With cybercriminals increasingly targeting backup environments and embedding malware into recovery points, traditional restoration methods are no longer sufficient. At SHIFT 2025, Commvault introduced a suite of cyber-recovery innovations engineered specifically to help organisations perform fast, clean and automated recoveries — even when adversaries aim to undermine backup integrity.

The updated Threat Scan now uses AI to detect malicious encryption patterns, uncover early indicators of compromise and quarantine suspicious files before they contaminate recovery workflows. This feeds directly into Synthetic Recovery, which surgically strips out compromised data during the restoration process while preserving the clean portions of a backup. Security teams are no longer forced to choose between restoring infected datasets or rolling back so far that business continuity is impacted.
Commvault also advanced its cleanroom-based recovery automation, enabling teams to build isolated, production-like environments for testing and validating restorations safely before returning systems to the live environment. Analysts view this as a major step beyond traditional “backup hygiene,” moving toward autonomous, intelligence-driven remediation.
The company also announced extended identity resilience features, addressing Active Directory — one of the riskiest attack surfaces in today’s threat landscape. The new functionality detects anomalous changes, provides full audit trails and supports immediate rollback of unauthorised modifications.
With ransomware and identity-based attacks becoming increasingly intertwined, Commvault’s integrated approach offers a clearer path to clean, complete and verifiable recovery at enterprise scale.








