Fady Richmany, Corporate Vice-President and General Manager for Emerging Markets at Commvault, a provider of cyber resilience and data protection solutions, has stressed that the rapid evolution of cyber threats, coupled with growing reliance on artificial intelligence (AI) and cloud computing, is forcing organisations to rethink data protection.
Rather than simply maintaining backups, organisations need an integrated cyber resilience framework capable of detecting attacks, responding to incidents and recovering from their impact, while minimising disruption to business operations.
Speaking during a media session on the sidelines of Commvault SHIFT 2026 in Cairo, Richmany discussed the evolution of data protection and the challenges facing organisations in an increasingly digital environment. He noted that cyber resilience had become essential to business continuity amid a rise in cyberattacks and the growing sophistication of the tools used by attackers.
From Backup to Cyber Resilience
Richmany explained that Commvault initially focused on data backup before gradually expanding its approach to encompass security, compliance, data management and data utilisation.
As digital risks have evolved, the company has increasingly focused on cyber resilience, which addresses what happens after an attack succeeds and an organisation must recover its data and systems and resume operations with minimal disruption and losses.
He noted that backups alone are no longer sufficient. Organisations must ensure that the data they rely on for recovery is secure, reliable and recoverable, while establishing clear incident-response procedures and testing them regularly.
This shift is reflected in the evolution of Commvault’s Unity platform, which brings together capabilities for cyber recovery, identity protection, data security and resilience across AI environments.
AI Expands Opportunities for Innovation and the Attack Surface
Richmany discussed the dual impact of AI on organisations, explaining that the technology offers significant opportunities to improve productivity and efficiency while introducing new risks to the digital environment.
As organisations expand their use of AI applications and intelligent agents, the volume of data processed by these systems increases, as does their access to systems and applications. This creates a need to reassess how organisations protect their data, identities and the environments in which these applications operate.
AI also offers advantages to attackers, who can use the technology to identify and exploit vulnerabilities more quickly. According to information Richmany presented during the session, the time needed to exploit certain vulnerabilities has fallen from weeks to less than a day, making rapid response and recovery more important than ever. Al Wafd previously reported this point, citing Richmany and referring to reports by PwC.
‘Synthetic Recovery’ to Minimise Data Loss
Among the solutions highlighted by Richmany was Synthetic Recovery, a technology designed to reduce the amount of data an organisation could lose following an attack.
He explained that an organisation may have a clean copy of its data from an earlier point in time, while more recent backups may have been compromised or encrypted. In such cases, advanced technologies can be used to clean a more recent copy and combine it with the older, clean version, reducing the data gap that the organisation might otherwise have to accept.
This approach transforms recovery from a process based solely on restoring the latest clean backup into a more flexible one that aims to recover as much recent data as possible.
Simulating Attacks Before They Happen
Richmany revealed that Commvault was working to develop simulation environments that replicate organisations’ actual operating infrastructure, enabling teams to test their ability to respond to cyberattacks without affecting live production systems.
These environments can replicate components of an organisation’s infrastructure, including servers, network devices and certain connected systems and devices. Teams can then simulate attacks to analyse how intrusions occur and how effectively they respond.
The objective extends beyond determining whether an attack can be detected. It also involves testing what happens after a breach, including how an organisation identifies the attack path, conducts digital forensics and restores its systems and data.
Preparedness Means More Than Having a Plan
Richmany stressed that having a disaster recovery plan does not necessarily mean an organisation is prepared to deal with a cyberattack.
He compared this to a building evacuation plan: documenting emergency exits is not enough if people do not know where they are or have not been trained to use them. Similarly, organisations need to test their response and recovery plans regularly and ensure that their teams and technologies can work together when an actual incident occurs.
He explained that some organisations treat backup, cybersecurity and business continuity as separate functions. However, the nature of modern cyberattacks requires these elements to be integrated into a single strategy covering preparedness, detection, response and recovery.
Cloud Computing Is Redefining Data Protection Responsibilities
Cloud computing also featured prominently in the discussion as more workloads and applications move to cloud platforms.
Richmany explained that relying on cloud service providers does not transfer full responsibility for data protection to those providers. Although they supply the underlying infrastructure and platforms, organisations must maintain independent strategies for protecting and recovering their data.
He noted that Commvault provides solutions to protect cloud workloads across on-premises and cloud environments, as well as software-as-a-service (SaaS) applications such as Microsoft 365, Salesforce and Dynamics. Its solutions also follow a cloud-agnostic approach, enabling organisations to protect data across multiple cloud environments without being tied to a single provider.
He also highlighted air-gapping and immutable data technologies as important safeguards against data deletion or tampering if systems or administrative accounts are compromised.
Shadow IT Adds a New Challenge
As the use of cloud services and AI applications expands, Richmany identified another challenge: shadow IT, which occurs when employees use tools or cloud services outside their organisations’ officially approved environments.
Company data may consequently be transferred to platforms that are not subject to the same levels of oversight and protection as official systems. Organisations therefore need to broaden their data protection strategies to cover the different environments in which their data may reside.
Cyber Resilience Depends on More Than Technology
Richmany emphasised that the transformation driven by AI extends beyond technology to skills and human resources.
He noted that the growing adoption of AI tools capable of writing code and developing applications would change the nature of certain jobs and the skills they require. At the same time, demand would increase for expertise in analysis, modern technology management and the assessment of digital risks.
Building cyber resilience therefore requires a combination of appropriate technologies, clear procedures and trained professionals capable of making informed decisions and responding effectively to incidents.
Recovery Capability Is What Matters When Attacks Succeed
Concluding his remarks, Richmany stressed that organisations could no longer regard cyberattacks as a remote possibility, as businesses and institutions across sectors worldwide face threats targeting their data, systems and services.
Against this backdrop, the priority is shifting from trying to prevent every attack to preparing for the possibility that an attacker will breach an organisation’s defences. Key questions include how quickly the organisation can detect an incident, identify affected data, prevent the attack from spreading and restore operations while minimising data loss.
This, according to Richmany’s assessment during the SHIFT 2026 session, lies at the heart of cyber resilience. Data protection does not end with preventing threats; it also involves ensuring that an organisation can maintain business continuity and recover when a cyber incident occurs.
The shift outlined during the session reflects a broader evolution in Commvault’s approach, from traditional backup to comprehensive data protection and, ultimately, an integrated cyber resilience framework that recognises data as one of the most critical assets underpinning business continuity in the digital economy.










