SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Commvault adds Google threat intelligence to recovery

Commvault adds Google threat intelligence to recovery

Mon, 3rd Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Commvault has integrated Google Threat Intelligence into its Threat Scan product to help customers identify clean recovery points after cyberattacks.

The integration brings Google's threat data and scanning tools into Commvault recovery workflows, allowing backup and recovery teams to check whether stored data has been compromised before restoring it.

One of the main challenges after a cyberattack is deciding which recovery point is safe to use. Security teams may quickly identify indicators of compromise, but recovery teams still need to confirm that backup data is free of malware or other signs of intrusion before systems can be brought back online.

Under the new arrangement, Commvault users will be able to analyse protected workloads for malware and use Google Threat Intelligence to identify threats linked to specific recovery points. Threat Scan customers will also receive additional context for issues found in their environment to support investigation and remediation.

Google Threat Intelligence combines intelligence from Mandiant, VirusTotal and Google's own security operations. That data will now feed directly into Threat Scan workflows to help narrow down which stored data sets are suitable for recovery.

Inline scanning

Alongside the integration, Commvault is adding scanning features that collect file hashes during backup operations. Those hashes can then be checked against threat intelligence indicators to help teams identify files likely to be safe for restoration.

This inspection method allows customers to start with a rapid validation step, then carry out deeper malware, encryption and forensic analysis where needed. The aim is to reduce the time needed to assess recovery options while maintaining confidence in restored data.

The new functions also extend Commvault's Synthetic Recovery offering, which uses an AI-based process to detect threats and remove them during recovery while leaving unaffected data intact. This is designed to improve the completeness of recovery after an incident.

The announcement builds on broader ties between Commvault and Google Cloud, where the two companies already work together on cyber resilience and support for Google Cloud workloads. This latest development focuses more specifically on the point at which organisations move from incident detection to operational recovery.

Cyber recovery has become a growing focus for technology suppliers as ransomware and other attacks leave companies facing prolonged outages even when backup copies are available. In many cases, the issue is no longer whether data can be restored, but whether the chosen recovery point contains hidden malicious code, encrypted files or evidence of compromise.

That has created demand for tools that connect threat intelligence with backup environments. By linking threat data to stored recovery points, vendors are trying to help customers avoid restoring infected data and reduce the risk of repeated disruption after an initial recovery attempt.

Commvault described the new integration as a way to close the gap between security analysis and operational recovery, giving recovery teams faster access to information that would otherwise need to be gathered and assessed separately.

Pranay Ahlawat, Chief Technology and AI Officer at Commvault, said: "Businesses need confidence that the data they're restoring is clean.

"By combining Threat Scan and inline scanning with Google Threat Intelligence, we're helping customers validate recovery points faster and accelerate clean recovery when it matters most."

Google said the collaboration is intended to simplify decision-making during incident response and recovery, an area where companies often have to balance speed with the risk of restoring compromised systems.

Miton Adhikari, Head of Google Security OEM Partnerships at Google, said: "Organisations are looking for ways to strengthen cyber resilience while reducing complexity during incident response and recovery.

"Through our collaboration with Commvault, customers will be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed recovery decisions and reduce recovery uncertainty."