Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Incident Response Automation with Cohesity Recovery Agent

Cohesity
03/12/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hello everyone, my name is Shelley Calhoun-Jones and I'm a Technical Marketing Director here at Cohesity. Our customers are telling us that they need the ability to orchestrate recovery from a wide variety of situations that include data disasters, catastrophic events and cyber attacks. In the context of this demo, I'm an incident responder and I'm currently dealing with an active security event. To address this situation, I plan to secure the system in an isolated space to investigate without the risk of further spread. Additionally, I need a safe and repeatable process to ensure that I can respond quickly. In this demo, we'll explore how organizations can utilize Recovery Agent to set up a digital jump bag and a clean room for incident response. But first, let's set the stage. As an incident responder, I can use recovery groups to accelerate incident response and disaster recovery during a ransomware attack. I can automate workflows without guesswork or miscommunication. It could be a critical workload which requires a quick recovery time objective, like with a CRM application. Or you may have a recovery group for your digital jump bag. Let's take a closer look at how this works. A recovery group can help me coordinate resources and tools to restore systems after a cyber attack or outage. This recovery group acts as my digital jump bag. And if you've ever worked with digital jump bags, you know that it's important not to wait for an actual emergency to use it for the first time. As an incident responder, I need to ensure that our tools are functioning properly. It's also vital that I prepare my team to handle incidents and identify any gaps in readiness. In the configuration section, you'll find options for a threat scan and a rehearsal, along with the ability to set up multiple configurations for testing. And you'll also notice that we have a blueprint. You can think of a blueprint as an automated workflow. It's designed to help bring your systems back online quickly and safely after a ransomware attack. When applied in clean room environments, it can automatically create a safe, isolated space that you can use for investigating and recovering data. And with the digital jump bag, the blueprint can launch ready-to-use virtual tools and configurations, ensuring that my responders have everything they need to conduct their Speaking of which, let's take a look at blueprints and how it helps in automated workflows. You can set up recovery options, dependencies, and automation rules to ensure that incident response happens consistently and efficiently. It's a virtual runbook that you can run once or periodically. In this workflow, you can see that we're performing a threat scan and rehearsal on our digital jump bag. We're also looking to determine if we need to recover a CRM application into our clean room environment. So we're performing a threat scan and rehearsal on different components that represent the application. This gives us a workflow that's threat aware and repeatable. At the end of the workflow, you'll notice that we have a five-minute pause and a teardown from an automation server. If I want to add additional steps, I can click on the ellipsis, choose add new task, and we can add those steps here. Let's take a look at how to run a blueprint. On this screen, you can choose a specific recovery point, which can be helpful if you need to test recovering a snapshot from a specific date range into the clean room environment. For example, we could be looking for an infected snapshot to analyze. For right now, I'll click on submit. I can also monitor from the orchestration activities view and see each completed activity. And if I click on the completed activity, you can see the different tasks that were completed in this workflow. And I can also generate a report for my internal documentation. This really gives a lot of good details here. If you are going in and analyzing snapshots for your clean room, this gives you a list of items that are performed. If it ran into any threat detections, it gives a lot of really good information that you can add to your internal documentation. Another new feature in Recovery Agent is the new Copilot integration, which can help incident responders through standardized workflows. Let's take a look at how we can use Copilot to create a recovery group and blueprint. I'll choose the workload that I want to create a recovery group for, and then confirm that I want to create a blueprint. I can also take a look at the new blueprint and add additional business logic. In this example, you can see that we have a recovery workflow. I can also look at the new blueprint and add additional business logic. For example, I may want to choose to run a threat scan before performing the recovery. And if I click on the recovery group, we can see objects from the end of the recovery group and the NBU workload that will be recovered. This completes the demonstration. We took a look at Cohesity Recovery Agent and how organizations can use it for incident response.

TL;DR

  • Recovery Agent automates incident response workflows through recovery groups and blueprints that act as digital jump bags, enabling organizations to orchestrate recovery from ransomware attacks and disasters without manual coordination
  • Blueprints function as automated runbooks with threat scanning, rehearsal capabilities, and dependency management, allowing teams to test recovery procedures before actual emergencies and ensure tools function properly
  • Clean room environments can be automatically provisioned with isolated workloads and forensic tools, enabling incident responders to investigate compromised systems safely while preventing further spread of attacks
  • New Copilot integration streamlines the creation of recovery groups and blueprints through guided workflows, reducing the complexity of configuring automated recovery procedures for critical workloads

Orchestrated Recovery for Cyber Incidents

This demonstration showcases Cohesity Recovery Agent, a feature within DataProtect designed to automate and orchestrate recovery workflows during ransomware attacks, data disasters, and catastrophic events. The presentation focuses on incident response scenarios where organizations need to isolate compromised systems in clean room environments while maintaining access to forensic tools. Recovery Agent introduces the concept of recovery groups that act as digital jump bags, providing incident responders with pre-configured, automated workflows that can be tested and rehearsed before actual emergencies occur. The solution addresses the challenge of coordinating recovery efforts without guesswork or miscommunication, particularly for critical workloads requiring rapid recovery time objectives.

Blueprints and Automated Workflows

The core functionality revolves around blueprints, which serve as automated runbooks for recovery operations. These blueprints enable organizations to define recovery options, dependencies, and automation rules that execute consistently across different scenarios. The demonstration highlights threat-aware workflows that perform automated threat scans and rehearsals on both digital jump bag components and application infrastructure before recovery. Blueprints can be configured to recover specific snapshot versions, allowing incident responders to analyze potentially infected backups in isolated environments. The system includes built-in reporting capabilities that document each step of the recovery process, providing audit trails for internal documentation and compliance requirements. A new Copilot integration further simplifies the creation of recovery groups and blueprints through guided workflows.

Chapters

0:00 - Introduction and Use Case
1:04 - Recovery Groups Overview
2:15 - Configuration and Blueprints
3:14 - Blueprint Workflow Demonstration
4:13 - Running and Monitoring Blueprints
5:20 - Copilot Integration

Key Quotes

0:15 "Our customers are telling us that they need the ability to orchestrate recovery from a wide variety of situations that include data disasters, catastrophic events and cyber attacks."
1:08 "As an incident responder, I can use recovery groups to accelerate incident response and disaster recovery during a ransomware attack. I can automate workflows without guesswork or miscommunication."
1:51 "And if you've ever worked with digital jump bags, you know that it's important not to wait for an actual emergency to use it for the first time."
2:32 "You can think of a blueprint as an automated workflow. It's designed to help bring your systems back online quickly and safely after a ransomware attack."
3:50 "This gives us a workflow that's threat aware and repeatable."
Categories:
  • » Webinar Library » Cohesity
  • » Data Protection » Backup & Recovery
  • » Data Protection
  • » Cybersecurity » Compliance & GRC
Channels:
News:
Events:
Tags:
  • Data Protection
  • Security Operations
  • Demo
  • Technical Deep Dive
  • Incident Response Automation
  • Ransomware Recovery
  • Clean Room Environments
  • Digital Jump Bags
  • Disaster Recovery Orchestration
  • Threat Scanning
  • Recovery Workflows
  • Backup Rehearsal
  • Cyber Resilience
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Incident Response Automation with Cohesity Recovery Agent

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    03

                    Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                    08/03/202611:00 AM ET
                    • Aug
                      06

                      Safeguarding Sensitive Data in the Era of AI Adoption

                      08/06/202604:00 AM ET
                      • Aug
                        06

                        Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                        08/06/202602:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/03/2026
                          11:00 AM
                          08/03/2026
                          Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Safeguarding Sensitive Data in the Era of AI Adoption
                          https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-ai-adoption/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version