For years, the awkward truth about corporate cyber defence has been that most organisations have no idea whether their recovery plans actually work until the worst day arrives. Backups get taken, boxes get ticked and disaster recovery documents gather dust, but the real test only comes when ransomware has already locked the doors. Data protection vendor Commvault is now trying to close that gap with artificial intelligence, launching a tool that stages simulated attacks against a company’s own environment and then scores how ready it really is to bounce back.
The move, reported by CRN Australia, marks another step in the broader shift from prevention-first security thinking to what the industry now calls cyber resilience: the assumption that a breach will eventually happen, and that the measure of a good defence is how quickly and cleanly an organisation can get back on its feet. Rather than promising to keep attackers out, Commvault is effectively inviting them in, under controlled conditions, to see what breaks.
How the simulation works
At the centre of the launch is the idea of turning recovery from a vague reassurance into a hard number. The tool uses AI to model the kinds of attacks a real adversary might attempt, probing how data is stored, protected and restored across an environment. It then produces a recovery readiness metric, a score intended to tell executives and boards in plain terms whether their organisation could survive a serious incident and how long that recovery might take.
That framing matters because it speaks to a persistent blind spot. Plenty of companies invest heavily in backup infrastructure without ever running a genuine, end-to-end restoration under pressure. When they finally do, during an actual attack, they often discover that backups were incomplete, corrupted, or themselves compromised by the intruders. By simulating the attack in advance and measuring the outcome, Commvault is pitching a way to find those failures on a quiet Tuesday rather than in the middle of a crisis.
The approach also reflects how attackers themselves have evolved. Modern ransomware crews routinely hunt for and destroy backups before they trigger encryption, precisely because they know a clean, tested recovery path is the one thing that lets a victim refuse to pay. A tool that stress-tests recovery against that exact playbook is trying to meet the threat where it now lives.
Two ways to read the launch
Supporters of this kind of tooling argue it drags a neglected part of security into the light. Recovery has long been the poor cousin of the cyber budget, less glamorous than threat detection or fancy firewalls, and far harder to demonstrate to a board. Giving leaders a single readiness score, and the ability to watch it improve or slip over time, could finally make resilience a metric that gets managed rather than assumed. For chief information security officers under growing pressure to prove their spending works, a measurable figure is a powerful thing to carry into a budget meeting.
Sceptics will push back on a few fronts. There is a reasonable worry that any single score risks oversimplifying a messy, context-dependent problem, and that a healthy-looking number could breed complacency if executives treat it as a guarantee rather than a snapshot. There is also the broader industry pattern of stapling “AI” to established products, and buyers are right to ask how much genuine intelligence is doing the work versus clever automation of tests that skilled teams could already run. The value of a simulation ultimately depends on how faithfully it mirrors the tactics of real attackers, which change constantly. A readiness score is only as good as the threat model behind it.
What it means for Australia
For Australian organisations, the timing is pointed. The past few years have delivered a run of high-profile breaches that turned cyber resilience from a technical concern into a boardroom and kitchen-table one, and regulators have responded in kind. Directors now sit under sharper obligations to understand and govern cyber risk, and the federal government‘s cyber security strategy has leaned hard on the idea that Australia should be able to withstand and recover from incidents, not merely try to prevent them. A product that puts a number on recovery readiness lands squarely in that conversation.
The stakes are heightened by the shape of the local economy. Australia is rich in exactly the kinds of targets attackers prize, from banks and health insurers to telcos, superannuation funds and critical infrastructure operators, all holding vast troves of personal data. Many of these organisations are also grappling with the security implications of their own AI adoption, adding fresh complexity to environments that are already sprawling. Tools that promise to test recovery before an incident, rather than after, speak directly to the anxieties of Australian executives who have watched peers spend months and many millions cleaning up after a breach.
There is a cost dimension too. For mid-sized Australian firms without deep security teams, running realistic attack simulations by hand is often out of reach, which is part of the appeal of automating the exercise. Whether the pricing and complexity of enterprise-grade resilience tooling actually suit the broad middle of the market, rather than just the big end of town, will shape how far this kind of capability spreads locally.
What’s next
The real test for Commvault’s launch will be whether the recovery readiness metric proves credible enough to change behaviour. If boards start asking to see the score, and if a poor result triggers genuine remediation rather than a defensive shrug, the tool will have done its job. Expect rivals in the backup and resilience space to answer with their own AI-flavoured readiness measures, and expect customers to probe hard on how the simulations are built and how often they are refreshed against emerging threats.
The deeper shift is the one worth watching. Australian organisations are being nudged, by regulators, insurers and hard experience, to treat recovery as something to be proven rather than presumed. Whether artificial intelligence turns out to be the tool that finally makes that discipline routine, or just the latest label on an old problem, will become clearer as the first readiness scores start landing in front of Australian boards.
Sources: CRN Australia.


















































