Tim Zonca, Commvault | Black Hat USA 2023
The digital landscape is evolving. Cyberthreats have become more sophisticated, data estates are growing, and IT resources are shrinking. Today’s organizations need a more proactive approach to protecting their data in an ever-changing threat landscape. And while traditional data protection solutions may play a pivotal role in recovering post-attack, they are reactionary, narrowly focused, and no longer sufficient.
Transcript
This is Textron tv. Hi, this is Shera Rubinoff coming at you live from Black Hat. I'm here with Tim Zko from Commvault.
Tim, such a pleasure to be speaking with you here today and welcome to Black Hat. Thank you. Can you please share with our audience who you are and what you do for Commvault?
Sure. Thanks, sheriff, for, for having me. I'm Tim Zaka.
I'm VP of Portfolio Marketing at Commvault, and there's a few different functions that that includes, but it's mainly, uh, customer marketing. So we have a really vibrant community of, of customers and partners and users. Uh, we have a a strong kind of advocacy group within that.
And so we, my team works directly with our customers and our partners, um, and kind of brings the, the, the feedback and engagement that we hear with them to then the product marketing team, which is the other group within the organization that I've run. So. Excellent.
And can you share with our audience a little bit about where Commvault sits in the cybersecurity sphere? You know, it's quite a large, vast, uh, area of cybersecurity. Love to hear where, where Commvault really lies.
Yeah. I think that the main place is, you know, most of the, the customers that we work with and, and CISOs or security directors, you know, they adhere to some sort of framework or, you know, maybe it's a Mitre or a NIST sort of thing. So if, if you take nist, kind of the, that last area is recovery or recovery and like we excel at that.
Um, so that's what our customers use us for. Um, we more recently have started using a lot of the kind of proven best practices and technologies that, um, other security experts use, but it's, it's all in service of, of making sure that a, you know, the, an organization can recover. Well, that's very critical.
We talk about being proactive and reactive in the cybersecurity sphere and in cybersecurity posture. So with the reactive piece is something really where you excel at? Yeah, I think, um, reactive insofar as, you know, making sure that people can recover, frankly, it's as easy as like, is their organization their business up and running, and is it serving their mission well, that's, can they serve their customers?
Can they serve their patients, their partners, their employees? Um, and so there's a part of it that is, is reactive in that, you know, after there's some sort of data incident or you know, a cyber incident and you need to recover. Yes, yes.
That's reactive. There's a whole set of, um, things that we also not only offer, but suggest people do that, that's more proactive in nature. So making sure that, um, you know, people have early warning, like, are there bad actors kind of knocking around?
And so you don't wait till it's time to recover, but you're always in a constant state of recovery readiness. Well, That's critical, proactive reactivity going hand in hand in the same strength. So it's very excellent that you do that as well.
So how has the digital landscape evolved and what challenges do organizations face in protecting their data? And that's been a question on people's minds and there's lots of different answers around that, and I'd love to hear what Convolt and what your, your offering is and how you actually face that. Yeah, I think there's two really big categories of of shifts in, in evolution that we've seen.
Mm-hmm. And I think one is, um, and it's been going on for a while, is like, you know, people call it like the move to the cloud or whatever it is. Yeah.
But their data's just distributed everywhere. Correct. And there's no future where that's going to be any less distributed than it is today.
And so is it across clouds, is it across data centers? Is it across regions? Is it across apps, partners?
It's all of it. It's everywhere. And, and so, so that's just made kind of good old recovery, really hard.
And so I think that's a big shift is that just that data sprawl. I think. Um, then the other big shift is, uh, the, just the impact that the skyrocketing cybercrime has also had in light of that already complex set of, you know, kind of processes and, and tasks and protection in that, you know, bad actors today are, um, quieter than they've ever been.
Sure. Even just, okay, hackers can be great with, you know, off the shelf, uh, tooling. Uh, so threats are just more pervasive, they're more autonomous.
And so I think those are the two biggest sets of, um, of kind of trends that, that are really shaping the conversations we have with our customers and, and the way that they implement our, our technology. Sure. And when we talk about data protection and data security, what traditional data protection solutions are no longer sufficient in addressing cyber threats?
Because a lot of organizations say, listen, we only have certain budgets that we could use to spend on dealing with this area. So why are they no longer efficient and why do they have to look elsewhere in order to have that proper protection? Well, I think it goes back to those kind of two big shifts.
Yeah. So if you, if you believe that, you know, data's distributed and, and it keeps, it's, it's more and more distributed and that, um, you know, cyber crime is, you know, more sophisticated in advanced than ever. I think where they, where a lot of solutions fall short in, in the market are, you have a lot of solutions that were, we're kind of born in, in a traditional world.
So they're, they're good at managing kind of on preemie, you know, data center sorts of, of workloads. And then they struggle when they need to, to burst out and, and kind of protect cloud workloads or maybe recover to the cloud. You have the opposite, which is you have more kind of cloudy borne or kind of cloud native or you know, kind of cloudy solutions.
They're usually pretty proficient at helping protect, um, data on the edge. Uh, but then vice versa, they're not super proficient at also protecting things that are a bit more traditional. Sure.
And then you have this, this group that's kind of in the middle, these tend to be organ, uh, vendors that have usually, like their history is around like an appliance for managing stuff. And so they give you some cloud management capabilities, but it's really inefficient and hard to then, you know, burst to the cloud when you're, uh, you know, trying to recover fast, you know, and at scale and cost effectively. Those just come to their knees.
And so the, the result is you have these organizations that are cobbling together, you know, a whole bunch of solutions and, and it's just painful. I mean, it's, it's really, well, there's the Gap and the security there 'cause you, well, and then I think that that totally widens the gap because you have multiple interfaces, multiple approaches for frankly doing the same thing, which is, is my data resilient and is it recoverable? Certainly.
And so I think it, it just exposes additional risk. Yeah. Well there's a lot of organizational talk about overlaying different technologies on each other, but then there's also the security area and the security factor.
When you look at that and putting cobbling, as you mentioned, once security solution over the other, there's gaps in the security, but also you have to really keep an eye on every single little piece. One goes down, it all goes down. Yeah.
So can you talk a little bit about the recovery, just how that really would work a step-by-step guide maybe to our audience? They could really understand what that would look like. Yeah.
I mean, I think there's, there's a few fundamental attendance. I I think even before you recover one of the things that there's, there's, um, we also really think a lot about like recovery readiness. Sure.
And so, um, you know, before an incident occurs, do you, you know, are do you have layers of, of your recovery processes and kind of your backups, you know, ready to go? Uh, do you have versions that are kind of immutable and indelible and are they stored in an kind of air gaps, you know, cloud fashion so that, um, you, you can also, you know, you can ensure that you're recovering those, are you, are you confident that they're clean? Yes.
Um, and so do you have a clean recovery point? Um, so there's, there's notions of just constant verification or validation rather that, uh, that we think are important that, that starts even before this is like, you need to get to the point of recovery. Think Somewhat training.
I think it's training. Like I, it maybe it's just my, my bias having come from kind of a DevOps world, but it's just like that kind of, um, you know, they have like kinda C I C D in a software production context. It's like this notion of kind of continual testing and continual integration.
Like that's, are you always ready to go and when you need to? Can you are, are you ready to go? That you can always win when things, you know, like in the software, like you need to push to production, like when you're ready to go and you need to go and, um, back up.
Do you know what it is? Is it, are you sure it's clean? Do you, um, and are you backing up just what you need to, not everything.
'cause that becomes costly and slow as well, and kind of just confusing. Well, also there's extra data out there that you really don't need. Yeah.
And having that extra data out there could also be a security risk for organizations. Yeah. So cleaning up that data is important as well.
Well, and that's a big challenge I think a lot of organizations face, going back to one of your early questions, which is, you know, what's, what's challenging when you have all these point solutions? Because if each one's doing it a different way. And, and one of the unfair advantages our customers have is some of the kind of just unique capabilities we allow for having that precision.
So you're backing up just what I'm, I'm sorry. Restoring just what you need. Yeah.
Um, whereas with many other technologies, you gotta do it all and, um, slow, expensive and kind of just really inefficient. Sure, Sure. And when we talk about the cybersecurity world itself and what CISOs are struggling with, and they're struggling with budgets, they're struggling with getting the right solutions implemented, proactive and reactive cybersecurity posture, being worried about ransomware attacks and the like.
What advice can you give CISOs when they look at it and say, where do we even begin? Where do we begin to expend our dollars? I I think, you know, I'm going to speak with the obvious bias of coming from kind of a recovery world.
Yeah. So, um, I, you know, they wouldn't wanna listen to me and like, Hey, what should we be doing? You know, in it's some, some other aspect of, you know, like let's say network protection or something like that.
But where I think, um, the CISOs that I work with, what they, what I've heard from them, so I'm kind of just parroting them. It's like, look, if we don't have a strong recovery plan in place, it's, it's like walking across, you know, the Grand Canyon on a tightrope with no safety net. Of course.
And so, so prioritizing that as part of their portfolio of, you know, high priority investments, we think is just critical. Uh, and the CISOs I work with think it's silly to not do that and or irresponsible whatever, whatever your word is for that. So I think prioritizing a strong recovery practice.
And I think the second thing related to that is, is in the, the security and data protection ecosystem is so strong, uh, now, and it's, it's really straightforward due to integrate with different solutions. And so, you know, prioritizing recovery, but then prioritizing the ability for systems to talk to one another so that, um, you know, you don't have multiple like single panes of glass. 'cause then you have, but like that the right apps are talking to the right apps so that people are able to work in their context, keep their data safe and, and, and recoverable without having to, to skip across a lot of interfaces.
I think that's like what I would put as like a second tier priority within that recoverability. That's reasonable. Certainly.
And if you had to speak to our audience and say, how does Commvault stand apart from its competitors and why is it something that you really need to look at? Can you explain that to our audience a little bit as well? Yeah.
I think there's, um, a few things that we do that are, are unique and, um, when our customers look to us is, I think the first thing is that we deploy, um, security capabilities in the context of recovery. So, um, one of them is early warning. Yeah.
So it's, I think it's tempting for threat, uh, actors to, to um, say like, I'm not gonna go kick around in production because there's trip wires all over the place and I don't wanna make any noise. Sure. And so a lot of times they'll go and they'll target the, the backup and recovery environments and infrastructure where there may be fewer trip wires there.
Correct. So one of the things that we do is we give customers early warning that spans both of those kind of production and um, kind of backup areas. So it really makes sure you have a strong moat, uh, you know, around that.
And, um, so that if someone comes knocking you are, you are ready. And, um, and you can, and, and that's a sophisticated set of, of capabilities. So we just embed it in the, the daily workflow of a typical data protection engineer.
So for example, you're spinning up a new environment, I need to back up my M 365 environment, like, Hey, do you want to throw some early warning out into these environments? Here's what it looks like. Here's your recommended density.
It's just part and parcel with what they're doing anyway. So that's something that, um, only we do. So, so no one else, uh, does that.
And then I think the second thing is, as you are protecting your, your estate, um, no one covers in this distributed world, no one covers the breadth of, um, that estate like we do. And so we don't care if it's, you know, uh, in the cloud, if it's a SaaS app, if it's on-prem, if you think, well, hey, I'm guarding this and protecting this on-prem, but I want to be able to burst to the cloud and recover there. Like, we got you covered.
Right. So the portability is also, um, just un you know, unparalleled. And, and I think those are a couple of the, the main things that our customers look to us for.
And, and I think then the third and final is just what we've always historically been known for is we recover, uh, faster, um, more efficiently and at the lowest T C o by at least a factor of three. Wow. Um, compared to any other provider out there.
Oh, that's excellent. And I, I actually like the way that you highlight, you know, the backup and recovery that is it clean? You know, a lot of organizations, and when we talk about in the cybersecurity world, we talk about the data, are you protected?
What are you doing? Is it, you know, up to snuff in different areas, but no one's really focusing, or I haven't really heard people focus about the clean data that you need to be when you recover. Is that clean?
Do you know that you're not putting in problems when you have to recover? So I think that's very important that you highlighted that and you spoke to that. And I'd love to for you to speak a little bit further on that topic itself about clean data and making sure it's clean and how that is done.
Yeah, I, I mean, I think it, it goes back to something we were just talking about, which is if, you know, if you're a bad actor and you are looking to, you know, compromise an organization, um, going and kicking around and making noise in production is like a really risky, uh, thing. Sure. So if you can embed yourself into what's going to get recovered mm-hmm.
After an incident Sure. Um, if, if an organization isn't set up well enough and they don't have as, as as many, you know, trip wires listening for that sort of, uh, activity. If they don't, uh, if they aren't looking for anomalies, I mean, encryption has gotten so quiet and that it's, it's hard to detect those sorts of things.
There's living off the land attacks. And so if, if, or if, uh, if a, a bad actor can go in and embed, you know, malware or whatever the, the attack is into a recovery, you know, uh, kind of the backup data, and then they could just go knock over production. Well, and then they gotta sp you know, what do you have to do?
You have to recover. Sure. Um, that is, I, I mean that's why it's so important to, to make sure that you understand and have a high degree of confidence that indeed the, you have a clean recovery point, um, you're recovering to a clean location.
And, um, and you could do that, you know, if you're, if you were planning on doing that to, let's say an on-prem data center, your private cloud, and you need to do it in the cloud, like you should be able to do that on the fly. And I think it's that, um, I think that's the, where the importance of like cleanliness, uh, indelible storage and thing and capabilities like that, I think are really paramount for, to have a really strong, um, healthy and I think just highly confident and resilient system. No, well, thank you for that.
That's important. And I guess another question that's always on people's minds is how easy is it to implement your solution? What does it take for an organization to do that?
So I don't want to knock on all the marketing people that might be, uh, listening. I'm a mar but I'm a marketing person. Uh, I was able to do it in, you know, a matter of a couple minutes.
Wow. Um, so, uh, it's as easy as, you know, signing up and getting going and, and you know, what I did is like easy M 365 environment, or maybe it's Kubernetes or something like that. Yeah.
So you can spin us up in a matter of moments. And then we have like really sophisticated, um, installations with customers where it is distributed data and it's across multiple clouds and multiple regions and multiple private clouds. Um, and, uh, we kinda span the gamut.
So it's, you know, anywhere from someone like me doing it in a matter of moments to a really sophisticated, uh, setup, uh, and anywhere in between. Excellent. And any other cybersecurity points or helpful hints you'd like to share with our audience?
I always like to ask the people that I speak to. What else can you share with our audience, even in the cybersecurity world itself, some pointers or some helpful hints? I, I think the biggest one, to me, again, it has the bias of, of coming from, you know, the of vendor that leads the, the resilience and recovery space is, um, going back to your question around the role that recovery plays in in security, it, it, it's kind of disheartening to see a lot of just like the confusion out there because it's, it's attractive to, you know, talk about what you do from a security perspective.
And, uh, I think when that gets confusing is when you have vendors that actually don't really do security labeling themselves. You know, like we do security. Yeah.
And it, and it, and it does a disservice to the security and the IT teams that are trying to protect their organizations. And so I guess my guidance is as you, as you work, um, as you flesh out and you evolve your recovery plans, um, you know, of course it fits a, a security framework, you know, like a NIST or something like that. Yeah.
And you're going to hear about things like early warning and risk analysis and threat scanning and anomaly detection and things like that. But, and at least for conva, like we do that in service of your recovery. Yep.
And so, um, I think the guidance is to just don't be, um, you make sure that you understand kind of where your, your providers, their sweet spot is and where they fit across what's a pretty sophisticated and complex landscape of, you know, myriad vendor offerings across, you know, a, a wide gamut of practices. Of course. That's such sound advice.
Well, Tim, thank you so much for your time today. Thank you. And I'm really happy we were able to talk today, today during Black Hat.
Yeah, I appreciate it. And for our audience, please stay tuned and we'll be coming back at you live shortly. Thank you.





