Cybersecurity and the challenges with data protection and ransomware are only expected to heat up in 2022. To get a better understanding of things, VMblog spoke to industry expert, Indu S. Peddibhotla, the Senior Director of Products and Strategy at Metallic.
VMblog: Indu, can you tell us a little bit about your background and your current role at Metallic?
Indu Sekhar Peddibhotla: Over the past decade, my work has focused on the development of technologies that help companies secure, govern and protect their data. I have led teams responsible for developing new threat detection, data loss protection, and data governance technologies, and most recently led product development and engineering for a cloud security and governance start-up before it was acquired.
In my current role as senior director of products and strategy at Metallic, the SaaS division of Commvault, I am responsible for developing data security services within the Metallic Portfolio – like the recently launched Security IQ. In this role I am also working to expand Commvault’s partnerships and other strategic alliances in the data protection and security ecosystem.
It is an exciting space to be in right now. Enterprises are increasingly realizing that if they are not proactively and intelligently managing their data – in particular, making sure their data is as secure and protected as reasonably possible – they are placing the integrity of their business at risk.
VMblog: In your experience, what are some of the most common oversights that IT leaders make when it comes to protecting their data from ransomware attacks?
Peddibhotla: One common oversight I see time and time again is IT leaders forgetting that, in addition to securing the production environments on which their database, file, CRM system and other data resides, they also need to secure the data protection environments where their backup data is stored.
An analogy between data and business documents can help us describe this type of oversight. Companies understand they need to secure their critical business documents (their data), so they invest in a safe and lock these documents up at their office. They also know they need to have a copy of all these documents in case someone breaks into the safe and steals or destroys these critical documents. But often they make the mistake of keeping backup copies of these documents in a poorly locked file cabinet in that same office. This makes it easy for the criminals to access critical data by accessing the backup documents in the file cabinet.
What companies need to do is store copies of their critical documents in a secure place – like a safe deposit box in a bank – that is in a different location than where they store the original copies of these documents. Like a bank, this location should have its own security personnel and policies to ensure only people authorized by their company can access these documents.
That is one of the things we are doing at Metallic – making it simple for companies to get a very secure digital safe deposit box in which they can safely store copies of their critical data. For example, with Metallic they can sign up in minutes for a service that backs up their VMware, SAP HANA, Microsoft 365, Salesforce and other critical business data to an independent cloud environment that uses a completely different security domain than their production environment.
In addition, our Security IQ features use AI-powered technologies to constantly monitor a company’s data, and alert the company if abnormal conditions or behaviors indicate a malicious actor might be trying to lock, alter, or destroy this data. A virtual air gap between their production environment and the backup cloud environment further ensures that, even if criminals access their primary data, a verified, pristine copy of their data is secure, and ready for them to restore to their production environment at a moment’s notice.
So rather than copies of a company’s critical documents being in a file cabinet in their home or office, with Metallic they reside in the basement vault of a nearby bank, in a locked safe deposit box, with cameras and security guards at the bank on constant lookout for anyone who might want to get their hands on them.
VMblog: What role do you see data protection solutions playing in the future in helping companies identify ransomware and other cyberattacks early, so that they can minimize these attacks’ “blast area” or even stop these attacks from occurring?
Peddibhotla: As the threat posed by ransomware and other cyberthreats continues to grow, data security is top of mind for private and public businesses.
That is why our Metallic solutions are designed to provide these businesses with the data protection capabilities they need to implement an effective, well-rounded, and multi-layered strategy to secure and recover their data on a moment’s notice.
For example, Metallic’s AI-powered technology can be used to look for unusual conditions or behavior on a company’s production data when it is being backed up. Functioning as a “second set of eyes” these technologies can detect behavior that indicates an attack on this production data between the present time and the time it was last backed up. It can then alert the company’s IT team of this attack – allowing them to stop the attack before it can do any damage, or at least limit the attack’s “blast radius” so whatever damage it causes can be fixed quickly.
Given the sophistication of today’s cyberattacks, it is this type of multi-layered security – in which data protection and security technologies work hand-in-hand to identify, fend off, and resolve attacks – that IT leaders need if they want to be able to focus on using their data to improve business outcomes, and not on rebuilding their systems after a cyberattack has devastated them.
VMblog: Metallic has recently begun referring to its offerings as Data Management as a Service (DMaaS). How is DMaaS different from Backup as a Service (BaaS)?
Peddibhotla: I would not say that BaaS is different than DMaaS – rather that BaaS is a subset of DMaaS. Commvault delivers Intelligent Data Services that span beyond data protection to data security, data compliance, data transformation and more. At Metallic we are constantly working with our customers to understand their data protection, security, governance, migration and other data management needs, and then enhance our DMaaS solutions to address these needs – for example through our managed storage service, Security IQ, or eDiscovery capabilities.
We are fortunate in this regard, in that at Metallic we can draw from the decades of experience and deep levels of expertise that Commvault has in data governance, migration, analytics and other areas of data management, and use this experience along with brand new innovations to continue to grow our DMaaS portfolio. This is why Metallic is so well-positioned to solve companies’ complex data management problems. Through a single pane of glass, customers can secure, govern, move, and otherwise manage their critical data – all in a simple cloud-delivered service. This is what we mean at Metallic when we talk about DMaaS.
##






