, within each of these as we cover them, I want to go through some of the operating practical advice that I heard over the course of the day that you all can take on your own and consider figuring out how to operationalize within your environments. So trust the new KPI. So, what I heard is if India's cloud and AI momentum is real, so resilience has now become a strategic differentiator because the data growth just exploding, complexity is increasing, risk is increasing and the integrity of that data matters more than ever. I think one of the things we heard is if AI runs on data, the first thing is that security control to be able to ensure that data remains trusted is key. And then the last control is proving that you can recover when that trust breaks. Now I realize putting up here on the slide, like trust is the new KPI. It can't really, you know, there's no kind of trust measure, I don't know, or is there? But I think a few of the things that we've heard over the course of the day are proxies for measuring trust. I heard Amit say something like, gone are the days of RTOs and RTOs. Well, a way of measuring trust in today's cyber kind of attack-driven world is what about meantime to clean recovery? You know, I think it's kind of the emerging way to think about a recovery objective is maybe it's not an RTO or an RPO where you trust the data in a disastrous area, but when we don't trust the data, what about time to clean recovery? What about understanding your identity system and their resilience? What about understanding your critical applications and your critical data and knowing, are you testing those? What's the frequency of your tests? These are all sorts of things that do have tangible metrics that you can measure and then assign to some way of having it contribute to an organization's understanding of their trust for being able to restore the business to operations after some sort of outage or breach. I think a few of the then operational takeaways that I heard over the course of the day is, you know, first, how data integrity, or again, you know, trust, it's becoming a board-level concern. And that's something, frankly, one of the most common conversations that I have with customers is around this. A couple of weeks ago, I had the chance to talk to 10 different customers of ours all at the same time. About half of them were CISOs, the other half were SVPs and VPs of cloud infrastructure. And we spent an hour talking about results. And this was the number one topic that they cared about, is when data integrity, clean data, trust, improving resilience operations is paramount. That's become a board-level discussion. And one of the things that they were asking us is help for telling that story to the board. And so understanding how to, you know, what are some of the proxies for measuring trust and bringing these to other executive-level conversations and even to the board helps establish how your organization is helping, you know, using improving resilience to demonstrate that sort of interest. I think another thing we heard over the course of the day is understanding kind of the multi-cloud gaps. We heard a few of the presenters talk about just distributed data, which means distributed risk. I think Putin did a great job talking about the better you have a sense of the visibility across that, not only can you control costs, but then also thereby kind of control the risk associated with that. And then lastly, having kind of resilience as a platform capability, or I think said another way where it's just built in. This is something we're going to touch on in actually over the course of another couple themes that emerge. The next big theme that I heard today was around designing for breach and being able to recover minimum viability. So one of the ways we heard this was Phil and Amin talking about in a zero perimeter world, resilience is measured by how quickly and confidently you can restore core business. Not just by how many tools you have that help you do it, but how fast can you get the business back up and running? How quickly can you start making sure you're delivering on your mission to the patients you're serving, the customers that you're serving, the citizens that you're serving, the students that you're serving. And here's when, as Jill and Amin talked about, like the perimeter disappearing, I think one of the things that really came through is that that becomes a business perimeter is kind of how I internalize this. And that means you have this criticality of identity plus the critical data, and that kind of becomes then the core kind of business perimeter that's key for restoring that in order to get the fastest path back up to the organization operating. A few of the maybe more tactical, like operational things you can take on the organizations, or maybe if you already are doing these sorts of practices, just continue to improve on, is really having an understanding of your minimum viable company. And really be clear on like what do you need to protect most and make sure it's back up and running first after some sort of large outage or attack. Now I've seen this one span the gamut. I was talking to Jill earlier today, and she said, I just was talking to a customer, and it took them four years to define what a minimum viable company is for them. I'm like, that's a long project for defining what's critical, and my guess is the moment you're done, it's out of date and it's evolved. I've also talked to a customer, I was talking to a CIO at one of our customers, they are the planet's largest private power generation company. The way that he established minimum viability in this company is he went to an executive meeting. He said, if we had a massive outage, what would be the first applications that you all think we would need to get up and running? And I'm like, oh, this would be easy. No one in the room agree. And that was such a loud message to the executive team that they were actually really rapidly able to prioritize defining what to them was minimum viability for their organization. The second thing, we've heard this across multiple presentations today, is just best practices. One that we've heard a few times is air-gapped immutable storage. I'm curious, just by a show of hands, who here is using kind of a cloud air-gapped immutable storage location for applications or data that you're responsible for? So this is interesting. Here's what's interesting as a vendor, as someone at Commvault, we talk about this a lot. We have a whole bunch of new capabilities and we always want to talk about kind of the really new powerful things we have. This small amount of hands that just went up is actually really representative. Immutable air-gapped storage has been a best practice for a while. I was just talking to Gardner last night as part of some work we were doing with them on the Magic Quadrant, and they're like, people still are not doing it from the immutable storage in the cloud. It's still a best practice that I think it is like top of the list for organizations to really ensure that they have a safe, trusted place where they can go in and use to reestablish data after some sort of significant outage. And then the last one is you can use cleanroom recovery mechanics in order to recover key data in an isolated location, use it to validate that data, and then reintroduce it to production once you have trust that it is clean and has high integrity. The third theme that was covered over the course of the day across multiple sessions is identity. And there's kind of a tension across identity that I've heard. On the one hand, with your identity, it's, you know, it's the first domino that's going to fall. I think I've heard Jill say something along the lines of, so many cyberattacks aren't actual attacks, they're simple logins. And so identity has become one of the key attack factors. In fact, nine out of 10 cyberattacks include Active Directory. So on the one hand, you have identity as a kind of a critical, you know, or common attack factor. And then on the other, because of that, you have it as a critical tier zero application or service that not only needs to be up and running, but needs to be up and running in a trusted way so that your users can access the data that's critical for them to get their jobs done, serve your customers, you know, work with patients that they're serving, work with partners, or what have you. I think one of the things that makes that a daunting challenge is this trend we're seeing on the explosion of identities. So, you know, I list here 20 to one human, I'm sorry, non-human identities compared to human identities. L is a stat, you know, 80 to one. I was just talking to one of the researchers that we work with. This is unpublished data, but they had seen in some cases, even up to like a thousand to one, regardless of which of those stats you decide to listen to, it's tremendous. And I think one of the things that I see is as I talk with customers is people aren't quite sure, is this just a new way to ABI? Or is there something fundamentally different about how we want to treat these non-human identities and we don't understand the risk yet? So I think this is having a sense of how you're going to monitor, you know, access and kind of identities, especially this proliferation of non-human identities, I think is a key question that people have actively opened and they're watching, especially as they continue to adopt AI. Another thing that I heard across multiple presentations is around the criticality of Active Directory. Amit talked about, you know, EnterID, Okta, regardless of which of the systems that, you know, your organization uses, because of this criticality of having access to the applications and data that are important to your business, it's becoming kind of the new control plane for organizations. And I think Amit said it really well when he said that the best organizations, they have a deliberate and prioritized practice around identity resilience. And then I think finally is that identity recovery, it's not just kind of a restore the directory, it's really about restoring trust and access back to those critical systems. And so I think one of the biggest practical takeaways that I heard from today is just the importance of treating your identity systems as a tier zero application. The fourth theme that emerged today was around, I thought this really interesting correlation between hidden cost and then the hidden risk associated with that. Woojin did a great job of saying, hey, when you can't see it, you can't control it. And so I think an important connection between that, he highlighted a few things. First of all, just the tremendous challenge associated with the sprawl, not only of data in general, but in particular, for those of you in this room, because it's the sprawl of secondary data that's a daunting challenge. The second thing is when you have the sprawl, and especially if there's not strong hygiene against it, is you have too many copies. And so I think the obvious thing that he first anchored on was that just costs too much. But I think the interesting connection point that he drew out is that, and not only does it cost a lot, but it's slower and it's riskier restores. And kind of the final thing is, I think there was this link between having strong visibility around your secondary copies and then ultimately being able to understand how that impacts the cost and compliance and the confidence that you have in restoration. I'm curious here, Honorable Ashika, sorry, but remember in the morning, she said, hey, you know, raise your left hand if blank, you know, raise your right hand if blank. So I'm curious to know as it relates to costs and visibility, who here, I'm going to ask like kind of a, do you believe one or the other, who here believes it's harder to, you have a harder time getting visibility into your secondary copies and kind of what that data is and where it is so that you can control it. And who here has a harder time justifying the cost of that secondary data to your boss or the finance group? So which one of those is harder? For those of you who think it's harder to see the secondary copies of data and gain visibility, raise your right hand. All right. And then what about those who think it's harder to justify the cost of that secondary data? Raise your left hand. So it's not an equal mix. I have any people who are like, hey, it's all hard. I was fortunate enough to meet any of those out there too. So I think the take home for this is something that Pooja really teased out is visibility, is gaining control and command over the visibility that you have of those secondary copies is going to unlock better cost efficiencies. And then I think the kind of the hidden correlation is it's going to unlock better risk reduction as well. And then the last theme that I've heard over the course of the day is around how AI amplifies everything. This jumped out at me in two sessions in particular. Raul from CloudSec, he was talking about how AI really empowers bad actors to traverse identity graphs and data graphs. And the so what is, he's like, so what used to take months or at least weeks, but sometimes months for bad actors to kind of piece together can now happen in a matter of minutes. So kind of on the downside or the negative side, you have AI amplifying just malicious activity. I think Woon had this beautiful graphic too, of talking about how, you know, kind of just bad data in an AI system is also amplified as it kind of moves left to right across the AI data pipeline. So on the one hand, you have AI amplifying everything in a bad way, but then we heard some examples of how AI could be used to then amplify your resilience in a positive way. So I think a couple examples of that is on the last bullet point of this slide, is that trust must be designed and designed in your system and not simply just assumed. A couple examples of this, where you can kind of build trust in your resilience systems, as Poojan talked about, using AI, especially automating, restores at a dramatic level for scale. That's something that you could build it. He talked, he and both Woon went into some details around just using kind of serverless capabilities in some of the parallelism that you can gain from that from a compute perspective. That's something that can be made in your resilience process with something like a Clunio. Another example was, I think it was, Amin was talking about how conditional access for non-human identities, also a best practice. That's something that can be baked in to your resilience practice. So I think this idea of AI amplifying everything, yes, it's scary on the one hand, but I think it's also a powerful weapon that you can leverage to improve your resilience practice. And so Elliot touched on this in his presentation, Rajiv from IDC actually did a great job touching on this. I believe at Commvault that unifying your resilience practice is kind of the next era of resilience in today's AI driven landscape. This means a few things. Elliot touched on the first two, is unifying resilience across your data security practice. So understanding what your data is, how you're classifying it, the access governance to this. Unifying that with your identity resilience so that you can ensure that you can restore trust and kind of access to your critical systems. And then you're unifying that with also your cyber recovery practices. So that's kind of one thing that we believe is important to unify. The second thing is unifying your resilience across everything, no matter where it lives, across all your workloads. These may be established workloads that are in your production, they've been in your cloud environments for years, or these may be emerging new AI workloads, but all of them should be treated equally with rigorous resilience processes in place. And no matter where they live, across clouds, across regions, across accounts, even if you needed to snap in edge locations or, you know, any kind of on-prem environments. And I thought Rajiv from IDC added a third element too, is to unify resilience across the intelligence that your critical security, identity, and recovery systems have. So being able to share intelligence across the, you know, likes of a SIM or a SOAR or an XDR, sharing that with Commvault and vice versa, sharing that with identity systems or systems like CloudStack that understand what potential compromises may be out across the dark web. When you can share or unify that intelligence across your resilience practice, that will also improve your time to cyber recovery after some sort of significant attack. So what? So when you leave here, you know, I call this, what could you do on Monday morning, assuming that first of all, I thank you all for spending your valuable time with us today. So my guess is your Friday is going to be catching up. So when you get back to the office on Monday, what are some actionable things that you could do to improve your organization's resilience? The first thing is define your minimum viable company. What do you think are the first five to 10 services that have to return after some sort of outage or attack? If you already had them defined, go around and query some of the folks that are your counterparts, especially those not in your department. Do they agree with you? Do they have the same five or 10? Most organizations that I work with, they already have a list. The hard part is they don't agree on the list. And that's where all of a sudden the resources get spread thin when it's not the right time to be figuring out which ones to pull up first, second, or third after some sort of significant outage or event. So that's a great one to make actual. The second thing is understand if you don't have a way to prove clean recovery, what could you do next to further your journey there? Do you have a way to do isolated kind of clean room recoveries? If so, are there ways to improve that? What about, what are you doing to validate clean points so that you're confident that the data that you're recovering is to the latest kind of known good clean statement? You have a high degree of confidence you're not reinfecting any environments. And then the third is operationalized visibility. I love this tie into visibility being more than just understanding what your data is or what it's costing you, but what's the risk associated with it? So understanding cost, policy, visibility, and your secondary data, and then figuring out how to connect that to governance or security signals, recovery readiness. Those are kind of three categories, kind of recommended next steps that I think you can take back to your office on Monday and either start to establish if it's a new set of practices to you, or if you're already down the path, some next steps to further it. Now, in closing, I want to steal a line from Poojan. He got up and he's like, I am in a room of builders. And he talked about building, you know, cutting edge, organizational and shifting, innovative applications. And that's exciting. It's exciting to be in a room with people like you who are doing that. I'm going to take it, you know, to kind of add one more layer to it. I also see you all as builders of a movement. And so that you chose to take a day to spend with us and learn more about how you can improve your resilience practice. You're part of a movement. You're building a movement around improving resilience, around figuring out how you can help your organization have a stronger res ops posture, especially in a really daunting era. So we thank you on behalf of Commvault, on behalf of our partners, Microsoft, AWS, and CloudSec. Thanks for being builders that are helping us build this movement to an improved world of resilience. I'll see you all later today when we're kind of mingling with drinks after the next session. Thank you.