AI-Powered Cyber Resiliency – Brian Brockway, Commvault
On Nov. 8, 2023, at its SHIFT event, Commvault announced the largest pivot in its 30-year history with the launch of a new AI-powered cyber resiliency platform and a new ecosystem of partners. The new direction and ecosystem will help businesses meet the ever-complex security demands created by generative AI and the rise of ransomware and help protect global businesses from cyberattacks. The pivot couldn’t come at a better time, with IDC reporting that only 33% of CEOs are involved in their company’s cybersecurity preparedness initiatives-even though 61% expect a threat in the next 12 months.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
I'm really happy to be joined by Brian Brockway, CTO at Conva Brock, as we they call him, is here to tell us about some exciting, uh, happenings going on at Commvault, kind of earth shattering for the folks at Commvault even, or fans of the company. But before we get there, let's welcome and find out a little bit more about Brian. Hey Brian, welcome to Tech Drunk tv.
Hi, Alan. Uh, thanks for having me and, uh, and, and great to join everyone today. Fantastic.
So, Brian, you're, as I mentioned, you're CTO, but, uh, at Commvault, but let, let's hear a little bit more about your journey, if you don't mind. Oh, uh, uh, thanks for, thanks for the opportunity. Yes.
So I've been, uh, I'm just finishing my, uh, my, uh, probation period. So I'm sitting at about 21 years in the company now. Um, so You're a newcomer, you got it.
Rookie. Yeah. So he started, uh, many years ago, ran products and, and uh, kind of worked hand in hand with, uh, uh, everything we built in the core foundations and things like that.
So, I'm gonna say the first, the first, uh, 10 years was building out a lot of the platform and, and all the other fun pieces and kind of some transition a couple years ago as we, as we started to shift to the CTO, uh, roles and things like that to say, how do we get out with customers and really make sure everybody can take full advantage of the products we we put together. So it's not just we drop a bunch of products in your lap, how do you understand how to use 'em? How do we really get those outcome benefits?
And I'll say, uh, Alan, as, as you've seen from, from the years, uh, we've always been recognized as a real innovative leader. And I will be the first to admit, it's not that we were all super smart and we could predict a future if we could, we'd may be retired on islands right now. You would be both Doing is listening with customers.
So if we can listen to customers understand what's the challenge, where they're going next, that's where we come back over rapidly iterate back into the product, and then we're able to kind of meet 'em, uh, meet 'em together with a great outcome. I love it. I love it.
Um, you know, Brian, a lot of people out here in our audience, they've heard of Commvault Commvault's, kind of a, a name that's been out there, and many of them will say, oh yeah, Commvault, I know those guys. I know what they do, but they don't really know what they do. If you don't mind, let's just delve in a little bit to about the, you know, with the company more than you've already told us.
Sure. In terms of kind of the hist, you know, from a product, what we do point of view, who we are, Uh, that history. So let me start, uh, just like you said.
So, so we've been the, you know, uh, a recognized top leader, innovator, customer numbers, data protective, things like that for, uh, I'm gonna say really the last 12 years running from a lot of the analyst, uh, uh, analyst, uh, studies and everything else built on, built on customers and feedback, things like that. But to your point, a lot of that has been how do we come over? How do we condense, how do we automate, how do we help you do data protection in a faster, easier manner?
But as we all know, the last, I'm gonna say the last four or five years, uh, we're no longer coming back to just help fix mistakes, you know, or failures. Um, ever since 2017 when non petia hit, uh, the world changed and opened up to say, uh, cyber warfare is no longer between governments. Uh, it was now, you know, uh, being, uh, being conducted on companies.
So we had a couple of the, the primary, uh, companies that were affected by the non petti event where we all opened the, opened our eyes to what happens when you have to come back and rebuild the entire enterprise globally from the backup environments, which nobody thought, nobody even contended with that idea beforehand. Since then, we've been doing a lot of work to say, how do we take that to the next step forward? So it's not just about securing the backend, but how do we help automate, how do we help you really kind of, uh, derive and find the good stuff from the bad stuff?
Because, uh, when cyber comes over and it hits you, um, it hits you in a, in a hard, fast, and wide manner. And that's really where you need to be resilient. And resilient is kind of the whole nature of these days of not assuming you'll never fail, assuming you're going to fail, you know, and am I built to be able to handle failure?
So can I come back in my practice? Do I have the right kind of intelligence? Can I come back and sort out the bad stuff from the good stuff to get back, back to an operating business as quickly as possible?
And that's really a lot of our, our new shift of the capabilities we've had that have been kind of sitting some of them in bit in bits and pieces under the covers. We said, can we raise 'em all the way to the top level, really build them out in a much stronger, wider basis, and then bring that to not just the backup teams and the storage teams, but how do we then provide value back with the security teams? 'cause it's now it's a group of them.
Absolutely. Absolutely. So Brock, you know, there's that old Irish proverb that you live in interesting times.
Well, I don't need them this interesting to tell you the truth, right? It's, it's crazy times and in the world and on so many different levels, I don't even want to start, but we're also seeing in the tech space kind of, I just, you know, you've been around a while. Like I have, we, we've seen these sort of boundary layer points, right?
Where things just change, right? The internet, man, when the internet went commercial, everything changed beyond technology. Everything in civilization changed.
The cloud was a huge thing for us in tech, right? It just changed the whole way we, we look at running our stuff. I, I, I just feel like we're at one of these boundary points again where things just a lot's gonna change.
Where, you know, this, the whole c experience kind of force fed digital transformation on everyone. You had to figure that out yesterday. Um, but now there's AI and, and, and some of these quantum computing, there's so many new things that are just game changing.
I mean, they're game changing. And any company that doesn't, you know, it's, if you're not moving forward, you're dying. Right?
I heard that from a VC once. If you're not moving forward, you're dying commvault's no different. Right?
Absolutely. And is that, tell us, Let, lemme go back to one of the points you brought up on digital transformation. Um, it's something we all got forced into, like you said, uh, you know, suddenly one week we're all in the office.
The next week we're at home and we're at home for the next two years. And all of those discussions that we all had on, should we go remote, uh, suddenly became, you know, exercise strategy by the next Tuesday. Um, one of the great outcomes I think from there is, like I said, it, it changed how we interact, how we work, all the other kind of fun things.
But more importantly, it also increased a digital dependency. And I think as, as you said in a couple of different, different sessions and others, the, you know, the world these days is usually defined by, uh, by data. So the flow of data, the accessibility of data, if you've got a remote team that you're all tied together on a project, uh, the team only stays collaborative and they can only do things as long as they can all touch, you know, touch the data.
Uh, if somebody came over and took it away in the middle, uh, it's not like the old days where, you know, well, everybody's got their own paper copy and they can go off and finish the project and come together at the end. You know, now we're, now we're at, at a stuck point. So we're seeing this new working environments, this new digital dependency that's happening all the time.
And unfortunately, while that's happening, on one side of the coin, you have the other side of the coin of, uh, there's a lot of, I'll say bad actors, bad bad folks and others that are coming over to say, can they put exploits to it? Um, if you look at the, the cyber or the ransomware or the other type environments, and there's a host of numbers out there, uh, ransomware as a service is cited in some cases be almost like a $20 billion annual, annual business with a, with a 50% growth rate. So you look at this and saying, we don't die.
Damn, that sounds Like a great visit, but you're like, wait, this is, you know, criminal intent. You're doing bad things to bad people, holding them hostage. Um, and that's not a good thing.
And, but it's something that is rampant and it's happening through every facet of business, whether it's, you know, large government, multinational companies, all the way down through K through eight, and you see it in the headlines every day. Now it's hospitals. So hospitals get hit, hospitals have to go dark, you know, in some cases, and we've seen, you know, some examples out there, uh, and this is more I'll just cite out of the press to keep everything, uh, on the up on the upper level.
You know, you've seen evidence, uh, in the press of hospitals going down for 30 days. So they're in the dark. They can't, you know, they can't run normal operations.
And it's not just the hospital that takes the hit, it's the community around the hospital. Because in those 30 days, there's a lot of procedures, there's a lot of other things that are all being, you know, expected to be done that are not being done. So what we're seeing now is this problem set that we, you know, used to see, you know, was it just data had a failure?
Somebody made a mistake, somebody fat fingered something. Can I go back and revert it to now suddenly where digital businesses in every facet of life, if that digital flow, uh, stops and shuts down, the impact is not just on myself as a business, it's up and down through my community, who's in front of me, who's behind me, what's the impact that kind of goes all around. So that's why we're seeing this massive shift and change in realization that risk is real.
And there's a lot of organizations that are coming back over and saying, the only way for me to deal with this, I can't just pay more insurance. I have to have better tools. I have to be better prepared for this.
I have to practice for these. Uh, you can't show up, you know, at a, uh, at a football game and, you know, try to define your practice on the field the first time. That's a losing strategy.
You know, and not only that, you mentioned insurance. Look, cyber insurance is certainly something that a lot of companies are availing themselves, but the cyber insurance companies themselves are now becoming the enforcers. They're the new compliance chiefs.
They're the ones who are saying, look, you want insurance, you've gotta have this, that, this, and that. Absolutely. And we want to see it, and if you don't have it, we're going to impose it on you and charge you for it as part of your insurance.
Right? So in, in, in some ways, yeah, you can think insurance is going to save you, but, and it may because it's gonna force you to do what you gotta, what you, you know, what a reasonable person should do or a reasonable organization should do. Um, it it, it's crazy.
Now let's talk specifically. So Let me add one point to that. So I think what we all have to recognize too, is insurance in this kind of a case is different from car insurance.
Yes. So car insurance, I, I unfortunately No fault the, the Tree jumps in front of me, uh, right. I'm usually going outta pocket for 10% of the car insurance is covering the rest.
And a lot of cyber is the reverse. The cyber insurance is gonna give you 10% of your, your immediate recovery fees. The other 80, 90% that you're gonna be impacted with is coming outta your pocket.
And that's what we're seeing in a lot of organizations is when they realize it's not just, you know, I pay something quickly to get back. The get back is a lot longer if you haven't really prepared for it. Now you're saying as, as a business, if I, if I'm not getting, you know, the, the 50 million or a hundred million dollars that I thought I was gonna get next month, what does that do to me from a strategy perspective?
Do I have to completely change my business? Do I have to change how we're doing things? And that's, I think that's the reality that a lot of people are now realizing from others in their industry that have been impacted.
If they had one of their own incidents, hopefully it wasn't too big. And for some of those that it was a big impact and they realize how they were doing it in the past was wrong. That's where they're making the investments to say, is there a partner that has better capabilities, can keep it, you know, in a more hardened automated and intelligent, uh, context.
So the next time we get hit with this, we can react to it and, you know, not have the same kind of outcome like we had before. Yep. Agreed.
So this cyber resiliency platform, what, what more can you tell us? Sure. Talk to us.
So, so, uh, like I said earlier, uh, the, the first stage I'm gonna say in anything, uh, is even before you start to think about cyber resiliency is you have to say, do I have my house order? So do I have data copied protected? Do I have it in a couple of different buckets?
So, uh, in case I did have a failure at site number one, you know, storm, act of God, whatever it may be, uh, do I have another protected set of my data somewhere else? So that's, like you said, that's what we've been doing for a lot of years. How do we, how do we de-risk?
You know, how do we ensure you are ready if you need to go, but just being ready is not enough. This is where you really have to come back over and say, I need to add more intelligence to that process. Because quite frankly, nobody has a thorough understanding of what's inside their data until you go looking.
And usually what happens in some of these cases is you got hit last night and it's not just 10 systems that got knocked out. You had a thousand systems that got knocked out and your business is now down and you've gotta sort it out. The lights are out.
You have to come back and say, how do we at least try to get some emergency lighting back on? So we can try to sort out where are we, how far back do we need to go? Is it a couple hours?
Is it a couple of days? You know, have they been in the system doing bad things and we didn't notice it? So they've been actually, uh, uh, corrupting things for the last three or four weeks.
This is where you need that intelligence to say, now it's time for me to quickly analyze, understand the good from the bad, so I can take the bad off to the side to make a decision to say, how do I purge and get rid of it. And more importantly, then come back over and say, now I'm ready to come back and put what I believe to be the good data, but do I wanna do a couple of extra exercises to sanitize it before I put it back? So in a lot of our cases, it's how do you come over and do data recoveries, but I want to do some deeper scanning.
Uh, it's kind of the, uh, sign in a lot of restaurants, employees must wash hands before returning to work. Mm-hmm, same context comes into play here. Uh, I want to scan and scrub that data, uh, before I return it back to work.
'cause I wanna ensure that I'm not reinfecting it. So when you look at cyber recovery, it's coming above that data layer to say, how do I add some of these new capabilities, this new intelligence? It's a lot of deep indexing and other things that comes into play.
Fortunately for us, this is not, this is not a brand new game. Uh, we've had a lot of indexing and other capabilities in the products for years that we used on eDiscovery and other type cases. We had to take that forward and teach it how to come back over and understand these cyber problems.
How do we root out bad data from good data? And I'll say there's no, there's no definition of bad data versus good data. Uh, until we see your data set and you know, what is working, what is not working, That's where luckily Comes into play.
So Yeah, I was just gonna say that luckily, you know, necessity's the mother of invention and, and we happen to be living through a generative AI type of, uh, revolution here. Yep. So it seems to me we've got a great problem.
And, and here, here's something that could help You Got it. And, and the the nice nature, I'm gonna say, uh, I'm gonna probably get all of your listeners kind of up on their backs. When I look at ai, it's not only just the artificial intelligence, it's the automated intelligence.
So what do I mean by that? It's so coming over to say, can we, can we come over and look at those 10 systems or a hundred systems, index 'em and analyze and bring the facts back so your team can make a fast decision? What's good, what's bad?
Let's get rid of the bad and let's revert back to the good. Then we have good data in our hands, but then we have to say, how do we get it back into service? So that's where the automation comes into play.
How do we come back over and help you rebuild your applications? Is it just putting some data sets back on top of what was there before? Or depending on the kind of problems you had, you may have to come back over and completely rebuild systems from the ground up.
So it's really facets of how do these exploits happen? How deep did they get into your systems to compromise it? And then suddenly you may be coming back to say, now I have to go back and rebuild a thousand VMs.
I have to put 'em all back together as brand new images. I can't use the old ones, but then I have to be able to pick the old, uh, my application data outta the old ones, clean it, repopulate to the new ones, get 'em blessed by the team, and then get 'em back up in service. And I'll say, these are the actions that when you look at an organization, say you're gonna do a refresh of a thousand systems, they're like, yes, we have a, we have a 90 day plan of how we're gonna do that.
You know, on a rolling basis. Now you're like, well, now I'm in crisis mode. Uh, we, everything's knocked out from last night.
We have to get the thousand back into service as quickly as possible. And this is really where it comes down to, you know, how practiced are you? Uh, do you have some digital runbooks?
Uh, have you taken the time to come off and say it's not a thousand of the same, uh, it's not a thousand systems. Do I have 'em group, which are the ones that I make money on? Let's make sure we do those first, which are the ones that, you know, support the, you know, external sales teams.
I don't want them sitting idle. I need to get them up second. What are the third and the fourth and the, and the fifth group.
So it's putting process into play with the technology. And that's a lot of the new things we have. So some of the new capabilities of, like I said, the indexing, uh, to be able to help sort things out.
Something we call threat scan. So how do we use that automation as kinda like the MRI machine to come over, run your bad data sets through there, and it comes over to say, which is the, you know, which are the problem sets, and then how do we extract and curate them out? The other pieces are things we call auto recovery.
So how do you pre-program groups? So when you need to push the button and put 10 or 15 things back together, you don't have to kind of come over and figure it all out by hand. You've already got 'em, you know, pre-stage, pre-configured, and you can actually test that on a regular basis.
And then your, So this is, oh, I'm sorry. Go ahead. I'm sorry.
Uh, no, No, go Ahead. The final one is like, in a lot of the ai, like you said, uh, AI is more than intelligence. How do we come over and help automate, and we've been really diligent in trying to look at these processes that we've done with customers.
How have they gone through these exercises? What's the next questions they ask? If you have to do three more clicks and then go talk to somebody to get an answer, like you said, is that a better opportunity for us to use some, some AIG uh, GPT to come over and say, can I automate that response better?
So I'm not just writing you marketing emails, but I'm kind of looking at your problem, your context, and seeing if I can get you a faster answer so you can resolve it yourself without having to, you know, pick up the phone and call me. Excellent. So this is, look, this is, I mean, for Commvault, this is, this represents probably, you know, the largest pivot in in their history, right?
It's, you know, and, and rightfully so. As we said in the outset, we're at the dawn of a new age here a little bit. Um, you guys are announcing this over on, uh, on this, uh, shift event.
Absolutely. It was live and then there's a, or there was an in-person and then a virtual one. Um, just real quickly for people who are interested in, in, uh, checking out that virtual shift event, the, uh, let me see if I can get this right here.
com and then it's event dash shift dash launch virtual all registration. com, you might be able to get it off there, but, um, you know, that's where people can find out or they can participate in in, in the event and find out more about this. But I'm gonna assume rte, you know, this new resiliency platform will be all over the Commvault site as well.
Yes, Absolutely. So, uh, I think you, you mentioned the, the key word for a shift. So shift has been, uh, a, I'm gonna say top to bottom shift and change across Commvault.
So it's not just in some of the products. How do we kind of bring some of those pieces we had in the back and we really kind of, uh, flush 'em out to full formed, you know, very, uh, very automated, very simple and easy, you know, uh, convenient packages for people to come back over, either add to their existing environments or for those, you know, that are looking for a first, first start on a new and, and easier, uh, easier path. That's where you can come back over and look at the full stack from convo.
But it's not just the product, it's, you know, it's the people behind it. It's the support organizations. Um, I'll say, you know, one of the other things we're shifting to is there's a lot of key learnings, like you said earlier in the cloud.
Uh, we, uh, one of, one of the key things that we did a number of years ago was to kind of break our, break ourselves out and give us, give ourselves some freedom and the ability to accelerate and change, uh, was building out the metallic backup as a service offer on Commvault. So using our own technology to come over and say, for those who don't wanna, you know, set it up and run it anymore, you'd like to just come over and consume it, let's make that an easy outcome. Um, what we've been doing with that is saying that's not just kind of a, a side project, but that was really our testing zone to come over with some new capabilities, some new features, some new experiences.
And this has always been kind of the, the master plan on the back to say, can we use that to come back over and then adat it back into the core? So we kind of pull it all back into one common platform approach across the board. You can still take it and, and, and, uh, consume it in different ways, but more importantly, that's where a lot of that easy, convenient, uh, experience that we've taken from the SaaS side comes back over to say, it's now a benefit that all users can come over and enjoy with us too.
So not just the new features, it's the easier, more convenient, I'm gonna say more intelligent things. Uh, it's the product becoming increasingly becoming more and more int intelligence to figure out, Alan, you know, what does your environment look like? Alan, let me give you the recommendations, uh, for some improvements.
And the product can tell you that rather than having me, you know, pick up the phone and, and, uh, have to come over and do a site visit. Uh, so it's a lot of these things all tying together to say, how do we really try to give a, you know, a holistic experience to users, you know, that really, like I said, you know, shifts what we did in the past to kind of make it an easier outcome for the future. Excellent.
Hey, Brock, we're way over time. I got people in the green room. I gotta bring in real quick.
com, you, there should be banners and stuff up there to get more information on the shift event as well as the cyber resiliency. Brian Brockway, CTO Convault, thanks for joining us on Techstrong TV today. Look forward to seeing you soon.
Say hello to all our Convault friends, and best of luck with this big pivot. You got It. Perfect.
All righty. Hey, we're gonna take a break here on Tech Drunk tv. We'll be back in just a minute.