Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs

Incident Response Automation with Recovery Agent

Cohesity
03/12/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • Recovery Agent automates incident response workflows through recovery groups and blueprints that act as digital jump bags, enabling organizations to orchestrate recovery from ransomware attacks and disasters without manual coordination
  • Blueprints function as automated runbooks with threat scanning, rehearsal capabilities, and dependency management, allowing teams to test recovery procedures before actual emergencies and ensure tools function properly
  • Clean room environments can be automatically provisioned with isolated workloads and forensic tools, enabling incident responders to investigate compromised systems safely while preventing further spread of attacks
  • New Copilot integration streamlines the creation of recovery groups and blueprints through guided workflows, reducing the complexity of configuring automated recovery procedures for critical workloads

Orchestrated Recovery for Cyber Incidents

This demonstration showcases Cohesity Recovery Agent, a feature within DataProtect designed to automate and orchestrate recovery workflows during ransomware attacks, data disasters, and catastrophic events. The presentation focuses on incident response scenarios where organizations need to isolate compromised systems in clean room environments while maintaining access to forensic tools. Recovery Agent introduces the concept of recovery groups that act as digital jump bags, providing incident responders with pre-configured, automated workflows that can be tested and rehearsed before actual emergencies occur. The solution addresses the challenge of coordinating recovery efforts without guesswork or miscommunication, particularly for critical workloads requiring rapid recovery time objectives.

Blueprints and Automated Workflows

The core functionality revolves around blueprints, which serve as automated runbooks for recovery operations. These blueprints enable organizations to define recovery options, dependencies, and automation rules that execute consistently across different scenarios. The demonstration highlights threat-aware workflows that perform automated threat scans and rehearsals on both digital jump bag components and application infrastructure before recovery. Blueprints can be configured to recover specific snapshot versions, allowing incident responders to analyze potentially infected backups in isolated environments. The system includes built-in reporting capabilities that document each step of the recovery process, providing audit trails for internal documentation and compliance requirements. A new Copilot integration further simplifies the creation of recovery groups and blueprints through guided workflows.

Chapters

0:00 - Introduction and Use Case
1:04 - Recovery Groups Overview
2:15 - Configuration and Blueprints
3:14 - Blueprint Workflow Demonstration
4:13 - Running and Monitoring Blueprints
5:20 - Copilot Integration

Key Quotes

0:15 "Our customers are telling us that they need the ability to orchestrate recovery from a wide variety of situations that include data disasters, catastrophic events and cyber attacks."
1:08 "As an incident responder, I can use recovery groups to accelerate incident response and disaster recovery during a ransomware attack. I can automate workflows without guesswork or miscommunication."
1:51 "And if you've ever worked with digital jump bags, you know that it's important not to wait for an actual emergency to use it for the first time."
2:32 "You can think of a blueprint as an automated workflow. It's designed to help bring your systems back online quickly and safely after a ransomware attack."
3:50 "This gives us a workflow that's threat aware and repeatable."
Categories:
  • » Webinar Library » Cohesity
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Security Operations
  • Demo
  • Technical Deep Dive
  • Incident Response Automation
  • Ransomware Recovery
  • Clean Room Environments
  • Digital Jump Bags
  • Disaster Recovery Orchestration
  • Threat Scanning
  • Recovery Workflows
  • Backup Rehearsal
  • Cyber Resilience
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Incident Response Automation with Recovery Agent

              Upcoming Webinar Calendar

              • 03/17/2026
                06:00 AM
                03/17/2026
                L'importance cruciale de l'ITDR pour 2026 et au-delà
                https://www.truthinit.com/index.php/channel/1856/limportance-cruciale-de-litdr-pour-2026-et-au-delà/
              • 03/18/2026
                01:00 PM
                03/18/2026
                Beyond Chatbots: Agentic AI That Actually Fixes Identity Risk
                https://www.truthinit.com/index.php/channel/1847/beyond-chatbots-agentic-ai-that-actually-fixes-identity-risk/
              • 03/19/2026
                11:00 AM
                03/19/2026
                Risk in Real Time: Stopping Exploits Before the CVE Even Exists
                https://www.truthinit.com/index.php/channel/1372/unlocking-network-intelligence-for-smarter-risk-decisions/
              • 03/19/2026
                01:00 PM
                03/19/2026
                Cyber CSI 2.0: Phishing Forensics in the Age of AI and Deepfakes
                https://www.truthinit.com/index.php/channel/1842/cyber-csi-2-0-phishing-forensics-in-the-age-of-ai-and-deepfakes/
              • 03/26/2026
                01:00 AM
                03/26/2026
                Reclaim Network Clarity and Accountability with Netskope DEM
                https://www.truthinit.com/index.php/channel/1846/reclaim-network-clarity-and-accountability-with-netskope-dem/
              • 03/26/2026
                05:00 AM
                03/26/2026
                ITDR as an Integral Component of Critical Security Architecture
                https://www.truthinit.com/index.php/channel/1863/itdr-as-an-integral-component-of-critical-security-architecture/
              • 03/26/2026
                01:00 PM
                03/26/2026
                HUMAN Dialogue: Transforming City-Scale Cyber Resilience through AI Innovations
                https://www.truthinit.com/index.php/channel/1835/human-dialogue-transforming-city-scale-cyber-resilience-through-ai-innovations/
              • 03/26/2026
                01:00 PM
                03/26/2026
                Making GPUs Available On Demand (Without Breaking the Budget)
                https://www.truthinit.com/index.php/channel/1858/making-gpus-available-on-demand-without-breaking-the-budget/
              • 04/08/2026
                01:00 PM
                04/08/2026
                Managing Configuration at Scale Across Group Policy and Intune
                https://www.truthinit.com/index.php/channel/1865/managing-configuration-at-scale-across-group-policy-and-intune/

              Upcoming Events

              • Managing Configuration at Scale Across Group Policy and Intune

                Managing Configuration at Scale Across Group Policy and Intune

                04/08/202601:00 PM ET
                • HUMAN Dialogue: Transforming City-Scale Cyber Resilience through AI Innovations

                  HUMAN Dialogue: Transforming City-Scale Cyber Resilience through AI Innovations

                  03/26/202601:00 PM ET
                  • Making GPUs Available On Demand (Without Breaking the Budget)

                    Making GPUs Available On Demand (Without Breaking the Budget)

                    03/26/202601:00 PM ET
                    • ITDR as an Integral Component of Critical Security Architecture

                      ITDR as an Integral Component of Critical Security Architecture

                      03/26/202605:00 AM ET
                      • Reclaim Network Clarity and Accountability with Netskope DEM

                        Reclaim Network Clarity and Accountability with Netskope DEM

                        03/26/202601:00 AM ET
                        • Cyber CSI 2.0: Phishing Forensics in the Age of AI and Deepfakes

                          Cyber CSI 2.0: Phishing Forensics in the Age of AI and Deepfakes

                          03/19/202601:00 PM ET
                          • Risk in Real Time: Stopping Exploits Before the CVE Even Exists

                            Risk in Real Time: Stopping Exploits Before the CVE Even Exists

                            03/19/202611:00 AM ET
                            • Beyond Chatbots: Agentic AI That Actually Fixes Identity Risk

                              Beyond Chatbots: Agentic AI That Actually Fixes Identity Risk

                              03/18/202601:00 PM ET
                              • L'importance cruciale de l'ITDR pour 2026 et au-delà

                                L'importance cruciale de l'ITDR pour 2026 et au-delà

                                03/17/202606:00 AM ET
                                More channels
                                Truth in IT
                                • Sponsor
                                • About Us
                                • Terms of Service
                                • Privacy Policy
                                • Contact Us
                                • Preference Management
                                Desktop version
                                Standard version