logo
Quantum Threats Reshape Commvault's Vision For Data Security

Quantum Threats Reshape Commvault's Vision For Data Security

Forbes2 days ago

Commvault is incorporating post-quantum cryptography to address future data security risks.
Data protection provider Commvault announced earlier this month that it is adding more quantum-safe capabilities to its platform to build out defenses against post-quantum cryptography. This is important because, as quantum computing shifts from theoretical to practical use, it brings a new class of cybersecurity threats. To help organizations prepare, Commvault has incorporated NIST-recommended PQC algorithms into its data protection offerings, covering both cloud and on-premises environments. The goal is to ensure long-term data security by protecting backups made today from potential decryption by future quantum systems.
Over the past year, Commvault has introduced multiple post-quantum cryptography capabilities to safeguard data against future risks posed by quantum computing. PQC has important implications for customers, competitors and the broader industry, and all organizations should prepare for a quantum-driven — and quantum-safe — future.
(Note: Commvault is an advisory client of my firm, Moor Insights & Strategy.)
Understanding The Quantum Threat To Enterprise Data
First, a little background on why this is so important. Quantum computers apply principles of quantum mechanics to process information in fundamentally different ways from classical computers. While this could unlock incredible advances in medicine, materials science, finance, AI and more, it also introduces new security concerns. This is because current encryption methods such as RSA and elliptic curve cryptography depend on mathematical problems that are very hard to reverse — unless a powerful quantum computer is involved. Once quantum computers that powerful are launched, probably in the next few years, these algorithms can potentially be broken quickly, compromising these widely used encryption methods.
A crucial concern today is the 'harvest now, decrypt later' tactic, where bad actors can intercept and store encrypted data to decrypt it in the future once quantum capabilities mature. HNDL protection is especially critical for sectors with long-term data sensitivity, such as healthcare, finance and government. (Think of any setting in which sensitive information — names, dates of birth, government ID numbers, bank account numbers, medical histories and the like — remains unchanged for many years.) A survey by the Information Systems Audit and Control Association found that 63% of cybersecurity professionals believe quantum computing will shift or expand cyber risks, and half expect it to create compliance challenges.
This image shows how users can enable PQC within Commvault's CommCell environment by selecting a ... More checkbox in the group configuration settings.
Commvault's Post-Quantum Cryptography Response
Commvault has taken a practical, multi-stage approach to quantum-era risks. In August 2024, it introduced a cryptographic agility framework, which is meant to allow organizations to adopt new cryptographic standards for PQC without major system changes. The framework includes several NIST-recommended quantum-resistant algorithms — CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+ and FALCON. (My colleague Paul Smith-Goodson, who has been covering quantum computing for years, went into more detail about these algorithms in the context of IBM's PQC efforts, also in August 2024.)
Commvault's announcement earlier this month builds on last year's release by adding support for the Hamming Quasi-Cyclic algorithm, which uses quantum error-correcting codes to resist quantum decryption. But rather than focusing only on algorithm support, Commvault also emphasizes operational integration. Its Risk Analysis tools help organizations identify sensitive data, allowing quantum-resistant encryption to be applied where it's most needed. The crypto-agility framework offered by Commvault allows organizations to shift between cryptographic methods via relatively simple configuration changes, without needing to overhaul their existing environments. This flexibility helps minimize disruptions and lowers the costs associated with adapting to new standards as they emerge.
Securing Critical Industries For The Quantum Era
Commvault's PQC features should be especially helpful to organizations in healthcare, finance and government as they address compliance needs, ensure continuity and — most importantly — protect data that is held for decades. As touched on above, these industries are especially at risk for deferred decryption attacks, so implementing PQC features now should help address the risk of HNDL exploits later. Besides the benefits already mentioned, this could help organizations using Commvault maintain trust among regulators, customers and partners for the long haul.
As data protection standards in these industries become stricter in anticipation of quantum threats, solutions that incorporate quantum-resistant encryption are increasingly necessary. Forward-looking IT organizations are already adopting these technologies. For instance, the Nevada Department of Transportation has adopted Commvault's PQC tools to meet government security requirements and protect sensitive information. The company also cited Peter Hands, CISO of the British Medical Association, who said, 'Commvault's rapid integration of NIST's quantum-resistant standards, particularly HQC, gives us great confidence that our critical information is protected now and well into the future.'
The adoption of PQC is accelerating as both technological developments and regulatory requirements create a framework for organizations to address emerging threats from quantum computing. In the United States, for instance, federal agencies have been instructed to integrate post-quantum standards into their procurement and operational practices. Similar regulatory efforts are taking place in the European Union and other jurisdictions, where updates to data protection frameworks increasingly include provisions for quantum-safe encryption.
To maintain security and compatibility during the transition, many organizations are implementing hybrid encryption methods that combine traditional and quantum-resistant algorithms. This approach allows for gradual migration to fully quantum-resistant systems while enabling protection against both current and future threats.
PQC Challenges And The Push For Wider Adoption
Commvault's phased introduction of PQC capabilities is a step forward, but current support is mostly limited to cloud-based customers using particular software versions. This creates a gap for organizations relying on hybrid or on-premises environments, which are still widely used in sensitive sectors like those already mentioned. To address this, Commvault would benefit from providing a clear roadmap for extending PQC support across all deployment models. Such a roadmap should outline which software versions will be supported, specify the technical requirements and offer a realistic timeline for implementation.
The broader data protection market is also shifting as major technology providers such as IBM and Microsoft integrate quantum-safe features into their platforms. Other data protection vendors, such as Cohesity, Veeam and Rubrik, are expected to follow suit as industry standards become more established. This means Commvault will likely face growing competition in offering robust PQC solutions. Keeping pace will require not only technical expansion but also practical guidance for customers on how to adopt and apply PQC in various enterprise scenarios. Flexibility and clear communication about available features and best practices will be important for supporting a wide range of customer environments and needs.
Aligning Data Security Strategies For A Quantum Future
Commvault's early efforts in post-quantum cryptography and crypto-agility demonstrate a commitment to long-term data security. However, maintaining progress will depend on expanding access to PQC features for all customers, providing transparent information about costs and continuing to work closely with regulatory bodies.
Quantum computing presents both new risks and opportunities. As traditional encryption methods become more vulnerable, the need for quantum-resistant security will grow. Commvault's PQC features offer a practical way for organizations to protect data that must remain secure for years. By focusing on adaptability, compliance and targeted encryption strategies, Commvault helps customers build stronger defenses for the future.
The timeline for quantum decryption could be shorter than many anticipate, making it important for organizations to start preparing now. For enterprises, taking early action is important to avoid exposure and regulatory issues. For vendors, ongoing improvements in accessibility, transparency and alignment with emerging standards will determine long-term success. Simplifying the path to quantum readiness will be a key factor in supporting customers through this transition.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Authors call on publishers to limit their use of AI
Authors call on publishers to limit their use of AI

Yahoo

time27 minutes ago

  • Yahoo

Authors call on publishers to limit their use of AI

An open letter from authors including Lauren Groff, Lev Grossman, R.F. Kuang, Dennis Lehane, and Geoffrey Maguire calls on book publishers to pledge to limit their use of AI tools, for example by committing to only hire human audiobook narrators. The letter argues that authors' work has been 'stolen' by AI companies: 'Rather than paying writers a small percentage of the money our work makes for them, someone else will be paid for a technology built on our unpaid labor.' Among other commitments, the authors call for publishers to 'make a pledge that they will never release books that were created by machine' and 'not replace their human staff with AI tools or degrade their positions into AI monitors.' While the initial letter was signed by an already impressive list of writers, NPR reports that another 1,100 signatures were added in the 24 hours after it was initially published. Authors are also suing tech companies over using their books to train AI models, but federal judges dealt significant blows to those lawsuits earlier this week.

Tipalti's Darren Upson on the strategic use of AI-driven finance
Tipalti's Darren Upson on the strategic use of AI-driven finance

Yahoo

time27 minutes ago

  • Yahoo

Tipalti's Darren Upson on the strategic use of AI-driven finance

Tipalti currently serves over 5,000 companies via AI-driven solutions to automate finance operations. These include accounts payable, employee expenses, global pay-outs, procurement, supplier management, and tax compliance. What should excite Tipalti's backers is the sheer scale of the addressable market of prospects not yet using AI-powered finance software. 'There are a huge number of companies, especially those of a more traditional nature, that have not even scratched the surface of automation and what it can do for their businesses,' says Darren is a fully automated, cloud-based platform that simplifies the most complex finance workflows, helping its clients manage end-to-end payables across multiple entities, currencies, and countries—with built-in compliance. And its seamless ERP integrations gives complete visibility and control. So, it eliminates manual work and speeds up the entire payables process, automating everything from invoice approval to global payments and reconciles data seamlessly. That summary is hardly over-techy and should be understandable to even the most basic of business leaders. The Tipalti proposition is boosted by the backing of JPMorgan Chase, which is about as good as it gets if you had the widest possible choice of potential financial backers. Back in 2023, Tipalti raised $150m in growth financing from JPMorgan and Hercules Capital. At the time, it brought total funding to more than $550m and valued the firm at over $8bn. JPMorgan is also one of the major banks Tipalti uses to route its billions of dollars' worth of supplier payments on behalf of its customers. 'We work in the fintech space as an automation platform for accounts payable and also mass payments as well. We are both a software company and a financial services business. We execute payments for our businesses and we handle the whole accounts payable process from start to finish, basically stripping out all of the manual, redundant processes associated with accounts payable. 'As that is the most time-consuming part of finance, we're trying to help organisations, especially those fast-growing businesses, to actually put their people to better use and leverage technology to really do that manual, repetitive work more efficiently, faster and to be more scalable as well.' He says that a typical client firm will be high-growth, pre-IPO outfits that have already embraced automation. They will be firms that understand how automation enables them to be more agile as an organisation. 'The big challenge that exists now is individuals' understanding the art of the possible. There's a lot of people that think that they've already automated everything they can do. But there's always more and with AI tools and the technology that exists out there, there's so many more areas across an organisation that you can automate to create more efficiency, especially when businesses are looking to try and retain and attract talent as well. It's about, how do they make sure that the people that are coming into the workforce now are doing roles that are actually fulfilling and that they enjoy.' In the run up to the UK's Labour government first budget, there was much negative press coverage forecasting doom and gloom if taxes such as capital gains tax were raised. In the end, the rate of increase was not as steep as the most pessimistic forecasts but CGT did rise from 20% to 24% for higher rate taxpayers. And given the track record over history of past Labour governments, further tax rises are more likely than any tax cuts. Upson says that the UK is still the number one destination out of North America for start-ups. 'We've got such a hotbed of talent, and we've got a large banking infrastructure in place as well. So [tax changes] do not mean that the lights are going to go out overnight. But I think that there have to be more incentives to actually attract and support individuals that are looking to build the next big thing.' "Tipalti's Darren Upson on the strategic use of AI-driven finance" was originally created and published by Retail Banker International, a GlobalData owned brand. The information on this site has been included in good faith for general informational purposes only. It is not intended to amount to advice on which you should rely, and we give no representation, warranty or guarantee, whether express or implied as to its accuracy or completeness. You must obtain professional or specialist advice before taking, or refraining from, any action on the basis of the content on our site.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store