Commvault: Why Your Disaster Recovery Plan Could Make Ransomware Worse
Neil C. HughesJuly 20, 202600:30:06

Commvault: Why Your Disaster Recovery Plan Could Make Ransomware Worse

Could the disaster recovery plan designed to protect your company make a ransomware incident even worse?



In this episode, I speak with Darren Thomson, Vice President and Chief Technology Officer for EMEA at Commvault, about Resilience Operations, commonly known as ResOps, and why cyber recovery now requires security, infrastructure, identity and data teams to work from one coordinated plan.



Darren argues that many companies are accepting a difficult reality. Even with considerable investment in prevention and detection, a breach may eventually succeed. That does not make cybersecurity controls any less necessary, but it means recovery can no longer be treated as a secondary activity managed by another department.



The problem is that security operations and infrastructure teams have traditionally worked toward different objectives. Security specialists concentrate on identifying and stopping threats. Infrastructure teams protect data, maintain backups and restore systems after outages. During a cyberattack, a successful recovery requires both sets of expertise.



A backup administrator may be able to restore data quickly, but a forensic specialist must establish whether that data is clean. Without that confirmation, the company risks restoring malware and restarting the incident.



Darren explains why a conventional disaster recovery plan may be particularly dangerous during ransomware. These plans were commonly designed for physical failures such as a lost data center. Data would be copied from one location to another so operations could continue. If the source data is infected, however, fast replication can carry the malware into the recovery environment.



This is where ResOps enters the discussion. Darren describes it as an operating model rather than a product. It combines established practices from security and infrastructure management into a continuous program for testing, learning and improving recovery. Individual technology projects may come from the program, but resilience itself never reaches a final completion date.



AI adds pressure on both sides. Criminals can use it to create faster and more effective attacks, while defenders can use machine learning to inspect large volumes of information, detect patterns and identify the newest clean recovery point. Companies must also protect AI systems as they would any other business application, including the models, data repositories and identities connected with them.



Darren offers one practical starting point for CIOs and CISOs: Mean Time to Clean Recovery, or MTCR. This measures how long it takes to restore an application and its data with evidence that both are free from compromise.



Before measuring MTCR, leaders must define their minimum viable company. These are the systems and services the business cannot operate without. Once that list exists, teams can test how long a verified clean recovery would take and replace assumptions with evidence.



The initial answer may be uncomfortable. Teams may know how to restore an application without knowing whether the backup is clean. Security may know how to inspect the system but lack an established workflow with the recovery team. Darren sees those gaps as the starting point for a useful ResOps program because they provide everyone with a shared problem and a measurable objective.



If your most important systems disappeared today, how long would it take to bring the minimum viable company back using verified clean data? Listen to the episode and share your answer with me.