Summary is AI-generated, newsdesk-reviewed
  • Commvault outlines four essential steps for resilience in the Frontier AI landscape.
  • Advanced AI models accelerate vulnerability discovery, necessitating robust cybersecurity strategies.
  • Isolated recovery and continuous testing are critical for maintaining operational resilience.

Commvault has outlined four essential steps for organisations to maintain resilience in the era of Frontier AI, where advanced artificial intelligence models are expediting vulnerability discovery and exploitation timelines.

This shift necessitates a new level of resilience as AI models are transforming the threat landscape through the generation of numerous Common Vulnerabilities and Exposures (CVEs). According to research by Palo Alto Networks, AI cybersecurity models have identified vulnerabilities at a rate more than seven times higher than typical findings in monthly tests.

Rapid exploitation and remediation

The quick adaptation of AI in attacks has led to autonomous exploitation of vulnerabilities shortly after disclosure, drastically reducing the time available for remediation. This environment emphasises that resilience should now be a fundamental operating requirement, rather than a mere recovery plan.

The quick adaptation of AI in attacks has led to autonomous exploitation of vulnerabilities

Nick Patience, VP and AI Practice Lead at Futurum Group, highlighted the importance of evolving remediation programs given the rapid pace at which AI models uncover exploitable vulnerabilities. He stated, "While a rigorous patching strategy remains critical, the key now is also making sure readiness, resilience, and clean recoveries are top priorities."

Key preparedness steps

To navigate this challenging landscape, Commvault recommends that organisations adopt a preparedness framework comprising the following four steps:

  • Evaluate recovery risks: IT and security teams must assess their current recovery strategies to endure swift vulnerability discovery and exploitation cycles. Critical questions to address include the ability to restore essential systems cleanly, the isolation of recovery environments from compromised production systems, and the alignment of recovery plans with key dependencies.
  • Make isolated recovery and air gapping the baseline: Assume certain vulnerabilities or software flaws may surpass standard remediation efforts. Maintaining immutable, isolated copies of critical data and workloads is crucial. These copies should exist independently of production identity and management systems, providing a clean recovery option when immediate remediation is not feasible.
  • Prioritise essential systems: Identify and prioritise recovery for systems that are indispensable to business operations, such as identity platforms, billing systems, and core databases. Additionally, assess dependencies emerging with AI integration into business processes.
  • Automate resilience and continuous testing: Organisations should automate processes such as threat scanning, recovery point identification, and recovery orchestration. Regular testing of recovery plans in isolated environments ensures preparedness for actual incidents.

Operationalising resilience

Adopting this framework enables organisations to leverage evolving AI models while mitigating associated risks. Jayson Morgan, SVP Infrastructure at BOK Financial Corporation, stressed the importance of clean recovery and swift operation resumption. He stated, "What matters isn’t simply whether backups exist, but whether we can recover cleanly, validate integrity, and resume operations fast when it matters most."

ResOps, the operating model promoted by Commvault, facilitates this framework's implementation. It enhances resilience through continuous testing, measurable recovery readiness, and effective system restoration. Bill O’Connell, Chief Security Officer at Commvault, explained, "AI models will continue to evolve that accelerate remediation timelines and require a new approach to readiness. ResOps gives organisations a way to continuously validate readiness, advance clean recoveries, restore systems with confidence, and build resilience into the way they operate."

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...