Cyberattack recovery gets a security upgrade as Commvault brings Google Threat Intelligence into the backup process to help companies find safe data faster.
Commvault is integrating Google Threat Intelligence into its Threat Scan workflows to help organizations identify clean recovery points more quickly after ransomware and other cyberattacks.
Integrating Google Threat Intelligence with backup scanning
The announcement comes as organizations face a growing challenge during cyber incidents: knowing whether their backups have been affected before bringing systems back online. While security teams may detect indicators of compromise, recovery teams still need to verify that backup data is safe before starting restoration.
Commvault said the integration will combine threat intelligence data with backup scanning capabilities, allowing security and recovery teams to quickly identify compromised data and decide what can safely be restored.
This integration brings Google Threat Intelligence data into the recovery process to help customers analyze protected workloads for malware and identify recovery points that may have been compromised.
Google Threat Intelligence combines intelligence from Mandiant, VirusTotal, and Google’s broader threat insights collected from protecting billions of users.
The companies said Commvault Threat Scan customers will receive additional threat context for detected risks, helping security teams investigate threats and support remediation efforts.
“Businesses need confidence that the data they’re restoring is clean,” said Pranay Ahlawat, chief technology and AI officer at Commvault. “By combining Threat Scan and inline scanning with Google Threat Intelligence, we’re helping customers validate recovery points faster and accelerate clean recovery when it matters most.”
New inline scanning speeds up backup validation
Alongside the Google Threat Intelligence integration, Commvault introduces new scanning features designed to collect file hashes during backup operations.
File hashes act like digital fingerprints for files, allowing organizations to compare recovery points against known threat indicators. The company said this approach can help teams identify clean files more quickly instead of relying only on deeper analysis after an attack.
Commvault said its inline inspection technology allows organizations to begin with rapid threat intelligence checks and then perform more detailed malware, encryption, and forensic analysis when necessary. This layered approach is designed to speed up recovery decisions while helping maintain confidence that restored data is safe.
”Organizations are looking for ways to strengthen cyber resilience while reducing complexity during incident response and recovery,” said Miton Adhikari, head of Google Security OEM partnerships.
”Through our collaboration with Commvault, customers will be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed recovery decisions and reduce recovery uncertainty.”
Availability of the new integration
Commvault said the Google Threat Intelligence integration, inline scanning features, and related Threat Scan improvements are expected to become available in the coming months. The company will showcase the integration during a Google Theater Session featuring Commvault at Black Hat on Aug. 4 at the Mandalay Bay Convention Center in Las Vegas.





