Druva, the leading provider of data security solutions, announced the launch of Threat Watch, a zero-touch, automated cloud-native capability that continuously monitors backup snapshots to detect dormant threats and indicators of compromise (IOCs), enabling faster incident response and safer cyber recovery.
Modern cyber threats frequently bypass primary defenses, making it essential to understand data impact for effective incident response and recovery. Backups serve as an accurate mirror of production systems, offering critical visibility into threat scope and clean restore points. Threat Watch provides always-on, peace-time monitoring of backup data, complementing reactive threat hunting during active incidents. With tightening regulatory timelines under frameworks such as DORA and SEC rules, the capability helps teams quickly assess impact, prove data integrity, and meet strict reporting requirements.
"Cyber resilience isn’t just about having a copy of your data, it’s about the certainty that you can recover without reinfecting your environment," said Yogesh Badwe, Chief Security Officer at Druva. "Threat Watch brings a peace-time proactive monitor to what has historically been a war-time manual forensic process. With this new capability, we are giving customers the forensic evidence they need to meet strict regulatory windows and have clearer proof of what is safe to restore when the business is under pressure.”
Threat Watch leverages Druva’s fully cloud-native platform to scan backup data directly in the Druva Data Security Cloud, outside of production environments. This in-place approach eliminates delays from data egress, avoids performance impact on live systems, and upholds Druva’s industry-leading Data Movement Latency SLA. No additional hardware, agents, or complex integrations are required, making proactive threat detection accessible and cost-effective.
“Reporting timelines are getting tighter, and that puts pressure on teams to confirm what was impacted and what is safe to restore,” said Yong Jie Tan, IT Infrastructure Manager, at Woh Hup. “Threat Watch gives us ongoing visibility into backup health and the evidence we need to support both recovery decisions and audit requirements. It helps reduce uncertainty during an incident and strengthens our overall resilience posture."
Threat Watch delivers several key advantages for IT and security teams:
Threat Watch is generally available today for cloud and data center workloads, including Amazon EC2, Azure VMs, and VMware VMs, with additional workload support planned soon.
Resources
About Druva
Druva is the leading provider of data security solutions, empowering customers to secure and recover their data from all threats. The Druva Data Security Cloud is a fully managed SaaS solution offering air-gapped and immutable data protection across cloud, on-premises, and edge environments. By centralizing data protection, Druva enhances traditional security measures and enables faster incident response, effective cyber remediation, and robust data governance. Trusted by nearly 7,500 customers, including 75 of the Fortune 500, Druva safeguards business data in an increasingly interconnected world.