IT Brief Canada - Technology news for CIOs & IT decision-makers
Canada
Commvault links recovery actions into CrowdStrike SOAR

Commvault links recovery actions into CrowdStrike SOAR

Mon, 31st Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Commvault has integrated its cyber recovery actions into CrowdStrike's Charlotte Agentic SOAR workflows. The integration is now generally available to joint customers.

It allows security teams to trigger Commvault recovery steps as native actions inside CrowdStrike's workflow orchestration tool, reducing manual coordination between security and recovery teams during cyber incidents.

Functions included in the integration include restricting access in Commvault during an active incident to prevent unauthorised changes, suspending backup data ageing policies to preserve recovery points, and restoring potentially compromised assets into Commvault Cleanroom for forensic analysis without affecting production systems.

The companies are addressing a common problem in cyber incident response: detection and investigation may be heavily automated, but recovery actions often still require separate processes across different teams and software products.

By embedding recovery tasks into automated security workflows, Commvault is aiming to move backup and recovery operations closer to the centre of incident response, rather than treating them as a separate stage after investigation or containment.

Workflow link

Charlotte Agentic SOAR is CrowdStrike's orchestration platform for security operations. The new connector lets users include Commvault actions directly in those workflows, linking investigation, response and recovery within the same sequence of steps.

That means an organisation responding to a ransomware attack or suspected system compromise could use a CrowdStrike workflow not only to gather evidence and assign actions, but also to lock down recovery settings and prepare clean copies of systems for examination.

The integration is designed for joint customers and is also available through the CrowdStrike Marketplace, widening access for organisations that already use both suppliers' products.

Existing ties

The announcement builds on an existing relationship between the two companies. Earlier integrations connected CrowdStrike's Falcon Insight XDR with Commvault Cloud to bring threat intelligence into Commvault, while Falcon Next-Gen SIEM extended visibility across environments.

This latest step is more directly tied to operational response because it focuses on carrying out recovery-related actions from within an automated security workflow, rather than simply sharing alerts or telemetry.

The broader market trend behind such tie-ups is a push by cyber security vendors to make incident response less dependent on separate teams passing tasks between each other in the middle of an attack. Security operations centres often work in one set of tools, while backup, infrastructure and recovery teams work in another, creating delays when time is critical.

Vendors have increasingly sought to address that divide by linking orchestration tools with recovery systems, particularly as ransomware and destructive attacks have made the recovery stage more strategically important.

Vidya Shankaran, Field CTO, Commvault, outlined the company's position on the integration.

"Security and recovery teams need to move quickly and in coordination during an incident," said Vidya Shankaran, Field CTO, Commvault. "Our integration with CrowdStrike Charlotte Agentic SOAR makes Commvault cyber recovery actions available directly within security workflows, helping joint customers reduce manual handoffs and accelerate investigation and response. This strengthens cyber resilience and simplifies how security and recovery teams work together seamlessly."

The reference to manual handoffs reflects a longstanding operational issue for large organisations, where cyber incidents can involve security analysts, infrastructure administrators, backup specialists and external investigators all working from different systems and priorities.

In practice, preserving clean recovery points can be one of the more sensitive tasks during an incident. If standard retention or ageing policies continue to run during a live attack, organisations risk losing backup versions that may later prove to be the safest point from which to restore. Suspending those policies automatically as part of a response workflow may help reduce that risk.

Likewise, the ability to restore suspicious assets into an isolated cleanroom environment is likely to appeal to organisations that need to investigate malware or unauthorised changes without reintroducing compromised systems into live operations.

The launch also reflects how suppliers are increasingly using AI-led security operations as the framework for integrating adjacent tasks such as data recovery, containment and post-incident investigation. While the companies describe the workflow environment as agentic, the practical effect is that actions that previously sat outside a security playbook can now be inserted into the same automated process.

For Commvault, the partnership supports a broader strategy of positioning recovery as an active part of cyber defence rather than a back-office IT function. For CrowdStrike, it adds another operational workflow inside its security platform by linking detection and response with actions taken on protected data and systems.

The integration is generally available for joint Commvault and CrowdStrike customers.