One year ago, Druva introduced Dru MetaGraph; and now we’re starting to see how it all comes together where governance and AI land within their Resilience Cloud. Here’s what happened in between and why it matters for Cyber Resilience.

video transcript

When people talk about governance as it relates to IT, most immediately jump on the rules side: the policies and guardrails that essentially say what something can and cannot do. While rules provide a prescriptive framework for the future, the other equally important part of governance is accountability: the retrospective lens of who did what in a way that is auditable.

I’ve been in data protection for 35 years, over half of it as a researcher or analyst. What you learn over time is that there’s a lot of data, statistics, charts, tables, quotes, … and noise. The trick is not citing a statistic; it’s discerning the shape of data … it’s the correlating of different data from different sources and pulling it together in a way to understand that big picture so that you can gain insights … so that you can take action.

So, let’s connect some dots:

  • One year ago today, Druva introduced Dru MetaGraph, as a way to aggregate backup metadata and then expose it via AI and their own Dru agents.
  • Over the summer we saw Druva’s Resilience Cloud launch, as a way to unify their data, cyber, identity, and AI capabilities, including not only the ability to defend and recover from AI threats and errant AI actions, but also … you guessed it … govern AI work.
  • In between, they added support for an on-premises’ Dell Data Domain to complement their otherwise cloud strategy. That’s not applicable to this blog, but it’s too cool not to mention.

Which brings us to today’s announcement:

Backup may be ‘the great aggregator‘ for data, but it’s contextual awareness of the metadata that’s needed to unlock the accountability side of governance. THAT is what’s new in Dru MetaGraph: connecting and contextualizing activity across your identity platforms, mapping against the MITRE ATT&CK framework, and then generating recovery plans in preparation for remediation. Because until you understand the real blast radius for what the threat actors did once they got inside, you aren’t fully informed on what’s necessary to adapt your conceptual remediation plans into something applicable in the moment.

Where this gets really cool is that the platform itself handles rollback/recovery of the identity environment back to a known-good state. And in true Governance fashion, the handling of containment, sessions, and credentials are prescribed by Druva, but executed by your human in the loop within your identity provider. Speaking of accountability as part of governance, the other notable nuance is that Druva is the tamper-proof record of who did what.

Cuz you can’t have governance without accountability … and you can’t have accountability without auditability … which requires a defensible record of what happened, when, by whom, as well as what steps you took to remediate it. DPM is looking forward to getting some hands-on time inside Druva’s Resilience Cloud later this year, including leveraging their MCP to turn Claude into my backup admin; but that’s a different vlog. Until then, leave your thoughts below.

Leave your thoughts on the LinkedIn article.

Leave a Reply

Trending

Discover more from Jason Buffington .com

Subscribe now to keep reading and get access to the full archive.

Continue reading