Commvault has outlined four essential steps for organisations to maintain resilience in the era of Frontier AI, where advanced artificial intelligence models are expediting vulnerability discovery and exploitation timelines.
This shift necessitates a new level of resilience as AI models are transforming the threat landscape through the generation of numerous Common Vulnerabilities and Exposures (CVEs). According to research by Palo Alto Networks, AI cybersecurity models have identified vulnerabilities at a rate more than seven times higher than typical findings in monthly tests.
Rapid exploitation and remediation
The quick adaptation of AI in attacks has led to autonomous exploitation of vulnerabilities shortly after disclosure, drastically reducing the time available for remediation. This environment emphasises that resilience should now be a fundamental operating requirement, rather than a mere recovery plan.
The quick adaptation of AI in attacks has led to autonomous exploitation of vulnerabilities
Nick Patience, VP and AI Practice Lead at Futurum Group, highlighted the importance of evolving remediation programs given the rapid pace at which AI models uncover exploitable vulnerabilities. He stated, "While a rigorous patching strategy remains critical, the key now is also making sure readiness, resilience, and clean recoveries are top priorities."
Key preparedness steps
To navigate this challenging landscape, Commvault recommends that organisations adopt a preparedness framework comprising the following four steps:
- Evaluate recovery risks: IT and security teams must assess their current recovery strategies to endure swift vulnerability discovery and exploitation cycles. Critical questions to address include the ability to restore essential systems cleanly, the isolation of recovery environments from compromised production systems, and the alignment of recovery plans with key dependencies.
- Make isolated recovery and air gapping the baseline: Assume certain vulnerabilities or software flaws may surpass standard remediation efforts. Maintaining immutable, isolated copies of critical data and workloads is crucial. These copies should exist independently of production identity and management systems, providing a clean recovery option when immediate remediation is not feasible.
- Prioritise essential systems: Identify and prioritise recovery for systems that are indispensable to business operations, such as identity platforms, billing systems, and core databases. Additionally, assess dependencies emerging with AI integration into business processes.
- Automate resilience and continuous testing: Organisations should automate processes such as threat scanning, recovery point identification, and recovery orchestration. Regular testing of recovery plans in isolated environments ensures preparedness for actual incidents.
Operationalising resilience
Adopting this framework enables organisations to leverage evolving AI models while mitigating associated risks. Jayson Morgan, SVP Infrastructure at BOK Financial Corporation, stressed the importance of clean recovery and swift operation resumption. He stated, "What matters isn’t simply whether backups exist, but whether we can recover cleanly, validate integrity, and resume operations fast when it matters most."
ResOps, the operating model promoted by Commvault, facilitates this framework's implementation. It enhances resilience through continuous testing, measurable recovery readiness, and effective system restoration. Bill O’Connell, Chief Security Officer at Commvault, explained, "AI models will continue to evolve that accelerate remediation timelines and require a new approach to readiness. ResOps gives organisations a way to continuously validate readiness, advance clean recoveries, restore systems with confidence, and build resilience into the way they operate."
Commvault, a pioneer in unified resilience at enterprise scale, recommends four steps organisations should take to stay resilient in the age of Frontier AI – where advanced AI models are accelerating vulnerability discovery, compressing exploitation timelines, and elevating the need for resilience.
Frontier AI is reshaping the threat landscape in two ways. First, advanced models are generating a deluge of Common Vulnerabilities and Exposures (CVEs) – Palo Alto Networks research shows AI cybersecurity models identified more than seven times the typical number of vulnerabilities found within a single month during testing. Second, attacks are becoming autonomous: once a vulnerability is disclosed, AI-assisted exploitation can now emerge within minutes, not weeks. The remediation window for organisations is collapsing – no vendor is immune. Resilience is no longer a recovery plan, it's an operating requirement.
Compromised production systems
“Frontier models change the economics of vulnerability discovery. AI models will reveal exploitable vulnerabilities at such a fast pace, remediation programs must evolve,” said Nick Patience, VP and AI Practice Lead, Futurum Group. “While a rigorous patching strategy remains critical, the key now is also making sure readiness, resilience, and clean recoveries are top priorities.”
To help enterprises prepare for the Frontier AI era, Commvault recommends that organisations embrace a preparedness framework that includes four key steps:
- Evaluate recovery risks: IT and security teams should assess whether their current recovery posture can withstand fast-moving vulnerability discovery and exploitation cycles. This means looking beyond whether backups exist and asking harder questions: Can critical systems be restored cleanly? Are recovery environments isolated from compromised production systems? Are recovery plans mapped to key dependencies?
- Make isolated recovery and air gapping the baseline: Organisations should assume that some vulnerabilities, software flaws, or third-party exposures may outpace normal remediation cycles. Maintain immutable, isolated copies of critical data and workloads, separated from production identity, network, and management planes. These copies help provide a clean fallback when patching or when remediation cannot keep pace. Organisations should also pressure-test RTOs and RPOs against realistic attack scenarios – not just failure modes. If your recovery time objective was set before autonomous exploitation was possible, it was set for a different world.
- Prioritise systems the business cannot operate without: Identify the systems required to function as a minimum viable company, including identity platforms, billing systems, operational databases, and cloud services, and define the order in which they must be recovered. As AI becomes embedded into business operations, organisations should also assess newer dependencies such as data pipelines, model repositories, vector databases, and agentic workflows.
- Automate resilience and test continuously: Recovery plans cannot remain static documents in the Frontier AI era. Organisations should automate threat scanning, clean recovery point identification, dependency-aware restoration, and recovery orchestration, while regularly testing plans in isolated cleanroom environments before incidents occur.
Measurable recovery readiness
“Organisations that embrace this four-step process will be better suited to take advantage of rapidly evolving AI models while also mitigating the risks,” said Patience. “Resilience continues to be a high priority for us,” said Jayson Morgan, SVP Infrastructure, BOK Financial Corporation. “What matters isn’t simply whether backups exist, but whether we can recover cleanly, validate integrity, and resume operations fast when it matters most.”
ResOps is the operating model that makes this framework actionable. It operationalises resilience through continuous testing, measurable recovery readiness, clean recovery validation, and protection of both production and recovery environments. It’s foundational for business continuity during cyberattacks, outages, and AI-driven disruptions.
“AI models will continue to evolve that accelerate remediation timelines and require a new approach to readiness,” said Bill O’Connell, Chief Security Officer, Commvault. “ResOps gives organisations a way to continuously validate readiness, advance clean recoveries, restore systems with confidence, and build resilience into the way they operate.”