testing sdx crop
– Ton Photograph/Getty Images

Commvault announced that Commvault Cloud Cleanroom Recovery is expanding and will soon be available to its software-as-a-service (SaaS) customers. The company aims to give enterprises of all sizes modern recovery and testing capabilities that are critical in today’s ransomware era. It says it’s also adding functionality to help speed up recoveries and improve security. Commvault recently announced it was acquiring Appranix, a cloud security company that should add to its cyber resilience play.

I recently had a briefing with Thomas Bryant, director of product marketing at Commvault, ahead of the Cleanroom announcement. He put Cleanroom Recovery in context.

Ransomware is everywhere

“Before I even get into Cleanroom, we have to acknowledge how the landscape is in the world,” he said. “There’s ransomware everywhere. Every week, it’s a new hospital, a healthcare company and/or a petrochemical company. It’s not going away. It’s the new normal, and if people don’t realize it’s the new normal, they will find out when their company’s name is in the news.”

He said that even large enterprises hit by an attack still have trouble recovering. “It takes a long time,” he said. “We see that 23 days is the industry average. And we see even longer from many organizations. It takes them months to recover. And that costs them not only money from a potential legal standpoint – but also lost revenue, the loss of reputation and brand image.”

Testing and retesting

Commvault says that Cleanroom Recovery can rapidly test and retest cyber recovery plans across a customer’s IT infrastructure. Commvault's Cleanroom Recovery isn't just about recovery but continuous validation against emerging threats. The service incorporates AI to simulate evolving ransomware attacks, offering businesses a real-time gauge of their defenses and preparedness.

Cleanroom Recovery should help companies recover in the aftermath of an attack. Plus, Commvault says that it will help meet the requirements of security legislation that is proliferating around the globe, including the EU’s Digital Operational Resilience Act (DORA), Australia’s Infosec Registered Assessor Program (IRAP), and the new cybersecurity disclosure rules from the Securities and Exchange Commission (SEC).

After an attack, Cleanroom Recovery creates a clean location in Microsoft Azure, which opens the cleanroom concept to companies that can’t afford the expense of an on-premises setup.

Commvault’s idea might seem like disaster recovery. But it’s different, Bryant said. The scenario-based testing offered by Commvault allows companies to confront their systems with various attack vectors, assessing their response in controlled yet intense environments. This targeted approach helps organizations understand where they are most vulnerable and how to prioritize their defensive efforts. With Cleanroom, he said, you turn it on. There is no need to worry about starting everything up and ensuring you have authentication with Active Directory, DNS, etc.

“There are all those things that people don’t think about that are the kind of plumbing to your enterprise applications, all the things that generate revenue,” he said. One notable aspect of Commvault's approach is its emphasis on granular, frequent testing. This allows businesses to verify their resilience and fine-tune their recovery strategies continuously, staying a step ahead of potential attackers.

And it doesn’t end there. With traditional cleanrooms, Bryant says, figuring out how the bad guys got in and what they did is often overlooked or ignored because it requires a specific setup – a massive cleanroom operation with pricey new hardware isolated and unsullied by the attack.

“Nobody really has a true cleanroom, or if they do, they’re generally the huge financial institutions that can afford that,” he said. “And that’s what we’re trying to do with Cleanroom – start with testing, do forensics, and then you do need to failover, and you’re going to failover, generally, where you test.”

An acquisition to bolster recovery

Alongside the Cleanroom news, the company’s recent announcement of acquiring Appranix adds to its capabilities. Appranix specializes in rebuilding cloud applications for companies recovering from ransomware attacks. Recovering data is one thing, but companies must also rebuild the cloud apps to be resilient. Commvault says it will bring together the four R’s: risk, readiness, recovery, and, with Appranix, rebuild.

Commvault says the Appranix team will join the company imminently and integrate the tech with Commvault’s portfolio by the summer – around the same time that Commvault’s SaaS customers can access Cleanroom Recovery.

Organic and acquired technologies

Commvault’s approach of blending a mix of homegrown and acquired technologies simplifies and, with Appranix, speeds up the time to recover. Ransomware is disrupting businesses of all sizes.

Many big-name enterprises with seemingly endless resources have paid substantial ransoms. Some recent examples are CWT Global, which paid 4.5 million to cyber criminals, while the U.S. Marshals Service had sensitive data stolen in a ransomware breach. In many cases, data is never recovered even when companies pay the ransom. Such an attack can sink smaller companies that do not have the resources of global enterprises. That's challenge Commvault hopes to overcome.