Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Incident Response Automation with Cohesity Recovery Agent

Cohesity
03/12/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hello everyone, my name is Shelley Calhoun-Jones and I'm a Technical Marketing Director here at Cohesity. Our customers are telling us that they need the ability to orchestrate recovery from a wide variety of situations that include data disasters, catastrophic events and cyber attacks. In the context of this demo, I'm an incident responder and I'm currently dealing with an active security event. To address this situation, I plan to secure the system in an isolated space to investigate without the risk of further spread. Additionally, I need a safe and repeatable process to ensure that I can respond quickly. In this demo, we'll explore how organizations can utilize Recovery Agent to set up a digital jump bag and a clean room for incident response. But first, let's set the stage. As an incident responder, I can use recovery groups to accelerate incident response and disaster recovery during a ransomware attack. I can automate workflows without guesswork or miscommunication. It could be a critical workload which requires a quick recovery time objective, like with a CRM application. Or you may have a recovery group for your digital jump bag. Let's take a closer look at how this works. A recovery group can help me coordinate resources and tools to restore systems after a cyber attack or outage. This recovery group acts as my digital jump bag. And if you've ever worked with digital jump bags, you know that it's important not to wait for an actual emergency to use it for the first time. As an incident responder, I need to ensure that our tools are functioning properly. It's also vital that I prepare my team to handle incidents and identify any gaps in readiness. In the configuration section, you'll find options for a threat scan and a rehearsal, along with the ability to set up multiple configurations for testing. And you'll also notice that we have a blueprint. You can think of a blueprint as an automated workflow. It's designed to help bring your systems back online quickly and safely after a ransomware attack. When applied in clean room environments, it can automatically create a safe, isolated space that you can use for investigating and recovering data. And with the digital jump bag, the blueprint can launch ready-to-use virtual tools and configurations, ensuring that my responders have everything they need to conduct their Speaking of which, let's take a look at blueprints and how it helps in automated workflows. You can set up recovery options, dependencies, and automation rules to ensure that incident response happens consistently and efficiently. It's a virtual runbook that you can run once or periodically. In this workflow, you can see that we're performing a threat scan and rehearsal on our digital jump bag. We're also looking to determine if we need to recover a CRM application into our clean room environment. So we're performing a threat scan and rehearsal on different components that represent the application. This gives us a workflow that's threat aware and repeatable. At the end of the workflow, you'll notice that we have a five-minute pause and a teardown from an automation server. If I want to add additional steps, I can click on the ellipsis, choose add new task, and we can add those steps here. Let's take a look at how to run a blueprint. On this screen, you can choose a specific recovery point, which can be helpful if you need to test recovering a snapshot from a specific date range into the clean room environment. For example, we could be looking for an infected snapshot to analyze. For right now, I'll click on submit. I can also monitor from the orchestration activities view and see each completed activity. And if I click on the completed activity, you can see the different tasks that were completed in this workflow. And I can also generate a report for my internal documentation. This really gives a lot of good details here. If you are going in and analyzing snapshots for your clean room, this gives you a list of items that are performed. If it ran into any threat detections, it gives a lot of really good information that you can add to your internal documentation. Another new feature in Recovery Agent is the new Copilot integration, which can help incident responders through standardized workflows. Let's take a look at how we can use Copilot to create a recovery group and blueprint. I'll choose the workload that I want to create a recovery group for, and then confirm that I want to create a blueprint. I can also take a look at the new blueprint and add additional business logic. In this example, you can see that we have a recovery workflow. I can also look at the new blueprint and add additional business logic. For example, I may want to choose to run a threat scan before performing the recovery. And if I click on the recovery group, we can see objects from the end of the recovery group and the NBU workload that will be recovered. This completes the demonstration. We took a look at Cohesity Recovery Agent and how organizations can use it for incident response.

TL;DR

  • Recovery Agent automates incident response workflows through recovery groups and blueprints that act as digital jump bags, enabling organizations to orchestrate recovery from ransomware attacks and disasters without manual coordination
  • Blueprints function as automated runbooks with threat scanning, rehearsal capabilities, and dependency management, allowing teams to test recovery procedures before actual emergencies and ensure tools function properly
  • Clean room environments can be automatically provisioned with isolated workloads and forensic tools, enabling incident responders to investigate compromised systems safely while preventing further spread of attacks
  • New Copilot integration streamlines the creation of recovery groups and blueprints through guided workflows, reducing the complexity of configuring automated recovery procedures for critical workloads

Orchestrated Recovery for Cyber Incidents

This demonstration showcases Cohesity Recovery Agent, a feature within DataProtect designed to automate and orchestrate recovery workflows during ransomware attacks, data disasters, and catastrophic events. The presentation focuses on incident response scenarios where organizations need to isolate compromised systems in clean room environments while maintaining access to forensic tools. Recovery Agent introduces the concept of recovery groups that act as digital jump bags, providing incident responders with pre-configured, automated workflows that can be tested and rehearsed before actual emergencies occur. The solution addresses the challenge of coordinating recovery efforts without guesswork or miscommunication, particularly for critical workloads requiring rapid recovery time objectives.

Blueprints and Automated Workflows

The core functionality revolves around blueprints, which serve as automated runbooks for recovery operations. These blueprints enable organizations to define recovery options, dependencies, and automation rules that execute consistently across different scenarios. The demonstration highlights threat-aware workflows that perform automated threat scans and rehearsals on both digital jump bag components and application infrastructure before recovery. Blueprints can be configured to recover specific snapshot versions, allowing incident responders to analyze potentially infected backups in isolated environments. The system includes built-in reporting capabilities that document each step of the recovery process, providing audit trails for internal documentation and compliance requirements. A new Copilot integration further simplifies the creation of recovery groups and blueprints through guided workflows.

Chapters

0:00 - Introduction and Use Case
1:04 - Recovery Groups Overview
2:15 - Configuration and Blueprints
3:14 - Blueprint Workflow Demonstration
4:13 - Running and Monitoring Blueprints
5:20 - Copilot Integration

Key Quotes

0:15 "Our customers are telling us that they need the ability to orchestrate recovery from a wide variety of situations that include data disasters, catastrophic events and cyber attacks."
1:08 "As an incident responder, I can use recovery groups to accelerate incident response and disaster recovery during a ransomware attack. I can automate workflows without guesswork or miscommunication."
1:51 "And if you've ever worked with digital jump bags, you know that it's important not to wait for an actual emergency to use it for the first time."
2:32 "You can think of a blueprint as an automated workflow. It's designed to help bring your systems back online quickly and safely after a ransomware attack."
3:50 "This gives us a workflow that's threat aware and repeatable."
Categories:
  • » Webinar Library » Cohesity
  • » Data Protection » Backup & Recovery
  • » Data Protection
  • » Cybersecurity » Compliance & GRC
Channels:
News:
Events:
Tags:
  • Data Protection
  • Security Operations
  • Demo
  • Technical Deep Dive
  • Incident Response Automation
  • Ransomware Recovery
  • Clean Room Environments
  • Digital Jump Bags
  • Disaster Recovery Orchestration
  • Threat Scanning
  • Recovery Workflows
  • Backup Rehearsal
  • Cyber Resilience
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Incident Response Automation with Cohesity Recovery Agent

              Industry Events (Sponsor Hosted)

              • Sep
                17

                Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                09/17/202610:00 AM ET
                • Sep
                  17

                  Unveiling the AI-Driven Underworld of Automation's Rapid Rise

                  09/17/202601:00 PM ET
                  • Sep
                    23

                    Visibility Gaps: Shielding Your Data from the Unseen Threats

                    09/23/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/17/2026
                      10:00 AM
                      09/17/2026
                      Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                      https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                    • 09/17/2026
                      01:00 PM
                      09/17/2026
                      Unveiling the AI-Driven Underworld of Automation's Rapid Rise
                      https://www.truthinit.com/index.php/channel/2108/unveiling-the-ai-driven-underworld-of-automations-rapid-rise/
                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Visibility Gaps: Shielding Your Data from the Unseen Threats
                      https://www.truthinit.com/index.php/channel/2087/visibility-gaps-shielding-your-data-from-the-unseen-threats/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhancing Visibility and Control in Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhancing-visibility-and-control-in-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version