When new indicators of compromise are detected, Druva automatically rescans the last 30 days of backup snapshots to identify the ideal recovery point. Infected snapshots are quarantined by default to prevent accidental restoration, and teams receive urgent alerts with dashboards showing threat details and recommended actions.