Commvault and CrowdStrike partnership brings recovery into SOAR

Security response does not always end with finding a threat. Once an incident is identified, teams still need to protect recovery data, investigate affected systems and coordinate actions across security and recovery tools. The new Commvault and CrowdStrike partnership aims to close that gap by bringing Commvault cyber recovery actions directly into CrowdStrike Charlotte Agentic SOAR workflows.
The integration allows joint customers to automate recovery actions as part of security workflows. The shift is important because it moves recovery closer to the point of incident response, reducing the need for security teams to manually coordinate with separate recovery teams when time matters.
Commvault recovery actions move into security workflows
The new connector allows Charlotte Agentic SOAR to trigger several Commvault actions during an incident. Teams can restrict access in Commvault to help prevent unauthorised changes, while backup data ageing policies can be suspended to preserve viable recovery points.
The integration also supports forensic investigations through Commvault Cleanroom. Potentially compromised assets can be restored into the isolated environment so investigators can begin analysis without disrupting production systems. For enterprises, the practical value lies in connecting investigation and recovery steps rather than treating them as separate processes.
From threat detection to recovery
The Commvault Cloud data connector builds on earlier integrations between the two companies. CrowdStrike Falcon Insight XDR previously brought threat intelligence into Commvault Cloud, while the Falcon Next-Gen SIEM integration extended visibility. The latest step adds recovery actions directly to automated security workflows.
That progression points to a broader focus on connecting different stages of cyber response. Instead of stopping at detection or investigation, the workflow can now incorporate actions that help protect recovery options and prepare affected assets for analysis.
What the integration means for enterprise teams
For security and recovery teams, the focus is less on adding another standalone tool and more on reducing manual handoffs during an incident. The CrowdStrike Charlotte Agentic SOAR integration gives security workflows access to Commvault cyber recovery actions through a purpose-built connector.
The integration is generally available to joint Commvault and CrowdStrike customers through the CrowdStrike Marketplace. With security actions and recovery steps brought closer together, the partnership places cyber recovery inside the wider incident response workflow rather than leaving it as a separate stage.
Read More:
Kaspersky SMB threat report puts META businesses on alert
ProHance appoints Ankur Agarwal to scale ProHanceCX
MSI Cubi NUC AI+ 3MG adds AI to Mini PCs
VerSe Innovation launches SparkStation for faster content production






