Commvault: Why Your Disaster Recovery Plan Could Make Ransomware Worse

Commvault: Why Your Disaster Recovery Plan Could Make Ransomware Worse

Could the disaster recovery plan designed to protect your company make a ransomware incident even worse?

In this episode, I speak with Darren Thomson, Vice President and Chief Technology Officer for EMEA at Commvault, about Resilience Operations, commonly known as ResOps, and why cyber recovery now requires security, infrastructure, identity and data teams to work from one coordinated plan.

Darren argues that many companies are accepting a difficult reality. Even with considerable investment in prevention and detection, a breach may eventually succeed. That does not make cybersecurity controls any less necessary, but it means recovery can no longer be treated as a secondary activity managed by another department.

The problem is that security operations and infrastructure teams have traditionally worked toward different objectives. Security specialists concentrate on identifying and stopping threats. Infrastructure teams protect data, maintain backups and restore systems after outages. During a cyberattack, a successful recovery requires both sets of expertise.

A backup administrator may be able to restore data quickly, but a forensic specialist must establish whether that data is clean. Without that confirmation, the company risks restoring malware and restarting the incident.

Darren explains why a conventional disaster recovery plan may be particularly dangerous during ransomware. These plans were commonly designed for physical failures such as a lost data center. Data would be copied from one location to another so operations could continue. If the source data is infected, however, fast replication can carry the malware into the recovery environment.

This is where ResOps enters the discussion. Darren describes it as an operating model rather than a product. It combines established practices from security and infrastructure management into a continuous program for testing, learning and improving recovery. Individual technology projects may come from the program, but resilience itself never reaches a final completion date.

AI adds pressure on both sides. Criminals can use it to create faster and more effective attacks, while defenders can use machine learning to inspect large volumes of information, detect patterns and identify the newest clean recovery point. Companies must also protect AI systems as they would any other business application, including the models, data repositories and identities connected with them.

Darren offers one practical starting point for CIOs and CISOs: Mean Time to Clean Recovery, or MTCR. This measures how long it takes to restore an application and its data with evidence that both are free from compromise.

Before measuring MTCR, leaders must define their minimum viable company. These are the systems and services the business cannot operate without. Once that list exists, teams can test how long a verified clean recovery would take and replace assumptions with evidence.

The initial answer may be uncomfortable. Teams may know how to restore an application without knowing whether the backup is clean. Security may know how to inspect the system but lack an established workflow with the recovery team. Darren sees those gaps as the starting point for a useful ResOps program because they provide everyone with a shared problem and a measurable objective.

If your most important systems disappeared today, how long would it take to bring the minimum viable company back using verified clean data? Listen to the episode and share your answer with me.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(2000)

Breaking Customer Service Silos With Fin AI Agents

Breaking Customer Service Silos With Fin AI Agents

What would change if a customer could return three days later through a different channel and continue the same conversation without repeating a single detail? In this episode of Tech Talks Daily, I s...

25 Aug 28min

Moving AI Beyond Black Box Answers With Neo4j

Moving AI Beyond Black Box Answers With Neo4j

Can organizations trust an AI recommendation when they cannot understand the evidence, relationships, and previous decisions behind it? In this episode of Tech Talks Daily, I welcome back Jim Webber, ...

24 Aug 28min

Building the Business Context Autonomous AI Agents Need With Reltio

Building the Business Context Autonomous AI Agents Need With Reltio

What does an AI agent need to understand about your business before you allow it to make decisions and take action without waiting for human approval? In this episode of Tech Talks Daily, I speak with...

23 Aug 30min

The Swivel Chair Problem Holding Back Enterprise AI With Clio

The Swivel Chair Problem Holding Back Enterprise AI With Clio

How much of your technology stack is being held together by people swiveling between screens, copying information, and quietly compensating for systems that cannot communicate? In this episode, I spea...

23 Aug 29min

Preparing Small Businesses for Making Tax Digital With ANNA Money

Preparing Small Businesses for Making Tax Digital With ANNA Money

Could Making Tax Digital improve the way small businesses manage their finances, or will it become another administrative burden competing for an already crowded evening? In this episode, I speak with...

22 Aug 21min

Regaining Control of Enterprise Software With Origina

Regaining Control of Enterprise Software With Origina

Who really controls your enterprise technology strategy: your organization or the vendors writing its software contracts? In this episode of Tech Talks Daily, I speak with Tomás O'Leary, founder and C...

21 Aug 33min

Fixing Broken Customer Service Before Agentic AI Arrives With Parloa

Fixing Broken Customer Service Before Agentic AI Arrives With Parloa

Why are companies preparing for agent-to-agent customer service when many customers still cannot get a chatbot to answer a straightforward question? In this episode of Tech Talks Daily, I speak with L...

20 Aug 25min

Building an AI Ready Workforce Without Abandoning Entry Level Talent With Year Up United

Building an AI Ready Workforce Without Abandoning Entry Level Talent With Year Up United

What happens to tomorrow's leadership pipeline when employers automate the entry-level tasks through which beginners learn? In this episode of Tech Talks Daily, I speak with Gary Flowers, Chief Inform...

19 Aug 31min

Populärt inom Politik & nyheter

aftonbladet-krim
p3-krim
aftonbladet-daily
rss-expressen-dok
flashback-forever
svenska-fall
rss-vad-fan-hande
rss-sanning-konsekvens
rss-krimreportrarna
motiv
svd-ledarredaktionen
rss-krimstad
spar
rss-frandfors-horna
politiken
rss-flodet
fordomspodden
krimmagasinet
grans
olyckan-inifran