Commvault · Security · YoctoIT tech page

Risk Analysis

Discover, classify and remediate sensitive data: PII and critical data mapped across file servers, endpoints and SaaS — with remediation actions, not just reports.

FOCUS · SENSITIVE DATA GOVERNEDFrom discovery to cleanup: move, archive or delete — inside the same tool
YoctoIT material for clients and partners · Commvault and the other products mentioned are trademarks of Commvault Systems, Inc.
01 · What it is

Risk Analysis, made clear.

Sensitive data piles up where it shouldn't: forgotten exports, copies of copies, folders shared with everyone. Risk Analysis discovers and classifies it — PII, financial, health data, intellectual property — using the protection infrastructure you already have, and lets you ACT: move to protected areas, archive, delete defensibly. GDPR stops being an Excel sheet.

60+
entities recognized: from tax codes to IBANs to medical records
Action
integrated remediation: move, archive, defensible delete
0 agents
analysis leverages backups and indexes that already exist
Risk Analysis
OFFICIAL BRANDING COMMVAULT
02 · How to use it well

The things that make the difference.

Data governance

Scattered datafile servers · endpoints · M365 · NAS
Discovery
ML classification
Risk scoring
patterns + machine learning + context
Risk Analysisthe data risk map
Remediationmove · archive · delete
Less surface, less risk, more compliance

Analysis from backups

Data already indexed for protection becomes the census base: zero impact.

Contextual risk

Not just WHAT's there: where, with which permissions, untouched since when.

Guided cleanup

Policy violations get fixed with actions: the report that executes itself.

Defensible deletion

Tracked, certified deletes: the right to be forgotten with evidence.

03 · In depth

From map to action: the data risk cycle

Classifiers (patterns, dictionaries, ML) analyze content and metadata from backups and sources; every finding carries context: owner, permissions, age, exposure; the risk score orders priorities; policies define the rules (e.g. 'no PII on public shares') and violations feed remediation flows — moves to protected areas, archiving with retention, certified deletion; reports speak GDPR: register, DSARs, oblivion.

  • Extended classifiers — Italian PII included: tax codes, IBAN, health
  • Context & permissions — the sensitive file on an open share: priority one
  • Location policies — where data MAY live: the rest is a violation
  • Fast DSARs — search by data subject: answers in hours
  • Certified delete — oblivion executed and documented
  • Infrastructure reuse — no new agent: you start from what's there
04 · Numbers and lifecycle

The numbers that matter.

60+
sensitive data types recognized
h
the response to a typical DSAR
-40%
typical reduction of redundant/obsolete data
GDPR
register and oblivion: with evidence
Data risk only shrinks by acting: a map that never becomes cleanup is just another PDF.
05 · Use cases

Where it really pays off.

Operational GDPR

DSARs, oblivion, register: executed, not promised.

File server hygiene

Shares full of PII: cleaned up.

Pre-migration

Migrate clean: the ROT stays behind.

How much sensitive data lives where it shouldn't? The first scan answers — let's run it.