Mario Leiva, specialist in architecting high-availability data protection frameworks across North America, Australia and Europe
Most organizations believe their backup is working. Most are wrong. Only 57% of enterprise backup jobs complete successfully, and just 61% of restore attempts meet the desired outcome — meaning nearly four in ten restores fail when data is actually needed (Backblaze 2024 State of the Backup Survey). At the same time, ransomware attackers now specifically target backup repositories in 96% of attacks, successfully compromising them 76% of the time (Veeam 2024 Ransomware Trends Report).
The result is a category shift underway across North American IT: from passive backup — storing data and assuming it’s recoverable — to verified recovery, where restore processes are tested continuously and recovery outcomes are guaranteed. Commvault backup, delivered through ThinkOn’s managed infrastructure, is built for that shift. Not just data protection, but documented, tested, auditable proof that recovery will work when it matters.
Glossary
Commvault backup: Commvault’s data protection platform, covering infrastructure and SaaS workloads from a unified console with automated recovery verification, immutable storage, and ransomware defense built in.
Verified recovery: A backup practice in which restore processes are regularly and automatically tested to confirm that data can actually be recovered — not just stored. Unverified backups may appear healthy but fail at the moment of restore.
Backup as a service (BaaS): A cloud-based model in which backup, storage, and recovery capabilities are delivered and managed by a third-party provider, eliminating the need to maintain on-premises backup infrastructure.
Immutable backup: A backup copy protected by object lock, preventing it from being altered, encrypted, or deleted for a defined retention period — even by attackers with full administrative credentials.
Air-gapped storage: A backup copy physically or logically isolated from the production network, ensuring it cannot be reached by ransomware or other network-based attacks.
RPO (Recovery Point Objective): The maximum acceptable amount of data loss measured in time — the point to which data must be recoverable after an incident.
RTO (Recovery Time Objective): The maximum acceptable time to restore systems after an incident. A lower RTO means faster recovery and less business disruption.
Why passive Commvault backup is no longer enough
Storing data and assuming it’s recoverable are two different things — and the gap between them is where most backup failures live.
A backup environment that runs scheduled jobs and shows green dashboards is not the same as one that has been tested. Most backup failures are silent: a job completes, no alert fires, and no one discovers the restore would fail until it’s attempted during an active incident. At that point, the cost of the assumption becomes measurable.
Organizations with compromised or untested backups face recovery costs eight times higher than those with intact, verified ones (Sophos 2024). The average ransomware incident costs $4.4 million in total damage (IBM Cost of a Data Breach Report, 2025). Attackers have made this worse by specifically targeting Commvault backup repositories and other backup infrastructure before triggering encryption — with a 76% success rate in compromising them. An unverified backup stored alongside a compromised network is not a recovery asset. It’s a liability.
The shift to verified recovery is the operational response to this reality. It means Commvault backup is configured not just to store data, but to test that data can be restored — automatically, continuously, without manual intervention — and to produce documented evidence of that outcome
What does verified recovery mean in practice?
Verified recovery means every restore has been tested and confirmed — not assumed. Commvault backup automates that verification across all workloads, continuously, and produces documented evidence recovery will succeed.
Commvault’s automated recovery verification runs restore tests without engineering intervention on an ongoing basis. For every workload in the protected environment — virtual machines, databases, Microsoft 365, Salesforce, Entra ID — Commvault confirms that recovery would succeed to a defined RPO and RTO, and logs that confirmation as auditable evidence.
For MSPs, this changes the commercial conversation entirely. Rather than selling backup as a cost of doing business, verified recovery is a deliverable with a proof point: documented test results showing every client’s environment can be recovered to a defined standard. That’s a service line, not a commodity — and it commands pricing that reflects the assurance it provides.
For enterprise IT leaders, it answers the question that matters most before an incident: if we needed to recover today, would it work? With Commvault backup and continuous verification through ThinkOn, the answer is documented.
How does Commvault backup protect against ransomware?
Commvault backup layers immutable copies, air-gapped storage, and isolated Cleanroom Recovery to prevent ransomware from reaching or destroying backup data — even when attackers have full administrative access.
Commvault backup layers three ransomware controls across every protected environment:
Immutable backup copies. Object lock-based immutability prevents backup data from being encrypted or deleted during the retention period — even if an attacker obtains full administrative credentials for the backup application. The lock is enforced at the storage layer, below the application, making it structurally resistant to credential-based attacks.
Air-gapped storage. Commvault supports air-gapped backup targets including ThinkOn’s hardened repository infrastructure, which physically isolates backup copies from the production network.
Cleanroom Recovery. Launched in 2025, Commvault’s Cleanroom Recovery capability stages data in an isolated environment for forensic verification before it is reintroduced to production — eliminating the reinfection loop that affects organizations without a verified recovery step.
Together, these controls ensure that a clean, recoverable copy of every workload always exists, regardless of what happens to the production environment. Organizations with intact, tested backups recovered within a week 46% of the time after ransomware; those with compromised backups recovered within a week only 26% of the time (Sophos 2024).
What workloads does Commvault backup cover?
Commvault backup protects on-premises servers, cloud infrastructure, Microsoft 365, Salesforce, Entra ID, databases, endpoints, and Kubernetes — all verified from one platform, with no separate tools required.
| Workload | Coverage |
|---|---|
| On-premises servers and VMs | VMware, Hyper-V, physical servers, NAS |
| Cloud infrastructure | AWS, Azure, Google Cloud VMs and databases |
| Microsoft 365 | Exchange Online, SharePoint, OneDrive, Teams |
| Salesforce | Objects, files, metadata, and chatter |
| Microsoft Entra ID | Directory objects, group memberships, conditional access policies |
| Databases | SQL Server, Oracle, SAP HANA, PostgreSQL |
| Endpoints | Windows and macOS laptops and desktops |
| Kubernetes | Container workloads and persistent volumes |
Verified recovery applies across all of them. Commvault backup doesn’t just protect each workload — it tests that each can be restored to a defined recovery point. Commvault has been named a Leader in the Gartner Magic Quadrant for Backup and Data Protection Platforms for 14 consecutive years, and was the only vendor to score 4.0 or higher out of 5 across all six use cases in the 2025 Gartner Critical Capabilities report — including SaaS, Disaster Recovery, and Ransomware Protection.
How ThinkOn delivers Commvault backup as a managed service
ThinkOn delivers Commvault backup as a fully managed, multi-tenant service — verified recovery, ransomware protection, and compliance documentation included — with predictable per-workload billing and no infrastructure to own.
ThinkOn’s Data Protect with Commvault Cloud service gives channel partners and enterprise clients access to the full Commvault backup platform without provisioning or maintaining the underlying infrastructure. ThinkOn operates the platform; the MSP or IT team operates the client relationship.
No infrastructure to manage. ThinkOn provisions and operates the underlying compute, storage, and licensing. Engineering time goes to client delivery — not platform maintenance.
Predictable, per-workload billing. Transparent pricing per workload with no egress fees on restores and no minimum duration charges. Total Commvault backup spend is a fixed, forecastable number.
Sovereign data residency. Data remains within ThinkOn’s regional North American infrastructure, with contractual residency commitments for clients in regulated industries.
Continuous verified recovery included. Automated restore testing and recovery documentation are part of the service — not an add-on. Every client environment is continuously verified against defined RPO and RTO targets.
Verified recovery turns backup from a line item into a guarantee. For MSPs, that’s a service worth charging for. For enterprise clients, it’s the difference between a tested plan and an untested assumption.
Ready to move from passive backup to verified recovery? Contact the ThinkOn partner team or compare Commvault Cloud vs. Veeam.
Key statistics and sources
- 96% / 76%of ransomware attacks target backup repositories; 76% successfully compromise them (Veeam 2024 Ransomware Trends Report)
- $4.4 millionaverage ransomware damage cost per incident (IBM Cost of a Data Breach Report, 2025)
- 57% / 61%enterprise backup job completion rate; restore success rate — 4 in 10 restores fail (Backblaze 2024 State of the Backup Survey)
- 8xhigher recovery costs for organizations with compromised backups vs. intact ones (Sophos State of Ransomware 2024)
- 46% vs 26%weekly recovery rate with intact tested backups vs. compromised ones after ransomware (Sophos State of Ransomware 2024)
- 14 yearsconsecutive Gartner Magic Quadrant Leader for Backup and Data Protection Platforms (Commvault, 2025)
