Commvault’s Fady Richmany on why resilience now beats prevention
The corporate VP and general manager for emerging markets explains why organisations winning in cybersecurity are no longer trying to prevent breaches, they are building to recover from them at speed
30 June, 2026
TT
16
The window between a cybersecurity vulnerability becoming public and an attacker exploiting it has collapsed from 23 days in 2025 to barely a day in 2026. No human watching dashboards can keep pace with that velocity.
At SHIFT Dubai, Fady Richmany, corporate VP and general manager for emerging markets at Commvault, explains why AI-powered threat detection is no longer optional, and why the real advantage now sits with organisations that have stopped trying to prevent breaches and started building to recover from them at speed.
How can AI help identify cybersecurity threats faster? Please provide a percentage and how many threats has it been able to identify in this year so far?
The honest answer is that speed has become the whole game. The window an attacker needs to move from a vulnerability becoming public to actively exploiting it has fallen from around 23 days in 2025 to barely a day in 2026, according to PwC, and a human watching dashboards simply cannot keep pace with that anymore. What AI does well is sit across enormous volumes of data and identity activity and recognise the patterns that signal something is wrong. This would include aspects like an unusual access request, or a privilege that quietly changes, or data that starts moving when it should be sitting still. AI surfaces those signals in near real time rather than days later, and that is the difference between containing an incident and explaining one afterwards.
The industry numbers support this. IBM’s 2025 Cost of a Data Breach report found that the global average breach cost fell by 9 per cent year on year, the first decline in five years, and the reason was faster detection and containment driven by AI-enhanced tools. The organisations using AI and automation extensively identified and contained their breaches 80 faster than everyone else and saved close to $1.9m in the process. The catch is that only about a third of organisations are using it that way today, so the advantage still sits with a minority who have embraced it.
At Commvault, we put AI to work in exactly this place, watching for anomalies across data and identity, drawing on third-party threat intelligence so we are never relying on a single view, and pointing customers to a clean recovery point the moment something looks wrong.
What best practices should organisations adopt when implementing AI-related cybersecurity solutions?
Start with the data, because every AI system is only as trustworthy as the data feeding it. If that data is poisoned or quietly tampered with, the integrity of everything downstream is compromised, so you need to know what you hold, classify it, and govern who and what is allowed to touch it before it ever reaches a model or an agent. That governance piece is exactly why we recently brought Satori into the portfolio.
The second thing is identity, and I would place it close to the top. AD is one of the hottest threat vectors for bad actors to exploit. Nine out of ten attacks target AD because it controls access to data, systems, and applications – without it, business operations can grind to a halt. Agentic AI is multiplying the problem, because every autonomous agent you deploy is effectively a new identity, a non-human one that lives on data and becomes its own door into the environment.
Protecting identity on its own is no longer enough. It has to be wired together with your data security and your recovery so that the three areas work as one discipline rather than three teams who only meet during a crisis.
The third is to accept that you will be breached one day and to build for that eventuality well in advance. Strong walls are necessary and you should still build them, but I always say that resilience begins where security ends. So, the real question becomes, how cleanly and how quickly you can recover when something gets through? That means testing recovery continuously rather than once a year, keeping a known clean copy you can actually trust, and rehearsing with the security and infrastructure teams in the same room. We wrap all of that into what we call resilience operations, or ResOps, which treats resilience as a living operating model built on people, process and technology rather than a tool you switch on and forget.
What are some common challenges and mistakes made by organisations in deploying AI cybersecurity solutions?
The most common and most damaging mistake is leaving the work in silos. In a large enterprise, you typically find one team running the collaboration platforms, another running infrastructure, another handling backup and recovery, another in security operations, and another in analytics. On an ordinary day, that division of labour looks perfectly sensible. The moment a cyber incident lands, it becomes chaos, because five or six departments who have rarely spoken to each other suddenly have to coordinate while forensics are still working out what happened and how far it spread. We call that the ‘IT collision’, and if those teams have never run the drill together, it is the hardest position an organisation can find itself in.
The second mistake is pouring the entire budget into prevention. I have seen organisations spend a lot building the highest possible wall around the castle, and they still get breached, because someone always finds a way in. That money would go a great deal further if some of it were redirected toward the dark day when the breach actually arrives, so that the answer to “what now” is a resilient operation that can restore identity, data and operations at speed.
The third is deploying AI on top of data that nobody is governing. IBM found that 97 per cent of the organisations that suffered an AI-related breach lacked proper access controls around those systems, and that most had no governance policy in place at all. People rush to switch on the capability and worry about who can reach the underlying data afterwards, which is precisely the wrong order to do it in. Instead, organisations need to establish governance before deployment, with clear controls around data access, identities, and accountability. AI is only as trustworthy as the data and safeguards behind it.
What are some emerging AI cybersecurity trends?
The trend underneath all the others is the explosion of machine identity. We have spent years learning how to secure human users, and now every AI agent we deploy arrives as a new non-human identity that breathes on data and has to be governed and protected like any other. G42 Group CEO Peng Xiao has talked about building and deploying a billion agents, and when you sit with a number like that you realise the attack surface is expanding faster than most security models were ever designed to handle.
Alongside that, attackers now have frontier AI in their hands, which is why the time from a vulnerability becoming public to it being exploited has collapsed from weeks to roughly a single day. The defensive response is AI against AI, using intelligence to spot the anomaly and point to the clean recovery point faster. We are also seeing data governance move to the front of the conversation, because both the value and the risk sit in the data feeding these models, and organisations are starting to govern how that data is used before it reaches an agent rather than after the fact.
Looking a little further out, resilience itself is becoming more predictive and more automated, with systems that can forecast where a recovery might fail and increasingly detect, validate and recover with far less human intervention. In the Middle East region, there is a particularly strong thread around sovereignty, where each country sets its own rules on where data lives and how it can be accessed, and the technology has to adapt to each of those rather than assume one model fits everyone.
What’s next for your business?
We are committed to our work for our customers and partners in the Middle East, and our SHIFT event in Dubai last week was the clearest signal of that. We used the keynote to talk about resilience reimagined for the AI era, we heard Dr Mohamed Al Kuwaiti, head of Cyber Security for the UAE Government, set out the national picture with the UAE absorbing close to 800,000 attacks a day, and we announced the Commvault Innovation Centre of Excellence with the UAE Cyber Security Council in Abu Dhabi. That centre matters to me personally, because it is where we will sit with government and with universities to research, develop and train local talent in cyber resilience, and building that homegrown capability is how a country stays ready over the long term rather than the short.
Beyond that, our focus is on helping customers move from owning a recovery tool to running resilience as a discipline. We are bringing identity, data security and cyber recovery together on a single platform in Commvault Cloud Unity so that recovery is clean, fast and complete when it matters most, and we are continuing to extend that platform into the AI estate itself.
The thread running through all of it is simple to say and hard to do well. Resilience is no longer a back-office insurance policy, it belongs at the centre of how every AI-era business is designed and run, and our job is to keep making that achievable for the organisations and the nations we work with across the region.
























