Cyber resiliency is a key focus for us: Balaji Rao, Area VP – India & SAARC, Commvault

Balaji Rao

In a recent exclusive interaction with CRN India, Balaji Rao, Area Vice President – India & SAARC, Commvault, sheds light on Commvault’s current strategy, focusing particularly on cyber resiliency amidst the rising threat of cyber attacks. Rao discusses the pressing need for businesses to prioritise recovery strategies in addition to strengthening security postures. He also emphasises the importance of board involvement in investing in security and highlights Commvault’s engagement with partners and customers in India.

Can you provide an overview of Commvault’s current strategy and focus?

In India and the SAARC region, the time is ripe for customers to invest in cyber resiliency. Despite increased investments in cybersecurity, the number of breaches and ransomware incidents continues to rise. Globally, there is an estimated loss of about $30 billion, projected to grow into a $100 billion industry within the next five to seven years. In India alone, 2022 saw approximately 1.9 million cyber attacks. 

The continuous growth in risk, coupled with widespread digitisation and network connectivity, has led to an overwhelming number of vulnerabilities. Every device connected to the network, from printers to cameras, has an IP address, creating numerous potential entry points for attackers. Given the limited budgets, it’s becoming increasingly challenging for customers to plug all these holes.

While improving security posture and plugging vulnerabilities are necessary, they are not sufficient. Companies must also focus on recovery strategies. Data, being the most critical asset, must be protected under all circumstances. Hence, the only way for companies to secure themselves is by ensuring they have a robust recovery strategy. This involves not only processes but also a comprehensive approach to recovering data.

Referring to the classical MITRE framework, the recommendation is to “shift right” – moving focus towards recovery. After thoroughly assessing risks and implementing various tools, it’s crucial to have a solid recovery plan in place. Customers are increasingly concerned about scenarios where both their primary and disaster recovery (DR) systems are compromised by ransomware, and their backups are unavailable. According to a Microsoft report, in 98% of successful ransomware cases, backups are disabled.

To address this concern, the strategy involves building a cyber resilient framework that prioritises recovery. This strategy focuses on ensuring businesses can get back on track within a specified time frame after an attack. Given the increasing customer anxiety about ransomware, the goal is to become the vendor of choice for developing and implementing a cyber resilient strategy that ensures effective recovery in the event of a breach.

With the introduction of the Digital Personal Data Protection Act, 2023 in India, do you see any changes in your customers’ approach to security or compliance?

We do see these trends and more questions being asked on that side. So far, the number of questions on data classification per se was a little more theoretical. We used to talk about it, we always had the tools to do this, but it used to be a good conversation that never proceeded to purchase, implementation, etc. But now, the questions being asked are a lot sharper because there is a fine. Yeah, earlier, the law wasn’t stringent, but now there is a fine of up to 250 crores. It used to be two percent of the turnover, so whatever that amount is, it’s getting them worried.

So, the questions now being asked are, “When I back up data, can I find out if there is an Aadhaar card in that? Can I see if there is a photograph in that?” Those kinds of questions are coming up. We do all this, by the way. We can provide them that data so they can segregate it and keep it in a separate place as PII (Personally Identifiable Information) and probably safeguard it a little more with limited access rights, etc., so that it doesn’t fall into the wrong hands and they get fined.

So, we do all this, but rightly so, and also customers are asking this question: “Is there a way we can delete data after our retention period?” Earlier, the vision of data was just to keep hoarding data. Nobody deletes data. But now, I hear a few questions coming up on that side saying, “We have a nine-year retention cycle. Can you automatically delete it?” Probably, they’re less liable if they delete data rather than just hoarding data. So, that’s one of the things.

So, they’re looking at that data landscape and how to segregate, keep PII separately, and how to secure that. All that kind of stuff is coming up now.

Do you have any success stories related to cyber resilience or ransomware in the Indian sub-region?

Certainly. Cyber resiliency is a key focus for us, and Persistent Systems offers a notable example. Persistent is a global IT services major, listed in India, with a strong international presence. They do significant work for IT majors, including product development. Persistent uses our SaaS solution, Metallic, which we call Commvault Cloud.

Persistent took a comprehensive view of the cyber resiliency landscape. The board was clear about their desired RTO (Recovery Time Objective) and RPO (Recovery Point Objective). They aimed to build a robust cyber resiliency framework that included cyber insurance, necessary tools and technologies, especially in cybersecurity, and a recovery strategy.

We assisted Persistent in transitioning from on-premises to a pure cloud environment, specifically moving to Azure. They shifted their entire physical data centre to Azure, opting for a pure cloud story rather than a hybrid model. This involved moving data from on-prem VMware to Hyper-V on Azure, given that India Azure doesn’t support VMware. We facilitated this with our ability to transition across hypervisors, automating the data move on the fly.

Additionally, we implemented an air gap copy, ensuring secure, application air gapping and immutable storage within Azure. Our Azure product inherently includes these features, making it straightforward for any user to push their data into the air gap for secure storage. In case of trouble, data restoration is seamless.

Persistent also conducted cyber resiliency testing in Azure, focusing on how quickly they could restore data and resume business operations. Initially, restoration testing took about three days, which was reduced to a day, and ultimately to eight hours and 20 minutes in the final test. Their RPO, expected to be an hour, was achieved in just 22 minutes. These impressive results, which we can share, demonstrate Persistent’s successful implementation and the effectiveness of our technology.

Most organisations focus on building an air gap but fall short on cyber resiliency testing. Persistent went beyond by testing their system extensively and running their entire organisation from the restored data for a day or two, ensuring they could survive a breach.

This success story showcases how Persistent, with our Cloud powered by Metallic, built and validated a comprehensive cyber resiliency strategy, setting an example for other organisations.

How do you see the board’s interest and involvement in investing in security?

I think it’s a good question. There are two key points here: physical security and perceiving it as a business risk rather than just a technology risk. Various global data indicates that boards are taking this extremely seriously. In fact, boards are now demanding an RTO and want to know how quickly the organisation can recover and what metrics are in place. For regulated industries, the requirements are even more stringent because regulators are asking these questions and want to know what safeguards are in place. 

Overall, there is a very strong push in this direction, recognising that this could be an existential crisis, especially given that everything is digitised. If we lose access to our data, how will the business continue to operate? Most boards have woken up to this reality. Those who have experienced breaches firsthand are even more aware and proactive. They’ve seen it, lived through it, and now know exactly what needs to be done. 

So, yes, boards have taken this up as a very serious action item, with regulated industries leading the charge.

How are you utilising AI for cyber resiliency and data management to enhance your data management solutions and protection?

For us, AI serves multiple purposes, primarily enhancing efficiency, scanning for threats, and addressing customer training and enablement needs. From a security perspective, we leverage AI extensively to detect ransomware-related risks. Its rapid data processing capabilities allow for thorough scanning across vast datasets, enabling pattern matching and identifying changes indicative of potential threats. We’ve integrated AI into our threat scanning solutions, strengthening our ability to detect and mitigate malware by leveraging comprehensive malware databases.

Additionally, our AI-powered assistant, Arlie, plays a crucial role in assisting customers. Arlie offers code assistance for API generation, aids in navigating software interfaces, and ensures data safety, especially in large data lakes. One notable feature is its real-time analysis, providing detailed reports and insights. For instance, users can effortlessly inquire about backup failures or seek integration guidance with specific security frameworks like Palo Alto, with Arlie promptly generating the necessary code.

In practical terms, Arlie simplifies complex tasks by guiding users through software interfaces step by step, similar to having a personal assistant. Moreover, it streamlines reporting processes, allowing users to obtain critical information swiftly and effortlessly. Overall, AI continues to play an expanding role in our operations, streamlining tasks, recognising risks, and enhancing overall efficiency.

Is it only operative in English?

Yes. One of the most practical applications of AI is in situations like ransomware attacks, where recovering data becomes critical. In such high-pressure scenarios, the IT team, along with the board and CEO, are under immense pressure to restore operations swiftly and securely. In these instances, relying on a last known good copy becomes crucial. With AI, we can predict which data copy is clean and safe to use for recovery. This ensures that the restoration process is efficient and minimises the risk of inadvertently restoring malware-infected data. Without the need for writing code or scripting, AI streamlines the recovery process, saving valuable time and resources, especially when dealing with large datasets that would otherwise take hours to recover. This capability provides peace of mind and confidence during data recovery efforts in ransomware situations.

How do you balance the role of AI, considering it both enhances as well as assists in mitigating risks?

We’re very deliberate about the extent to which we employ AI. Our ethos revolves around safeguarding data rather than flaunting technological prowess. In today’s landscape, data protection is important, given the relentless pursuit by malicious actors who seek to compromise it for ransom or other nefarious purposes. As threats evolve, including polymorphic threats that alter their signatures hourly, our approach must adapt accordingly. We recognise the imperative to fortify our AI solutions to detect and thwart these emerging AI-driven threats. It’s a delicate balance wherein we counter AI with AI, leveraging advanced algorithms to intercept and neutralise potential threats before they infiltrate systems. This strategic focus underscores our commitment to furnishing customers with robust AI-driven defences, ensuring that even the most sophisticated threats are swiftly identified and mitigated.

How do you engage with your partners and customers in India?

Our partnerships span a wide spectrum across various sectors of our business. We collaborate with Global System Integrators (GSIs) such as Infosys and Wipro, who operate on a global scale. Additionally, we engage with managed service partners like NTT and Yotta, offering colocation or shared services to customers. Tier two partners contribute by integrating systems, combining servers, storage, and our software to deliver tailored solutions to customers. Hyperscalers like AWS, Azure, and GCP are also part of our partner network, alongside Original Equipment Manufacturers (OEMs) like Hitachi, NetApp, HP, and Cisco, who bundle our solutions with their hardware offerings. Our approach ensures customers have a range of options, as we do not endorse any single proprietary appliance. As a software company, we prioritise collaboration with partners, providing certified architectures for various platforms like NetApp, Hitachi, and Cisco, ensuring performance, scalability, and reliable support.

In today’s landscape, openness is important, especially regarding cloud integration. We empower customers with the flexibility to recover data either on the cloud or on-premises using IP, enabling them to spin up multiple VMs and execute recoveries seamlessly. Our clean room recovery feature further enhances this capability, allowing recovery in any location or environment. By leveraging software solutions and maintaining partnerships with open systems and diverse vendors, we enable customers to establish secure and adaptable data recovery mechanisms, regardless of their chosen platform or infrastructure.

What percentage of your business would you estimate is attributed to channel partners?

100% of our business is through channel partners in India.

Do you offer any specific incentives or training programs for your channel partners?

Yes. We have a highly competitive channel program, mainly for our tier two partners. Our program not only offers enticing incentives but also ensures that our partners are equipped to meet certain performance benchmarks to earn rebates. We also extend these incentives to our field teams to boost motivation in promoting Commvault products. Regular training is a fundamental part of our approach; we recently conducted our channel bootcamp in various cities this quarter, with plans to continue in the next quarter. These sessions provide comprehensive training and are followed by hands-on programs to familiarise partners with our tools and technology. Our current focus lies heavily on enablement, particularly in light of the evolution of backup into cyber resiliency. It’s imperative that our partners grasp this messaging and possess the requisite skills to deliver on it, thus providing customers with ample options for procuring and implementing Commvault solutions.

What are some of the key positives we can expect from Commvault in this region, particularly in India, in the next six to twelve months?

I believe we’re observing a trend in the recovery domain, as I mentioned earlier. Customers are still in the process of establishing air gap solutions, and clean room recovery is becoming a significant focus for many. Some customers inquire about having an air gap copy for protection but wonder where to restore from. Thus, the recovery aspect, particularly clean room recovery, is something customers are eagerly examining. We’re partnering with Microsoft to offer a guaranteed malware-free environment for recovery, which is generating anticipation among customers.

Additionally, we’ve introduced Commvault Cloud, a unified dashboard for all services, addressing the challenge of managing multiple dashboards. This consolidation simplifies operations for our customers, making tasks like email archival and desktop backup more streamlined. The integration of everything into one console, with both SAS and software offerings, has significantly eased the process for our customers. 

The adoption of SAS is expected to increase further, given its simplicity. With our air gap copy available on Azure and soon on other hyperscalers, customers can seamlessly push data from Commvault software, whether on-premises or SAS, to the air gap copy for recovery. This service-oriented model eliminates the need for system integration and the purchase of storage servers, making it hassle-free for customers.

Moreover, by leveraging our storage on Azure, located in India, we help customers avoid additional charges associated with data transfer between hyperscalers. This straightforward approach is anticipated to drive increased adoption of air gap protection in the next six months.

Regarding security, we’ve enhanced our AD protection significantly, addressing concerns about communication backbone integrity. The advanced functionality, integrated with Microsoft products, offers granular features to mitigate risks effectively. We foresee a rise in adoption of this enhanced protection as organisations prioritise safeguarding their communication channels.

In our commitment to enhancing cyber resilience, we continue to integrate with various partners to ensure relevant dissemination of cybersecurity insights. This involves integrating with SIMS, ADRs, XDRs, and other tools where cybersecurity expertise resides. While we’ve made considerable progress in this area, we’re continuously expanding our partner ecosystem to strengthen our cyber resiliency journey.

Source Link

LEAVE A REPLY

Please enter your comment!
Please enter your name here