Commvault has announced a new integration with Google Threat Intelligence to accelerate one of the most sensitive processes after a ransomware attack: identifying which backups can be safely restored. The collaboration will enable the incorporation of Google’s threat intelligence directly into Commvault’s recovery workflows, helping to detect compromised copies before starting the restore and reducing the time needed to resume business operations.
The main points of the Commvault and Google integration in 20 seconds
- Commvault will integrate Google Threat Intelligence into its cyberattack recovery platform.
- The solution will help identify malware-free restore points before data recovery.
- It incorporates hash analysis of files during the backup process itself.
- The company thus reinforces its ransomware resilience strategy and defenses against AI-driven threats.
In recent years, backups alone have stopped being sufficient to ensure business continuity. After a ransomware incident, one of the biggest challenges is knowing which backup is truly clean and can be used to restore systems without reintroducing malware into the infrastructure.
That scenario is exactly what the new integration announced by Commvault during Black Hat USA 2026 aims to address, one of the leading international cybersecurity events.
Recovering the right data, not just data
When an organization detects a cybersecurity incident, response teams usually quickly identify indicators of compromise (IOC). However, the team responsible for restoring the infrastructure needs to verify which backup copies remain threat-free.
This process can delay full system recovery for hours or even days.
The integration with Google Threat Intelligence aims to reduce that uncertainty by leveraging multiple sources of intelligence developed by Google:
- Information from Mandiant, specialized in incident response.
- The threat knowledge base of VirusTotal.
- Intelligence collected by Google from safeguarding billions of users and devices.
All this information will be used to automatically analyze data protected by Commvault and identify recovery points showing signs of compromise.
Hashes during backup to speed up validation
One of the key technical innovations is the addition of file hash calculations during the backup process itself.
A hash acts as a unique digital fingerprint for each file. Comparing these fingerprints against known malware databases enables quick detection if a file matches previously identified threats.
This approach allows for a rapid preliminary validation before conducting deeper analyses such as:
- Malware scanning.
- Detection of malicious encryption.
- Forensic analysis.
- Advanced inspection of suspicious files.
According to Commvault, this staged strategy helps accelerate decisions about which copy to restore without compromising security.
Restoring only clean data
The new capabilities also enhance an existing feature in the platform called Synthetic Recovery.
This technology uses artificial intelligence algorithms to automatically detect threats present in protected data and remove only the compromised elements during the restoration process, preserving the rest of the information.
The goal is to avoid two common scenarios after an attack:
- Restoring an infected backup.
- Having to go too far back in time and lose valid data.
Instead of choosing between these options, Commvault aims to recover the greatest possible volume of clean data.
Recovery as an intelligence-driven discipline
This announcement reflects an evolution happening across the enterprise backup sector.
Traditionally, backup platforms focused on ensuring data can be recovered.
Now, the approach has shifted toward cyber-resilience, incorporating elements such as:
| Traditional approach | New resilience approach |
|---|---|
| Backups | Verified backups |
| Data recovery | Recovery of clean data |
| Storage protection | Threat validation |
| Periodic backups | Continuous analysis and threat intelligence |
This transformation addresses the growing sophistication of ransomware attacks, which can remain hidden for weeks before encrypting data or even compromising backup copies themselves.
Google and Commvault expand their collaboration
The integration is part of a broader partnership between the two companies.
In recent months, Commvault has already strengthened its support for Google Cloud, including new capabilities for cloud workload protection and integrating technologies acquired from Clumio, a cloud data protection specialist acquired by Commvault in 2024.
With this new integration, Google provides one of the world’s largest threat intelligence repositories, while Commvault directly embeds that intelligence into the recovery process.
The new features are expected to be available in the coming months, according to the company.
A market where backup and cybersecurity converge
The announcement also confirms a trend already followed by other sector players.
Companies like Veeam, Rubrik, Cohesity, and Commvault itself are expanding their platforms to incorporate cybersecurity capabilities, threat analysis, and artificial intelligence.
The aim is no longer just to protect data, but to ensure they can be recovered quickly and confidently, free of malware.
In a landscape where AI-driven attacks and ransomware campaigns continue to increase, verified backups are becoming as crucial as having the copies themselves.
Frequently Asked Questions
What does the integration between Commvault and Google Threat Intelligence offer?
It allows leveraging Google’s threat intelligence to analyze backups and identify which restore points are free of malware before starting the recovery.
What are file hashes?
They are unique identifiers generated from a file’s content. Comparing them against threat databases helps quickly detect known malicious files.
What is Synthetic Recovery?
It’s a Commvault technology that uses artificial intelligence to detect threats during recovery and restore only the data deemed safe.
When will this integration be available?
Commvault has indicated that the new features will be rolled out over the next few months, without specifying an exact date for general availability.

