Back
Gary Merrill
Chief Commercial Officer, COMMVAULT SYSTEMS INC

Balancing Risk, Recovery and Resiliency with Commvault | Meet the Chief

🎥 Sep 19, 2024 📺 World Wide Technology ⏱ 26m 👁 144 views
Cyber resilience has become an executive- and board-level imperative for organizations of all kinds. But how can leaders ensure ...
Watch on YouTube

About Gary Merrill

Gary Merrill, Chief Commercial Officer at Commvault, appeared on the "Meet the Chief" podcast on October 17, 2024, to discuss cyber resilience and data recovery. He stated that the key question for organizations has shifted from "do I have a good backup" to "am I ready to recover," describing this as the essence of resilience. Merrill noted that Commvault acquired a company called Oranic, which he said allows customers to recover entire applications alongside data in a cloud-native manner, reducing recovery time from weeks or months to minutes or hours. He described the company's approach to modernizing the traditional clean room concept for recovery, enabling IT teams to spin up on-demand clean rooms with zero trust architecture and automation. Merrill emphasized that AI is used to help customers recover by providing "bulletproof recovery start points" based on forensics and machine learning, and to operationalize complex environments. He said Commvault takes a "responsible approach" to AI, building in kill switches and keeping machine learning within the customer's environment. Merrill also commented that being a CIO before becoming a CEO provided him with perspective on business operations, and that immersing oneself in different cultures is valuable for making global decisions.

Source: AI-verified profile updated from Gary Merrill's recent appearances. Browse all interviews →

Transcript (27 segments)
T
Tracy Burn0:01
Hi everybody, my name is Tracy Burn and welcome to another episode of Meet the Chief. We are super excited to have Sanjay Mirchandani with us, the CEO of Commvault. You guys have been an amazingly trusted leader in this space for 13 consecutive years, leaders in Magic Quadrant. It would be really amazing to hear from you about how this industry has evolved over the years.
S
Sanjay Mirchandani0:25
Super Tracy, great to be here. Thanks for having me. Before I was CEO, I was CIO and have the notoriety of being the CIO on watch when RSA got hacked, one of the most famous nation-state attacks of its kind and one of the earliest. What we learned then and what continues to be paramount today is that what they want is the data. They always want the data. They don't want your trucks, they don't want your factories, they want your data. Data protection has evolved. It used to be about somebody making a mistake, insider threats, natural disasters, but today it's cyber. The vector we're all worrying about is cyber. The fundamentals of protecting data, protecting every workload that runs your business, not just being selective, and having a uniform platform that does it for you, that is the secret sauce. Having one platform that gives you visibility across everything is paramount. Data protection is at the heart of what has become cyber resilience, and I'm sure we'll touch on that in a bit. Cyber resilience is the modern outcome, the heart of which is data protection.
T
Tracy Burn1:48
Absolutely. At WWT, we help and coach our customers through their cyber resilience programs very frequently, and we're seeing a huge uptick in the prominence and interest in really making sure we're driving that maturity. Can you talk to us a little bit about what you're seeing from your vantage point about the conditions in the market and in cyber that are driving this?
S
Sanjay Mirchandani2:14
Absolutely. Cyber means a lot of things to people. A lot of money has been spent over the past 10 years on defenses, identification, defending, rooting out bad actors. We call that the left. But as you move down the kill chain, beyond identifying and removing them from your network, really being able to recover your data and rebuild your business. In our mind, the continuum has shifted. Our global events for customers are called Shift. We've done this for a couple years. Shift is about not only thinking about the left side, defending primarily, but also being able to recover. So much so that as a company almost synonymous with the word backup, we've started saying to customers, the question you ask yourself today is not 'Do I have a good backup?' It's 'Am I ready to recover?' That ability to recover is what resilience is about. That is the shift, the mental state, the preparedness our customers have to go through. The bad guys have to be correct once; they have to get through once. We have to be right 100% of the time. We've got to get that perfectly balanced.
T
Tracy Burn3:46
It's very true. One of the interesting elements when we talk about cyber resilience as a whole is that we all know it's more of a timing scenario, when is it going to happen to your organization. I really love that you guys are looking at it so broadly because it's not just about technology, it's about process, it's about readiness. As we see more focus in this space, all those best practices are going to become elevated so they can recover when something does happen. To dig into that a little more, when we talk about our enterprise customers, they have such complex cloud applications, many of them natively built, and that becomes a major challenge when they're trying to recover quickly and bring themselves back up. Can you talk about what you've invested in as an organization to really address this gap that our customers are facing in their own defenses?
S
Sanjay Mirchandani4:42
Great question. In a recent study we did with about a thousand leaders in technology, we asked them their take on breaches. 83% of them had a significant breach in the past year. What is scary is the ones that don't think they've had a breach or are not going to get breached. When you get breached, it's chaos. You spend a lot of time trying to figure out who did it, what they took, what they got. You've got all the forensic work going on, but what matters is if you're a CIO, your phone is ringing from the C-suite saying, 'When are we coming back to life? The world knows we're down.' Now, let's say you did a perfect implementation with us and we get your data back. Let's say it's a 24-hour cycle. If it takes you 8 to 10 hours to get your data back, assuming you've done it all right, the rest of the time is what it takes to get your app stack back. You get the data, it's validated, it's clean, it's ready to go, and then you have to test it, bring the entire application stack back up to make sure the data works. You don't run one app stack in a business; you've got hundreds if not thousands. Some are traditional, some are bare metal, some are virtualized, and some are in the cloud. What we did recently was buy a very exciting young company with some exciting technology that is truly multicloud, called Appranix. What Appranix does is allow you to go that last mile. In that 24-hour cycle, it brings back the application in its entirety alongside the data. It's a completely cloud-native capability that works on all three major clouds. Based on your policy, it will snap the data and make copies to give you the right level of data protection. It also takes application config, what makes up a cloud-native app, which is a very loosely coupled engineering capability. People use different elements on different clouds. We take all those resources, we know what makes up an app, and we know the sequencing and restoration process of that app. What could take you weeks or months to come back, we can do in minutes or hours. It's completely automated and available. It's completely cloud native. We're taking that last mile very seriously, saying, 'How does a business have continuous capability?' I'm not just thinking protection; I'm thinking the ability to bring a business back to life, including the applications that run it, at scale. That was an exciting element of it, but just one piece of what we do.
T
Tracy Burn7:23
It really is so exciting. When we talk about this landscape, businesses going down and the critical minutes that tick by, we've seen so many events like this that impact absolutely everyone and everything. It's really important that we be thinking ahead on how to respond in these types of scenarios. We really dug into technology there, which is obviously extremely critical, but can you talk to us about how you guys assist in the process itself?
S
Sanjay Mirchandani7:56
If there's one thing I learned from being at the helm when you get breached, it's that you're never ready enough. The more ready you can be, the more prepared you can be, the more realistic your chances of recovery in a way that is predictable. Most importantly, it's predictable. We've got 1,100 patterns for a company of our size, very focused in what we do. Some of the innovation we brought to market in the last year, I'll call out one: clean room recovery. We took the traditional concept of a clean room, which was a sealed spot with equipment that mirrored everything else, super expensive, barely anyone could afford it, you didn't want to touch it because you didn't want to mess with the config, and you hoped that if something bad happened you could go in there and bring your business back to life. Great concept, not the most practical and not the most scalable because you can't have clean rooms for every single workload. So we took that concept and brought it into a cloud-native way. We give you the ability to spin up on demand. In good times, like today, your IT team could go in and spin up as many clean rooms as they wanted. It's zero-trust architecture, it's pristine, there's nobody in the network because we just brought it up. We give you Active Directory backup, which is very important. The first thing that goes is Active Directory; you cannot trust your Active Directory if you've been breached. We bring back Active Directory, we bring back your crown jewels, your data, from an air-gapped copy that we have of yours, and then we bring the automation to bring that entire stack back to life. You can do that on demand as often as you want for every single workload, cheap and cheerful in good times. Why? So that you can use it to build your playbooks. God forbid the first time you get breached is not the first time you're trying to do this. Customers are really embracing this. I'm sure our teams are working together to get this in the hands of customers because this is truly innovative. We took a tried and tested concept that had its limitations and completely modernized it.
T
Tracy Burn10:11
It's so critical. I think that really shows how you guys sit on the same side of the table as your customers. It's just like anything else: you have to exercise those muscles to be able to respond properly. When you don't have the time or you're under so much stress that you can't think about it as clearly as you normally would, this element of practicing and really putting in the hours is almost a sports methodology. I think that's the world we live in, and that's why partners like WWT come in. You could be working with customers in good times to really test those out, help them build the playbooks, help them do these desktop exercises that companies do to make themselves feel better.
S
Sanjay Mirchandani10:50
I would feel better if that's the only defense I had? I'm not going to feel better. It's an academic exercise limited to nothing. What you want is breadth: you want every workload tested, you want the playbooks to be refreshed, you want people to be trained and know how to do this, the ecosystem inside a customer including us. That's the value we bring. I believe in our 27 years, this is the most partner-friendly platform we have ever released.
T
Tracy Burn11:18
Absolutely. We certainly do feel that in the partnership, and that really translates into how smoothly and effectively we deliver to customers. It's been a very worthy cause and one that's been great to work on together. Can we talk a little bit about this shift in the market towards how do we support the use of AI, generative AI, in our customers' environments and how that impacts this particular element of cybersecurity? You and I both know you can't go to the supermarket without seeing AI somewhere in the aisle.
S
Sanjay Mirchandani11:55
If you really distill it down, AI is extremely powerful. In our business, customers trust us with data. At the end of the day, we're the last stop for them to get their businesses back to life. If everything goes wrong, they know they've got Commvault protecting their data. We take that responsibility very seriously. We've had customers with us for decades. As much as AI has incredible promise and we are using it in every conceivable way we think we can, we're taking a very responsible approach. Data protection first, everything else second. The number one requested thing for me as a CEO when I talk to customers is, 'Give me foolproof recovery. Tell me where to start.' When the dam bursts and you're in the throes of a breach, you don't know the forensics. You run a security business, you don't know at that point what has happened, you don't know who it is, you don't know if you can believe it, you don't trust anything or anyone inside the network. It is absolute chaos. While chaos reigns, we're still trying to help customers come back to life. Where do they start? Which day, which time, so that you don't bring back malware? You're scanning to know you're bringing back clean data. We're using AI primarily to assist customers in recovery, giving them bulletproof start points, recovery points, to say, 'Based on all the forensics, machine learning, everything we've been doing on your environment, we think November 14th is the right point to start.' You iterate from there. You can use the clean room technology to spin up an environment, test it, make sure it's not dirty, and rinse and repeat until you get it right. For us, AI is incredibly powerful in helping customers recover, number one. Number two, the more complex a customer environment, the more I can use AI to help them operationalize it better, for core infra ops, backup ops, and SecOps. Helping them get that right, and then going down the logical chain of having a co-pilot and all those things. But really, our deep focus is recovery capabilities and operational excellence inside the product.
T
Tracy Burn14:21
It is such a powerful tool, and it always comes back to this kind of analogy that we make where it's man versus machine. We really do have to step up and leverage the same defensive mechanisms that are being used on the offensive. It's something where every organization is adopting it, and there are so many different use cases to get value out of generative AI.
S
Sanjay Mirchandani14:47
Sorry to interrupt, but I think it's going through the same lifecycle of validation that SaaS apps did 10 or 8 years ago. You didn't just throw a SaaS app into your environment; you wanted to make sure you knew what their standards were, what they had behind it, and so on. For every customer that asks me excitedly what we have by way of AI in our technology, another one will ask me if we have a kill switch because they're not ready. They don't have their policies in place. We're building it very responsibly. Everything we're putting in by way of machine learning and AI, and a lot of what we do is really machine learning, a deep amount of machine learning in the environment for the customer, it doesn't leave the customer. That allows you to be both operationally and from a recovery point of view that much better. We're just getting started, in my opinion.
T
Tracy Burn15:40
Absolutely. It's funny too, we talk about machine learning and that's a concept that's been around for over a decade. The process of validation and being able to leverage that technology, I think we're starting off from a really solid foundation given how much machine learning was already developed in so many other tool sets. Agreed. Wonderful. I would love to learn a little bit about you. We've talked a ton about technology, but you've had just a really incredible career yourself. Can you talk to me a little bit about how you got started in the industry and some of the organizations that you led and built? It would be some great learnings for our listeners.
S
Sanjay Mirchandani16:21
Well, thank you. I'm a technologist by training, but I go back a long way. I realized very quickly, thankfully, that I was better at helping customers with technology than actually building technology. I would have been the worst developer on the planet, so thank God I took my technical mind and applied it more towards helping customers with solutions. From a career point of view, I've always tried to take options that were less defined so that I could have my fingerprints on it. If it worked, great; if it didn't, okay, but at least I wasn't just part of something doing a small piece of it, but actually having a say in it. That's risky sometimes; it works and sometimes it doesn't. I've had both happen to me. I decided I wanted to be a CEO when I was a CIO. I think the best training for CEO is being a CIO because you see every element of the business. I got the opportunity to be CEO of Puppet, which was an open-source company, very well known, much bigger than its actual revenues. It was one of the leaders in open-source config management, a predecessor to some of the automation we have today. Then Commvault called. I loved it because I knew Commvault when I was at EMC; we competed. When I came in and met with the leadership team and the board, I was absolutely in love with the tech. It was a nice little business that needed a little shaping at the time, great people, great culture. I'm so glad I did it. That's sort of how I think about my 37 years.
T
Tracy Burn18:31
That's amazing. There are so many pieces of that that I want to pull out. Your career has been incredible. I like that you can feel the energy you have for building really good, solid organizations and bringing people up. One of the biggest takeaways I just heard from you is rather than passing any pressure or stress through in a way that's just very raw, it's really being cognizant of everyone around you and helping them achieve their greatest goals while being in an extremely healthy, great culture. I think that's huge.
S
Sanjay Mirchandani19:04
I don't know if my management people agree with you, but that's what I try to do.
T
Tracy Burn19:11
It's super cool to hear, and it's just more alignment in the cultures of our organizations. Neither of our companies are new, but they act as innovators, in some ways like very large successful startups, because they're always infusing new ideas into the business. What's a better way to drive a better outcome for our customers? Every single day we're essentially in a new security terrain.
S
Sanjay Mirchandani19:36
Exactly true. When you've been around for a little while, it's about not dismissing the fact that you've been around; it's about acknowledging what that has taught you. When we bring new talent into the company and infuse it, we almost systematically put them with people who've been around a little while. There's this cross-pollination of ideas: 'Here's why we did it, here's what it did for us, what's the better way of thinking about it?' Especially when you acquire companies, you can't squash that; you have to fuel that.
T
Tracy Burn20:17
Absolutely, because there's a reason why they got to the place where they are where you wanted to bring them into the fold. It's highlighting all those areas. It's so cool to hear about your career experience. One of the things I wanted to tap into as you were talking about your ability to move to drastic locations throughout your growth and career journey, what did you take away from each of those major life experiences of living in a completely different culture?
S
Sanjay Mirchandani20:48
I will admit I enjoy it. I enjoy immersing myself in different cultures. I think it's part of who I am. I grew up in India, moved here as a teenager, did university, and then decided one day to go see the world. We went to Dubai, which was a little town back then. From there, I got moved with Microsoft to India to run India, which was a huge opportunity because back then being a country manager, you were like the CEO; you made 80% of the decisions even for a multinational. Then I did a bigger regional job in Singapore. That was an immersion. People say Asia, but Asia is everything from India to Australia to Japan, Korea, China. You learn cultures, names, languages, everything. My kids were born along the way. They're confused; they don't know. We're American, but of Indian descent, but we grew up in Singapore. It's part of who we are. I thrive on it. I give executives a nudge: if you can, go spend time not in the UK, which is great but a lot like where we are now. Go to Korea, go to India, go to China, places where it makes you a little uncomfortable. People say, 'What about the kids?' My kids are young; I picked them up and took them. They've lived in nine or eight places. They learn languages, make friends all over the world. It's part of life, in my personal opinion. When you're making global decisions, it gives you a nuanced view as to how things are received, whether a market entry strategy is relevant or not. It gives you perspective, priceless in my opinion. If you're given the chance to do it, back then we had no choice; if you wanted that opportunity, pack your bags and go. Thankfully, I had the support of my family, and it worked out just fine. I don't think enough people do it.
T
Tracy Burn23:16
It's funny, I'm certainly of the same mindset when it comes to not only just travel but extended travel when you can truly become a part of the culture you're in. Throughout my years where I've had the opportunity to spend extended time out of the country, I just relate so much better to so many different types of people. I think it grows an innate curiosity that really allows you to keep learning throughout your life. I think it's so fantastic that as part of the culture in your organization, you push people for that kind of growth because it stays with them forever.
S
Sanjay Mirchandani23:54
I think it worked. I encourage my girls; they're both in the workforce. I said, 'Before you have excuses, go work somewhere else. Go immerse yourself somewhere.' They haven't taken me up on it yet. I'm sure they will; they'll think of something really good.
T
Tracy Burn24:13
Wonderful. It was so great getting to know you a little bit more as a person. We can see your passion for what you do in technology. You have an amazing opportunity where you speak to so many of the executives at the companies that you guys support. Are there any resounding themes or best practices that you think you'd like to leave with our viewers today?
S
Sanjay Mirchandani24:37
If I take a step back, I'm a CEO today in tech, so I have understanding of the cyber issues. But if I was in a business in shipping, logistics, or medical, it isn't what I do every day, it isn't what I'm trained on. The advice I'd give when I talk to my peer group or when I'm asked is: just be prepared. Just like your supply chain, COVID taught us you need multiple routes, multiple suppliers, options, because you don't expect the world to shut down. Don't wait for the attack to happen. Ask questions of your organization and bring the expertise to be prepared. Ask hard questions. You're not an expert in everything, but you've got to be good enough today as a CEO to really say, 'My business needs to be protected.' I'm not one for drama and I'm not one to scare people. I'm all about it like anything else. If you're dependent on warehousing, trucks, logistics, and airplanes, you want to make sure you have the best capability. Similarly, if you're a successful company with great IP and you're doing well, you've got to protect that. Find ways to make sure you're prepared. Some of the stuff we talked about allows companies and CEOs to be prepared.
T
Tracy Burn26:15
Absolutely. It has been such a joy chatting with you today. I feel like we've really learned a lot about how your organization operates, the immense importance that you put on your customers' businesses and making sure that they're staying up, they're able to be successful and resilient. Thank you so much, Sanjay. It was a wonderful chat, and thank you all for tuning in.