Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Everpure: Cyber Resilience Evolution: From Backups to Recovery

Everpure
07/22/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Greetings, and welcome to The Pure Report. I'm your host, Rob Luedemann. It is time to bring the orange, and we did it, Chad. I got Chad Monteith in studio so we can talk about the EverPure, and I have to look down because we just changed the name. We did. EverPure Resilience Service, formerly PureProtect, formerly EverPure Protect, but we're going to be digging into cyber resilience in kind of an interesting angle. Hey, thanks for making the time. Glad to get you out here finally in studio. How long has it been now that you've been here? A couple years? A couple few, right? A little bit more. It's about eight years. Oh my gosh. Came over in 2018, if you can believe it. Store-reduced acquisition. A store-reduced acquisition. That's right. It precedes this. You kind of navigated through. Well, it was even a little bit of the genesis of a lot of what we're doing here with what's really started as something that we called modern data protection. We came in. We'd built with store-reduced. I've actually done a number of startups, had a lot of fun being a builder with them. The store-reduced one, we'd built this object storage virtualization layer. It added some features that object storage didn't have, deduplication, replication, things like that. We'd caught Kaz's eye early, and we came over to build what became Object Engine on top of FlashBlade, which was an exciting time. That really built the modern data protection story. As with all things that we've got in tech, there's not so much things that are truly like light bulb type of things. A lot of it's innovative. It's incremental type of technologies. Back in 2018, modern data protection was an application of the Flash technology that we'd built that we realized, hey, we can do something much more performant than what anybody else had done, especially on the restore side. We've seen probably 100X growth in that business since we started there. But over time, you increment on that, and now we've realized with EverPure Resilient Service that there's a lot more that we can be doing for our customers. Well, rounded it out, and really the story around cyber resilience, or let's say modern data protection, I referred to it before, was just the realization that there's a lot in the portfolio that we have, either that we built natively or that we have acquired, but creating this holistic view end-to-end of what our customers need, because it's not just about backups anymore. You flash back 10 years ago, and it was just sort of like, well, we do backups. We're fine, and maybe we have a little replication sprinkled here and there in case a meteor hits our data center. But there's so much more that goes into it, and so I love that we position it now as cyber resilience as a practice, that there are specialists that go out and help, and you're certainly a part of that related to the resilience service. Have you always been in the data protection space? Is that kind of where you kind of perceive? Not so much. It's kind of interesting to see how careers evolve over time. Started a lot in the file space, and then actually spent a lot of time in massive-scale object storage. It was kind of funny back in when Amazon first published the S3 spec, so we're looking at like 2000... Well, they published in 2008, but think like 2010 timeframe. I remember, actually, before I went to Cleversafe, we sold that to IBM, a small team and I were pushing object storage as the next innovation. This is when things like Hadoop were big, and everybody's like, I need to do massive-scale things with Hadoop. And I would go to them, I'd say, well, you know, S3 object storage is probably gonna give you better scale and performance. Now, back then, a lot of them were saying, no, I do it this way. But there were a few that were willing to be innovative and build something new. The ones that were a little bit farther ahead of their time. And the people that started that then went and built massive-scale systems that were exabyte-level solutions that we'd go in and then help them go build those and work together to build them. Because nothing 15 years ago was really ready for exabyte-level scale. Everything required some joint development work, some figuring out, hey, when you put massive load on massive systems, where do things break? And you'd go figure out where that stuff broke and you continue to innovate in that space to build them. And a lot of those then turned into things that we see today that are these massive scale-out systems that, you know, things like AI come around and everybody's like, well, I'm building this from the ground up anyways. Let's build it with new technologies. And they don't go back to these old distributed file systems. They go to the tools that are available today that have already solved those problems like object storage. So, you know, it's great to see where that has come. I mean, I, you know, 10, 12 years ago, I was trying to advocate and work with developers to get it here. So, you know, I feel a little bit, you know, proud that the industry has really sort of with these things like AI caught up, you know, to what we were saying 10 years ago. Sometimes it takes a while to be validated, right? It really does, especially in tech. We think we move fast, but I think in reality, it's not as fast as we think it is. No, it's not. We have to make it seem fast. You're also a Denver guy. So that's why I love having you on. I'm actually, I don't know, by the time I publish this, I will already have headed out, but I'm heading out to the family cabin that we have about an hour southwest of Denver to open it up for the summer. It is not winterized, so I have to head out there, but I'm going over Memorial Day weekend. It's always super fun because way up in the mountains, super relaxing. The cell phone signal kind of reaches there, but not really. And we don't have internet and there's not even TV. So as long as you can resist buying a Starlink, you'll be all right. Well, yeah, I think my parents did that and they're maybe going to bring it this summer, but I will be there before they go and do that. Now it would be helpful because then I could actually sit and do work. My son installed one of the minis in his Bronco, so he's got access everywhere. Oh, that sounds really safe. Where are you in town, in Denver? I think I know this. Yeah, well, I'm on the southeast side, so one of the popular bedroom communities of the Denver community. But I've been there, man, I've been there- 25 years. No, on the Parker side. Oh, on the Parker side. Okay, got it. Southwest is Highlands Ranch, Parker. My aunt and uncle live in, they actually moved Parker Ranch back when it was still dirt roads and gravel and everything, and it's all moved out to them, right? Out that way. Well, I mean, Parker Road, I have friends who lived out there when it was a two-lane dirt road, and they used to have fuel delivered to them in an above-ground tank because they were so far away from any gas station, and now there's a gas station on every corner. So that's grown a lot, that whole area, Highlands Ranch, Parker, Castle Rock, all around there. But yeah, Colorado's a beautiful area, especially those mountains. We get up there, whether it's the state parks, the national parks, all the time. In fact, I'm heading up this weekend, we'll get out to our favorite place if you haven't been out there, Glenwood Springs. Oh, no, I've been to Glenwood. I've been to, yeah. Yeah, first place in Colorado with power, by the way. Yeah. Our family used to drive from here, because we're from San Jose, from the Bay Area, and every summer we'd take two or three weeks to go to that same cabin that I'm going out to this weekend. And as a treat, my parents would, we would stop and stay at Glenwood Springs and go in the giant, you know, giant pools. The giant hot springs. Giant hot springs pools. A lot of fun. It's just amazing, super fun. It's a great area. Well, have fun with that. You started as a sysadmin, and certainly one of the commonalities with a lot of the specialists that I bring on to the program is that they are or were practitioners, right? Actually working hands-on and then kind of evolved into these tech specialist roles or decided, you know, I want to go help people as opposed to actually doing that. What did that, what did that role teach you about and what'd you learn and how has it benefited you today with what you do with folks? I mean, I think all of us, you know, especially in these, these builder type technologist roles started getting our, our hands on things, you know, when we were younger, you know, that's why we went into, you know, the precursor of STEM things, which is, you know, we wanted to go, you know, build things. We like to see how it works. We'd go build the first PCs, you know, back when nobody knew how to do that and, and understand how all the pieces fit together, you know, and any technologist, you know, really needs to have that understanding of how do things go together? How do things work? You know, it can't be just a black box, you know? So, you know, we started there and, and, uh, did some internships in college, which was a lot of fun. Um, I actually, when I go talk to, you know, like the, the high school career days and things like that, you know, they always want to know like, what are you doing and all this stuff. But, uh, I usually spend more time impressing upon the kids that regardless of what they do, they need to find a way to do an internship, you know, because when, when you see the, the career trajectory of the kids that did internships in college versus the ones that didn't, it's, it's vastly, it's vastly different. You know, the ones that get their hands on early, um, at least in my experience have invariably have greater success as they get out into the job market. So I always try to impress upon them to do that. I did that and actually ended up in a, in a couple of sysadmin roles with some big telcos and then, um, uh, actually they were all, you know, pretty much big telcos, but, uh, you know, uh, you know, a couple of things that you learn in there is, uh, one, I learned that I still liked building things, um, and that's how I ended up getting into, uh, you know, the vendor world, uh, is I worked with, uh, with one vendor, with a gentleman who was like, Hey, you need to come, uh, work with us on the, uh, systems engineering side, you know? And I ended up taking that path. Um, and actually the guy that hired me back in, in 2004, um, uh, kept in touch with him in the, in the Colorado area. And a few years ago we ended up hiring him here at Pure. So it's funny how we, uh, we all stick together and, uh, keep entering our orbits. It is about those connections and the relationships, right? And so probably one of the reasons that the, the kids that are doing the internships have that is that you just end up meeting a bunch of people and you never know when you'll, when you'll cross paths with someone. I mean, that's how I landed here at Pure was, was with somebody I went to school with and that our families know and I'm kind of the first job I ever got out of college in tech at a really crummy semiconductor company was, uh, was a girl I dated in high school, actually. Right? So it's that kind of thing is just keep an open mind. You never know, but, but manage and maintain those relationships. That network in the relationships is, is sometimes it takes a people a while to understand. Yeah. Like when I first got in the industry, I thought I'm going to be a great technologist and that's how I'm going to be successful. Um, and then you realize that, you know, that it is barely a part of the equation. Um, you know, when I, uh, one time when I was doing interviews, uh, one guy pulled me in for an interview and it was, it was, it was, it was probably, uh, the most interesting interview I'd ever done due to its brevity and the content. So he pulls me in, he goes, Chad, um, thanks for coming to the interview. I want you to know that I'm not going to hire you, but I wanted to talk to you. And I'm like, I don't know, I'm like 22 at the time or something like that. And I'm like, I have no idea where this is going to go. I'm like, uh, what's going to happen here? Um, and he goes, well, you remind me a lot about myself. And the one piece of advice I want to give you is that to be successful, to, to achieve better levels of success than you're on the path for now is you've got to understand how to marry the technology that you're great at with the business and the business needs that the problems that are trying to be solved by the business. Yeah. So we talked about that a little bit. And it's interesting because if you look at the 25 or 30 years since I had that conversation, you know, everything that we talk about in the industry is essentially like even in, in our tech organizations, our specialist organizations, it's exactly what he said. Yeah. It's how do you marry what is happening with the business? What's the problem the business is trying to solve with the technology that you know how to apply. And so, I mean, you know, he had a wisdom that, you know, very young Chad didn't really understand. And, and, you know, perhaps it's taken me a little bit of time to fully understand, but you know, that was you know, that was a really interesting piece of advice back then that I think is prescient and we want to, you know, make sure that we, you know, impress on you know, the early and career people to understand, but also impress upon ourselves as don't forget the foundations. Don't forget first principles of what we're doing here, which is solving business problems. And also that any interview is a good interview, right? I mean, that's, that's the other part, right? Is, is, you know, you get an interview, you take it, whether you think you have a good likelihood of getting the role or not, just because you get the experience and meet somebody and make a connection. Cause I do know people, I mean, there's, there's a woman who just joined here at Everpure who I interviewed back in 2019, right? And she didn't get the job then, but she found something else that was a fit and obviously wanted to work here, but still, you know, made that connection. And then she reached out and said, Hey, do you remember me? I'm like, Oh yeah, I interviewed for, you know, for this SAP, you know, product manager role and, and it didn't work out, but now you landed here, which is great. We knew each other already. And that works, you know, across things. I mean, it's not just, you know, people, it's not just relationships, it's not just, you know, jobs, but I mean, I even see that recently and, you know, in the product side, you know, we had one customer that, you know, looked at what we've been building, was like, I need a few other things, you know, let me go this other direction. And, you know, we said, cool, look, like, let's stay in touch. Nine months later, they're giving me a call and they're like, yeah, that other direction didn't work out, you know? So, you know, it's, it's important to keep, you know, the door open in those relationships open, you know, whether 15 years later, my, you know, I'm referring my old manager to, to take a job or, you know, people are saying, Hey, I don't want to hire you, but I want to give you good advice. Yeah, no, it's all good. Yeah, it's all good. Well, I want to take what you said about marrying the technology with the business problem and dive into the EverPure Resilient service. See how I did that segue? That's, that's why I'm the podcast host here. Right. Yes. I've done a few of these here and there. I wanna go back kind of the beginning, right? I want to go back. Cause this was brought in via an acquisition. And I remember when that happened, you know, a number, several years ago, I think, were there. I think that was about four years ago. Yeah, it was three or four, but we all kind of scratched our heads and went, you know, okay, I get it. It's protection, it's data protection. Where and how does this fit? But it was always also really interesting in that this was a service, right? And you go back three or four years ago and look, we've moved into data management and there's digital experience services and we've expanded the subscription portfolio. But what stood out about it as an interesting acquisition is this is something that was subscription-based, right? It was a software-based type of solution. But hit for folks the origin on that since we've got all different levels of understanding about what it is. You know, we've been looking at, you know, cyber resilience portfolio for a long time, you know, and you can solve that in a lot of ways. You can solve that in the traditional data protection or backup use space. You can solve that, you know, with array-based technologies. Now we've got cybersecurity, which is kind of focused on network edge and endpoint type of things. So this technology came in because we were looking at how do we move away from what our partners do so well, you know, and there's not really area for us to innovate in that space because they do it so well. And that's why we partner with them. We've got here as a target, but we partner with them and, you know, that's great business. But we wanted to get more into that sort of active operational resilience space. And we wanted to deliver it as a service, you know, because we, you know, by delivering something as a service, it kind of changes the whole engagement model with software from, you know, less of a traditional waterfall software development to an operation model that's more cloud-like. And we can kind of, you know, continue to innovate and deploy, you know, on demand, but it also gives us, you know, operational insight so we can be more responsive to customers. So we made a small acquisition of a company that had built a VMware to AWS disaster, like operational recovery, disaster recovery technology. And so we acquired that and we spent probably a year or so building the foundational pieces to put that into Pure One or ever Pure One now, I suppose is what we're calling that. And so that allowed us to turn it from more of a, you know, traditional software model and take some pieces that had already been built in Pure One, tie this intellectual property together and build what we call disaster recovery as a service. D-Raz, right? D-Raz. And so, you know, for those who've been following Pure for a while, you'll remember the D-Raz name that we had probably three years ago. And the focus on that was VMware to AWS. And that was a great starting point because, you know, anytime you're building something, going back to the whole need for iteration is you've got to start somewhere. And you've got to start with a problem that you can solve, but allows you to build the other pieces around it. So it wasn't just disaster recovery as a service, it was building the whole operational infrastructure that we needed to deliver more than just disaster recovery as a service, but where disaster recovery as a service was the first use case. So we took that acquisition, we took some pieces that we had built into Pure One and we put them together and we launched, you know, the first version, which was VMware to AWS. So that's still available today. We still have a good number of customers that are utilizing the cloud for what it's good for, which is, you know, on-demand elastic resources that you can use temporarily or ephemerally, and then, you know, tear them down when you're done. And so that was a great initial use case that we'd built into the product. And we just used that to, you know, to build off of. Yeah, that was the foundational element. It was the foundational piece, yeah. And it's worked well for us. Yeah, for sure. And I love the connection in there. And we got Suresh. And we got Suresh out of that. That's right, we used Suresh at Accelerate, and I'm using him coming up here at Accelerate, and he's a smart cookie. And back to your point about building, he was really the original builder that saw the light and architected this. So we had acquired him and his company as part of that. So he came with that. He leads the product effort with product management now. So, you know, pretty much everything that you've seen in the last four years is due to his, you know, his vision and his influence and his leadership with the team that we have. And we've got a good-sized team that we host out of our Prague development office that are all local out there, and they do everything from development to our DevOps. And I think that, you know, if we were to dig into that a little bit, I think that is a, you know, a nascent capability that, you know, may not be understood yet, like what the impact is. And so what I mean by that is, you know, now that we're delivering as a service, you know, we get real-time perspective and view into metadata operations. You know, we've been clear from a security perspective. We're not going to take customer data. We don't want any of your actual data, but in order to provide a service, you've got to have metadata. You've got to have some visibility in what's happening, telemetry and things like that. But now that we have that, we can see operations and behavior in real time, which means if things go awry, it's no longer the model of waiting for your operations team to see something's wrong, open a ticket. You get rid of that diagnosis and yeah. That all goes away. Get rid of those steps because you're already there. Because we're already there. Yeah. Because we already have visibility to what's happening. We can, in some cases, automatically remediate it. We can reach out. I even see in the future us being more tightly integrated with customers, you know, operation centers to be able to respond to things quickly. Yeah. And it may just be, you know, hey, here's something that you've done wrong. It may be a no op. It may be something we don't need to do. It may be something we need to fix. It may be something the customer needs to fix, but all of those have a shorter path to resolution, you know, as we build these things out. And I think, you know, a lot of, you know, as people move towards, you know, more as a service type of things, I think businesses are going to have to get familiar with how do we tie together, not just locked away operation centers, but how do we coordinate operation centers, you know, across vendors? And, you know, I think we're going to be one of the leaders in that space. Yeah. Well, and it came along at the right time too, right? Yeah. Because a little bit prior to that, we were just bringing out some of the subscription-based services, but it was really just around how can you subscribe and use SLAs to connect to what you need with the storage, and it's expanded. Now, it's expanded at the heart of our ability to look at the telemetry data and make those connections, but when this acquisition happened, and then some of the development that's happened with it, it's almost grown as the portfolio of offerings in the as-a-service portfolio that we bring out. It's not just storage as-a-service, even though we've talked about it that way for a while. It's really data management as-a-service, data security, cybersecurity as-a-service, and that's increasingly what people want. Well, I mean, we started with, you know, how do we give you a cloud-like infrastructure model on-premises? And now we're expanding to how do we improve upon that to let you recognize better outcomes? And by better outcomes, which, you know, I know is probably an overused term in the industry, is how do we make things more responsive? How do we reduce SLAs? In doing that, how do we make it simpler? How do we make it durable? How do we make it provable and demonstrable to our customers? You know, all of this used to be multiple hardware and software pieces that people would have to integrate themselves. I mean, in the market, I've seen us be able to replace a number, multiple third-party vendors with a single product, you know, and it really drives that simplification in that now you've got Pure's hardware, but we can give you some software on top of it, some as-a-service that's better together and lets you simplify your procurement, your operations, your software stacks, while we're providing that to you. And I think there's a lot of value in that. Yeah, there is. I think one of the other interesting shifts and why we're in and around, you know, you went from modern data protection to how we position cyber resilience now as a company is this shifting role of the chief information security officer. And this is what I pulled for our stat of the episode segment that I like to do, da-da-da-da, on these episodes. But I think this was a Gartner quote that you pointed me to. By 2028, half of CISOs are gonna be asked to own disaster recovery in addition to incident response and what that reflects, basically a broader organizational shift. Because I would say before security and the CISO role, which really didn't kind of exist, it was just sort of, you know, malware and spam and phishing and email and things, you know, the stuff that employees interact. Now it's far more than that, but you see the CISO role expanding to where they have a much broader remit, which now includes the things that are going on in central IT. No, it absolutely is. And, you know, we're even seeing, you know, it was interesting when I read that original report from Gartner is that, you know, we've been seeing that in our customers already. You've got, you know, the traditional, you know, IT infrastructure, which was like, hey, I'm gonna do business continuity and then I'm gonna do disaster recovery and, you know, then I'm gonna do backup and I'm gonna do recovery and you take those pieces. And over that time, as you said, the security piece has grown, which started as, hey, how do we protect people from, you know, phishing and ransomware and things like that, to, you know, a board-level strategic initiative. And it's become a board-level initiative because when your security fails, when you can't recover from it, you lose face in branding, you lose potentially revenue, you're not making revenue, maybe there's cost with it, maybe there's regulatory issues, you know, maybe there's fines. Some countries are even applying those fines to officers of companies. And so it's no longer just this nebulous thing that occurs and is an irritation. It can now, you know, be something that is so impacting to the business that it could be, you know, business ending, even in some cases. And, you know, even recently, you know, the last week you see, you know, you see events with like Instructure and things like that, that have become very, very public with attackers going after them. So, you know, this innovation is really saying that, hey, what we had in traditional IT and what we had with security is now this board level issue. And we need to treat it as something that has that level of visibility and has that level of investment and the need to correct it. Because, you know, the CISOs are now saying, it's not just that I need to be defensive, because, you know, you can be defensive, but an attacker is always gonna find a way in, whether it's a human mistake or whether they're just compromising code, or they're just faster and smarter. They used AI to get something in faster than you, you will have an event. But this specific observation, where they're taking over disaster recovery, what that means practically is that everybody's admitting to the fact that the recovery piece is now critical. They're admitting that they will be attacked, that there will be an event, and that if they can recover fast, now fast is somewhat subjective, but I would say within a couple hours, maybe within tens of minutes, think of it like Dora, you know? Recover in 20 minutes, turn it off to UAT, and then progress on and get it back within two hours. You know, that type of recoverability saves the board a lot of grief. Because now, well, you may lose an hour or two of revenue downtime, but maybe there's less perception of it. Maybe your brand isn't as impacted. Maybe you can replay those transactions. There's a whole lot of things that could occur in there that means it's not as impactful to your business. And we've even seen, in forensic analysis, with some customers that have been attacked, if they come in, they see that they've got pure technologies that provide indelibility, that provide the rapid recovery, that allow them to bring entire application stacks or data centers back fast, they'll turn around and leave. And why do they turn around and leave? Because it's so unlikely for them to get any payment out of it, that it's not worth their time. And so being able to defend against them by saying, hey, it's not gonna be worth your time is important as well. So all those areas really feed into the fact that there's gonna be this convergence of security and IT, especially at the board level, to be able to ensure that they've got the right position. And we're using that, even to drive some of the roadmap and the integrations that we're doing in our product going forward, realizing that it's not just a traditional IT buyer, IT person that's interested, but now it's the security people that are gonna say, you know what, I can do something unique here. And that uniqueness is, not only are you solving a problem that I've got, but the whole ecosystem that they've got is really interesting. I call it the Apple corollary, because I think I heard this as a quote from somebody at Apple. But I never was really able to find the origin from it. So we'll just, you know, somebody said something similar to it at one point, but it was that people like to buy things that work with other things they've bought. I think the quote came from somebody talking about the iPhone or something like that and I think the quote came from somebody. why those ecosystems work really well. But if you look at it from a traditional IT perspective, well, you want it to work with the storage and the hardware and the operation stacks that I've bought. But the innovation now that we're looking at is how do we make it work with the security pieces that people are buying? You know, if we can tie in with the CISO's investments and say, we're going to make it simpler and more responsive, build clean rooms or IREs or do disaster recover from ransomware or whatever it is, if we can automate that for you so that by the time your SOC sees an alert up on a dashboard, we've already built all that for you and they just need to say, oh, it was a false positive, nevermind. Or yes, something's actually occurring, let's promote that up into production. Your response time has gone from days, hours, weeks, months, whatever it is, to minutes. And that's what the board's looking to see from these events. And it follows the pattern that we've gone with, with augmenting parts of the portfolio. And I hit on this a little bit earlier, but I look at the partnerships that we've added in the last 12 to 18 months, including some of those cyber partners that we've featured here on the program as well, but also building this notion, right? I mean, one of the talk tracks that we go out and talk with folks about is that tiered resilience and it hits right into what you're talking about with. It's not only about detecting and understand that something happens, but what are those layers of response that you can bring into play such that when something does happen, to your point, the attacker says, oh, this isn't worth it, right? I'm not going to get anything out of this because there's too many things I have to deal with or go through, or you've shrunk that time to address, which is super, super critical. I love when people throw acronyms out. You very quickly threw out clean room and IRE, and I know those are things that are related to the solution that you specifically focus on. We've been talking broadly about cyber things, which I love and it relates to that quote, but I want to get into the rapid recovery SLA, but also the aspects around clean room and IRE and just explaining for folks what we actually do, what actually we do in that space. Marc Thiessen And all of these are things that we've built upon other investments that we've made. Like the original MDP that we talked about earlier came into existence because we realized that our DFMs, our direct flash modules, could be applied to the recovery problem and really solve the problem of, hey, it takes 10 days or 20 days to recover from some of these traditional appliances. Now we can do it in a couple of hours. Marc Thiessen You shrink it. Marc Thiessen There's real value there. As the markets start to see, well, okay, I can restore from backup faster now. What are other use cases? Oh, I've got snapshots, but it's a manual process that I have to undergo. Well, those were popular before we really saw the convergence of cybersecurity, traditional IT type of things. So as that market evolved, we started taking similar concepts and giving them personalities, different personalities. And so over 20 years, you would say, okay, I've got a DR environment. There's a huge investment in that. And then some people started saying, I've got test DR environments or bubble environments, things where I could test. Then you started seeing those being built in the cloud. And those have continued to get additional personalities like we see here, like isolated recovery environments, IREs, or clean rooms, and other variations upon very similar concepts. And that's why we can use similar technologies to affect all of these outcomes is because there's just personality adjustments that you can define in those. Customers can come and say, if we have one of our security vendors detect a in-memory event on a virtual machine, they can pass us metadata. We can take a forensic snapshot. We can go build a clean room, which is essentially isolated, meaning- You set it aside. We've built your environment, but there's no network connectivity. Maybe there's other limitations. Maybe you can only get into it from a console perspective, or maybe there's a limited jump station, but that allows you to go investigate that. Maybe it's a forensics investigation. Maybe you want to just promote production, things like that, too. And those tend to be very pointed, whereas isolated recovery environments tend to have larger sets of the environment, but usually a subset. Whereas disaster recovery is usually, hey, let's figure out how we restore an entire data center. Again, those are all variations in personality on very similar constructs that we're able to build off of, because if you can recover 10,000 virtual machines in a DR event, you're going to be able to quickly and easily do five for a clean room or 100 for an IRE type of thing. We see these terms coming up, and they're really just personality variations that are configuration differences that we can automate and allow you to fine tune it. We see these terms even with some of our software vendors. I mean, Epic's a huge one that we work with, and they're stating that for customers to maintain honor roll certification, they ultimately need to have an IRE. So those are things that we can go facilitate and automate so that customers can maintain their best-in-class positioning with other vendors in these ecosystems. Yeah, I love that. I want to get into a little bit on the Resilient Service, right, on EverPure Protect now. I have to keep doing the- EverPure Resilient Service, yes, sir. Resilient Service, lowercase s, as Suresh keeps reminding me with the catalog at Accelerate, which is good. What stands out, and I always do things anecdotally, and I even told you this story, I think, from Accelerate last year when I bumped into you. I was on the elevator coming down from my room back to the floor at our Accelerate conference and just standing next to a guy, and he kind of said, hi, and I noticed he had a badge and went, oh, you work at, you know, whatever. He was an attendee. He was a customer. And because I manage breakouts and experiences and what people sit in for sessions and learn, I was curious. I guess it was a long hotel ride. We must have been at one of the top floors. And I said, so what's been interesting to you at this event, right? Have you gone to breakouts? Yes. Have you gone to the mini-theater sessions? Yes. Did you go to the main stage? Yeah. You know, he had done everything, which is great. We want somebody to have a rich attendee experience, and I said, what's most interesting? What has stood out to you the most and the first thing out of his mouth at that time with that brand? He said, yeah, the Pure Protect, the Pure Protect. I love it. This is something that I think our company can use right now because of the way that we operate. And I think since that time, you and I have talked because you come to town frequently, and the momentum has picked up, right? And you're seeing this now in a number of industries, to your point that you just mentioned, okay, there's a different flavor maybe of how it's getting used, but you're seeing great momentum around uptake of this service. How is that? Yeah, absolutely. I mean, we started with the AWS piece, but that gave people the flexibility. But where it really took off was when we integrated directly with our FlashArray products. And so at Accelerate last year, we had actually announced a lot of those pieces, integration with the FlashArray, some concepts that we're calling recovery zones, and those are really what made it usable and real for a lot of these customers. Because the big value on FlashArray is all of our competitors, primary competitors in the market, and even people that don't even do anything close to what we're doing, they like to operate at the VMware level, at the Broadcom VMware level. But there's changes in that space. I mean, Broadcom's making changes. They're changing how APIs are supported and interacted with. Those models come with requirements, load on servers, compute resources you need to do, operational overhead. And so when we did our FlashArray integration, we upended all of that and we said, we're just going to manage it. We're going to let the FlashArray do what the FlashArray does best, which is it's going to replicate, it's going to clone, it's going to provide storage to the infrastructure, and we do it all over API calls. And that really was the catalyst for our largest accounts. And a lot of our growth was the integration with the FlashArray and building on top of that. And then so many pieces that come after that with the ecosystems integrations and stuff like that. We're continuing to innovate and how do we make it more flexible too? Because ultimately a lot of customers, you know, traditionally in not even cyber-resilience, but when people thought of it as disaster recovery, it was very fixed, failover, failback, very binary. You know, even data protection, I'm going to back it up and maybe I can restore it fast. But you have to ask yourself at some point, like, how do people want to utilize this in new ways? You know, and we started seeing some of the precursors to that where people would, you know, clone Oracle databases and be able to refresh development environments. Well, a lot of those concepts are just being repurposed into things like the personalities that we're talking about. Yeah. You know, so as we build upon the FlashArray work and the AWS work, we look at things like recovery zones where instead of thinking of it in a very binary fashion, it's a very flexible fashion. It gives you as Rob Lee, our CTO, likes to use the term optionality. Yeah. Gives you optionality in what you do with the data. You can send it anywhere. You can recover it into any one of these personalities. You can then subsequently send it somewhere else. You can decide to promote it. You can decide to clean it up. You can do all of these things concurrently, you know, concurrently across the board. So that level of flexibility is going to be the next jump in usability because now operations teams instead of having to build and manage scripts or use, as I mentioned earlier, three or four different tools to achieve something, it's simply a runbook definition within PureOne. Yeah. And single subscription-based, right? I mean, so you've got the subscription-based, but the other key point and caveat is you're doing all these things outside of disruption to prod as well, right? And I did a database podcast yesterday with someone and we got into the whole prod, non-prod, whatever thing, and you're describing these scenarios of cloning an Oracle database and putting it in this environment to do things and you're not messing with production, right? You're just keeping it separate, but providing that flexibility and that simplicity to go and do all those things. And it's interesting. I love when we as technologists build and offer things, customers always go out and find other things to do with them that we didn't think about. That we didn't think about. It always happens. Yeah. And it does. Well, and even go back to the CISO board thing. Yeah. What does the board need from a CISO and an IT tech leader is what they're saying has to be demonstrably provable. And so that's where these test environments come into play is, okay, great. You've said you can do all this. We've invested in all of this. Where's the evidence? Like, can you prove and show me that when an event occurs that we're okay? And that's where a lot of these personalities come into play. And as you mentioned, these test environments is, you know, you need to be able to periodically be testing. Because invariably with just the natural churn of IT, somebody is going to deploy something and it's not going to follow some policy or process, you know, probably not on purpose, just somebody missed something. And it's going to, you know, sometimes the only way you can find that to mediate it is in a test failover. And if you're doing that regularly, then you know, what do I need to fix? How long is it going to take? What does the runbook look like? Because the last thing that you want is to have everybody stressed out because there's a ransomware event occurring and you're trying to recover and everybody's trying to figure out how to build and fix problems while an event's occurring. You want it to be as hands-off as possible. Push the big red button and bring it online and have as little work as possible that somebody who's stressed out in the middle of the night needs to think about because that's where more mistakes occur. And that's why we want people to continue to test and evaluate that because if everybody's comfortable with the process so that it's ingrained in them, that it's almost second nature, then the success is tremendously improved. But I think you had to make the test and evaluation easy in the first place. I used this joke on the database podcast yesterday, and I'll use it again here. One of the ways you used to have to punish DBAs is make them test backups because testing backups was painful and time-consuming and nobody wanted to do it or test replication as well. And so now there's this technology that comes where you, and I love it, you keep talking about constantly testing, constantly, but it's because you have these environments, you have these clean rooms, you have these IREs where you can go do this and it's not disrupting production. And that's huge, right? Absolutely. So you're making it easier. You're facilitating the ability for people to test or look at anomalies, or we might have seen something, we can go check it out without it being some big type of event. And maybe it's nothing, but it's better than the alternative. Yeah. Makes it easy to build. It makes it even easier to clean up. And to the database example, you don't have to spend hours watching a progress meter. Yeah. That's right. Yeah. Go do something more interesting. Which, I mean, who knows? Maybe there's some people that liked getting coffee during the progress meter. I was just about to say the coffee thing, right? That is a chance to go do some coffee. Well, kind of bring it home Well, kind of bring it home. on the whole EverPure Resilience service. You know, somebody out there is listening. They're like the customer I had in the elevator who goes, oh, I got to check that out. Like, hit the main points, like the use case. If somebody is struggling with X, why would they want to use this? Yeah. Well, so, you know, what we've built here with this is really this great tool set, you know, that gives a lot of options. So if somebody wants to get familiar with it, you know, hopefully it's somebody that is wanting to continue to experiment and build, you know, because, you know, we're a technology that's going to, you know, change the way you approach things a little bit. But in the end, you know, it'll be a lot simpler. So to get involved with it, you know, we've got a bunch of resources that are public. If you're a Pure One user, we've got documentation on the Pure One support portal. If you, you know, whether or not you are, we're starting to publish a lot of information on the Pure community. Thank you for that. I appreciate it. Absolutely. I'm going to be talking even more about it at Accelerate as well. Yep. We got your session. Some live deployments, some live using of the community. So, you know, we're publishing a lot of stuff up there as well, and we're continuing to add things incrementally. So that's a great, you know, resource to get familiar with. What are the steps that you need? You know, some of who's using it, how to use it and things like that. And then last one is to utilize our community edition. Yeah. You know, so we've created an easy to deploy. It's actually as easy as the production was. There's really, to be honest, there's really no difference other than we do a capacity limit. Five terabytes. It's the same. Fully featured. It's not like you created a different code set. It's not even a different version. Yeah. It's all the same pieces. But we see a lot utilizing that because, you know, you can spend a little bit more time looking at it. You can test it, you know, with your environment, your applications. It lets you do tests and production failovers or, you know, whatever it is that you're looking to achieve. And then when you're ready to buy, you just transact and the license converts and you don't have to redeploy anything. So, you know, those combinations, you know, the documentation, the pure community, our community portal, the community edition are great ways to get your hands on this and get familiar with it, you know, because you can do everything that you would do with 10,000 VMs. You can do with the five or the 10 VMs that we give you the ability to do with now. And we've seen, you know, tremendous uptick. I would say there's probably, I mean, I could hazard a guess on a percentage, but I would say the vast majority, you know, of our users are taking a path through the community edition and the pure community portal. And that's how people like to try it, you know. There's nothing worse than getting on your phone and seeing a game or something that looks interesting, but it has a price on it. And that's kind of gone away. Maybe I'm dating myself since everything is now in-app purchases, but there's nothing worse than going, oh, I'm going to buy something for 299. And then I'm trying it and I don't like it. I just wasted that money. As opposed to, okay, let me check it out. Let me check the tires. Oh, this is super useful. Oh, I didn't know it could also do this for me. All right, now I've hit that capacity limit. Okay, cool. It's just, it converts to subscription. So you don't even have to go through a lot of complicated, you know, paperwork and POs and crazy things like that because it is an as-a-service offering. Well, and it even lets the evaluators and the people who are going to operate it, you know, it gives them provable, demonstrable information so that when they go to justify something with their board, they can say, you know what, we've already put it through its paces. We've tested it. It's not just us trusting Pure. And there's a lot of people that trust Pure. Sure. And that's great. But in this case, they can actually stand up and say, we did all of these workflows. It's better than the alternatives. It's better than what we were doing in these five different ways or whatever it is. And it puts them in a much better position when they go stand in front of the board or the buyers. To justify their decision. And if we can help enable them to achieve that easier and with more data, then that's great. And that's what this is here for. Well, they can show it. It's not a leap of faith, right? It's not a leap of faith of, is this, you know, have you used it? I mean, it's like, yeah, we've used it and here's what it did. And now we're just need to go in and invest more. And it's interesting because we see, you know, the customers that do that, you know, traditionally in IT, people are like, I want to do a three-year investment and that's it. And then we'll go evaluate things. And, you know, that's a decent balance of, you know, costs versus risk and things like that. Because, you know, a lot can happen in three years. A lot of nothing can happen in three years, but a lot could potentially happen in three years. You know, but with these models, we see people, you know, making longer term investments and impure. Now, granted they've, you know, typically been pure customers as well. But, you know, when you see this and you see it hands-on, you're more willing to say, you know, let's give me a better subscription rate and invest for five years. But it's back to, and I found your quote, right? You know, people are already using pure. People buy things that work with other things they bought, right? So I'm not surprised that this is additive to existing customers always have, because they just go, oh, this is something that has the brand behind it and the investment and the technology. And the same hallmarks that we achieve with customer first and simplicity and being super intuitive and all that. I love that. And we got a bunch of sessions on this at Accelerate. So I'm super excited. Chad will be delivering one of our mini theater sessions, going into the community edition and doing some demos. And then we've got you and Suresh doing two different breakouts. They pulled a fast one on me, because DX submitted a session and then another one came through cyber. And you know what? Multiple opportunities to hear the same similar stories. I am more than happy to get up and keep advocating for what we've built here. You know, I'm, you know, excited. I'm proud of what the team's built. You know, they've built a great product and it's following a great plan. And I think it's a great team. And we're starting to see people get a lot of value out of it. I know, and I'm happy it's part of the portfolio. It's just part of the story now, not this kind of weird one-off, you know, what did we acquire kind of thing. Like it's evolved. People looked at me a little sideways at the beginning when I said what we were doing. And I'm like, just, we've got a vision. Let us, give us some time to go execute on it and it'll become clear. And we're there. And it's awesome. All right, I'm gonna put you through hot takes here. Oh, excellent. Real quick, yes. And we'll make this one maybe cyber oriented, right? So question one is always, you looking at all the people you talk to, you talk to a lot of IT folks. What's something that you think they're missing today or not paying enough attention to in the cyber resilience space? Well, you know, where I think a lot of what the, you know, the business leaders need to be looking at is, how do we become more demonstrably defensive, you know, for these attackers is, you know, we see a lot of situations where the attackers are able to come in, you know, they're able to spread around. And the outcome that they're looking for is, how do we not pay the ransom? And so, you know, if you go to RSA, there's a thousand vendors on the floor there. And to the point of buy things that work together, most of them aren't working together. And they're not working with storage. And they're not working with your data protection software. So there's really kind of these three pillars now of where there's data protection software that is great. And they're adding cybersecurity, cyber resilience pieces to it. But it's, you know, but that's always after the fact. That's, you know, I've got to take another backup and I've got data and I can go tell you, give you some insight about what happened and maybe where it started. Then you've got stuff on the storage side, where people are, you know, adding capabilities on the storage arrays, you know, and you see this in the tier one storage market, but that's making the assumption that things are hitting storage. And that's an assumption that I don't think applies anymore. You know, because now we're seeing attacks occurring in memory. There are attacks within 30 minutes. There are attacks at the network edges where they're detecting them. So where we need to innovate, you know, that shift is instead of thinking of it way after the fact, we're thinking of it within storage. It's to the ecosystem players, how do we get these pieces to talk together so that when something I've invested in upstream, you know, like a network or an endpoint detection system, how do those pieces drive real-time action in my cyber resilience, my cyber recovery strategy? And I think that's where a lot of people need to start to invest and think about is how do we become more responsive in real time? Because, you know, attackers are hitting and spreading out within what, 30 minutes now? I think we're seeing that they're able to spread across. Most of them are doing in memory. Disks aren't seeing it. Backups aren't seeing it. Your endpoint detection is sometimes seeing it. Your network is sometimes seeing it. So we need to get better at tying all those pieces together. And that's a lot of the investment that we've been making. We'll show a lot more of it at Accelerate. But, you know, I really think that that's where, you know, we need to take those thousand vendors at RSA and be able to communicate better with them so that real-time action can be taken. And if that real-time action is simply, hey, we see, you know, a ransom event in memory on a database server, go take a forensic snapshot, go build a clean room, continue on. So I think that's where a lot of this, you know, needs to start getting some focus. And that's where boards are gonna see real outcome. You know, real perceptible, tangible benefit. Yeah. And maybe where the CISOs are having more of a role to see across the organization, like the surface area has definitely expanded and it's not just about your backups or just basic security stuff. Gartner made their quote. Is, you know, the CISOs were the left and IT were the two right. Yeah. And in the future, you can't have those isolated pillars. Yeah. They all have to work together. And, you know, they're just really saying that the more adaptable, the more nimble, the more mature organizations are gonna be at the forefront of integrating those functions together. Yeah. Well, and cyber is everybody's job in the company anyway, right? Not just those orgs. That's what our compliance teams tell us. Yeah, I know, I know. Well, yeah, that's the simulated phishing emails that we get, right? Those are always fun. Your CIS ad, so you must've had some kind of oops moment where you blew something up or made a blunder. You're talking about, you know, change control and blast radius here in the notes, right? You know, definitely. You know, it was kind of funny back in my CIS admin days, you know, I was implementing a new technology, which actually is still around today. But back then it was pretty nascent. And I remember directly working with the CTO and having some entertaining conversations with him. But we rolled it out and actually it's used across the globe now that, you know, 25 years later, that technology, we actually use it at Pure. I won't mention what it was, but, you know, so I was working as a CIS admin. We're like, hey, we're gonna roll it all out. So we do all the change control. We notify everybody. We spend weeks or months saying this change is gonna occur and it's supposed to be completely transparent. And then we roll it out and everybody's happy. But then about, I don't know, maybe a week later, you know, we've got a, you know, a production system that suddenly goes offline. And they get it, you know, they figured out, we get it back. I don't think it was terribly visible outside of, you know, the organization and the company. But, you know, what that teaches is that even when you follow all the process, all the protocol's done, all the change control's done, everybody signs off, you know, there will still be systems in a mature organization built over years or decades that somebody just isn't paying attention to anymore and doesn't realize that there's a configuration that's at risk to a change. And so, you know, as you get it, you know, what that really, you know, Todd is, you know, one, you know, the best laid plans, you know, sometimes don't always work out. But in today's verbiage, in today's parlance, it really needs to be about managing the blast radius. Whether it's cybersecurity, you know, whether it's change control, whether it's rolling new upgrades, you know, you have to be, you have to control, like, what is the potential impact? Because there's always going to be something that is not considered or unpredictable. I mean, you know, that's just IT today. There's a lot of inputs, you can't account for everything. So, you know, the control in there is, you know, really let's make sure that, you know, the potential zone of impact across a wide range of IT problems is correctly managed. Good advice that you had to learn the hard way, right? Yeah, yeah. It was funny coming in and they're like, this happened, and I was like, oh, well, splendid. Yes, yes, have some fun. But not the worst story we've had on here, which is good. No, probably not the worst story. Definitely one that's educational. Hey, well, we'll wrap here coming up. I loved hearing everything. And again, plug, it'd be great to see you and Suresh at Accelerate and for folks to go check out the Community Edition. They can access that through Pure One, yes? Is that where you were? Yeah, and we're actually putting a lot of great tools into Pure One. So, you know, you log in, you do have to have a Pure One account. You know, so, you know, if you don't have one, you know, reach out to Pure. Reach out to your sales team. Yeah, talk to an SE. An SE can get you lined up. We'll get you lined up in there. But you really just go to the Pure One catalog. There's a Pure Protect tab, says Community Edition, and you just go request it in there. It's super easy. You pretty much just click a couple buttons and you get the request in. And then as you're getting ready, you know, we've added a lot of things into the assessment tools in there that help you understand what's the potential sizing gonna look like. There's qualification for AWS, like will my VM run in AWS native? Or, you know, how much network bandwidth do I need between sites and things like that? So there's a lot of great tools that help you kind of understand your environment in there. in there and then you request the community edition and we get that And then you request the Community Edition. processed and then we'll we'll send you some supporting documentation and get you going yeah and they've got you to call upon if help is needed absolutely hopefully over time more than just me but yes I know well and the other cyber FSAs can absolutely there's an army of people ready to help you which is really great awesome hey great thanks for coming on I appreciate it thank you super fun we finally did it I know it's been right every time you come to every time you come to campus I'm like I didn't know ahead of time and you come here quite frequently I need to warn you things no that's fine let's let's do your accelerate things and then maybe do a little check-in in the second half of the year just to see how things have evolved because I know there's some exciting things going on in the second half as well yeah we've got two we've got exciting plans for ever pure resilience I love it I'm looking for I love it that is fantastic thank you Chad so much for coming on and thanks everybody for listening to this episode a quick note not that she watches but a quick congratulations to my sister my parents watch so they'll like seeing this a quick congratulations to my sister who earlier this week I went down to her retirement celebration 26 year junior high school teacher congratulations now retiring so I wanted to mention that had a really nice celebration she did it her way she did it at a brewery in Anaheim and had all of her teacher friends out there and it was it was super fun it was a blast so congrats to her in retirement and now finding a way to spend a lot more time in the day someday you and I will be there as well so one day one day one day you know our retirement plans might not be as nice as 26 years but yes we'll see we'll have to see but but congratulations her in 26 years impact is impressive yeah regardless of you know what you think you know helping kids for that long is just great teachers are teachers are special people absolutely I still remember most all my teachers names yeah even in school I know and these will remember her as well they're their kids so congrats that thanks Chad again for coming on thank you for checking out this episode of the pure report podcast as always tell a friend share with a colleague go on go ahead and do that and we will keep the great guests like Chad coming on to the program with with that we will wrap forever pure and Chad Monteith this is Rob Lieberman saying don't look back something might be gaining on you you

TL;DR

  • Everpure's cyber resilience strategy has evolved from basic backup and replication into a fully integrated service covering clean rooms, Isolated Recovery Environments, and automated disaster recovery — all built on the same underlying flash storage constructs.
  • Chad Monteith explains that clean rooms, IREs, and DR are 'personality variations' of the same technology, meaning customers who can recover an entire data center can just as easily spin up a five-VM forensic environment in minutes.
  • The CISO's role is expanding to encompass disaster recovery, creating a convergence of security and IT at the board level — a trend Everpure is actively building into its product roadmap and go-to-market integrations.
  • Attackers conducting forensic reconnaissance have reportedly abandoned ransomware attempts upon discovering Pure Storage technologies, because rapid recovery and data indelibility make successful extortion economically unviable.
  • The Everpure Resilience Service Community Edition is accessible through Pure One, with built-in assessment tools for sizing, AWS workload qualification, and network bandwidth planning — lowering the barrier to entry for organizations evaluating the platform.
  • Chad's 'Apple Corollary' frames the strategic value of ecosystem integration: customers want recovery and security tools that work seamlessly with existing storage and infrastructure investments, not point solutions that require separate operational workflows.

From Modern Data Protection to Cyber Resilience

This episode of The Pure Report features Chad Monteith, Principal Field Solutions Architect at Pure Storage/Everpure, who joined the company through the StorReduce acquisition in 2018. Chad traces the arc from early modern data protection — built on FlashBlade's Object Engine — to today's comprehensive Everpure Resilience Service. He explains how the industry has fundamentally shifted away from reactive, backup-centric thinking toward proactive, operationally integrated cyber resilience. Where organizations once treated backups as a checkbox exercise and replication as a meteor-strike contingency, they now recognize that data availability is a board-level imperative. Chad notes that the business has seen roughly 100x growth since the early modern data protection days, reflecting how dramatically customer expectations and threat landscapes have changed. The conversation grounds this evolution in Chad's own career trajectory — from sysadmin and startup builder to field solutions architect — giving the discussion a practitioner's credibility that goes beyond vendor positioning.

Clean Rooms, IREs, and Automated Recovery Architectures

A significant portion of the conversation dives into the technical architecture of Everpure's recovery capabilities, specifically the distinction between clean rooms, Isolated Recovery Environments (IREs), and traditional disaster recovery. Chad frames these not as fundamentally different technologies but as 'personality variations' on the same underlying constructs — configuration differences that can be automated and fine-tuned. A clean room is a fully isolated, network-disconnected environment used for forensic investigation or targeted recovery of a small number of workloads. An IRE covers a larger subset of the environment for broader incident response. Full DR addresses entire data center restoration. Critically, Chad explains that if a customer can recover 10,000 virtual machines in a DR event, recovering five for a clean room or 100 for an IRE becomes straightforward. He also highlights that healthcare software vendor Epic now requires customers to maintain an IRE as part of its honor roll certification — a concrete third-party mandate driving adoption. The integration with security vendors enables automated forensic snapshots triggered by in-memory threat detection events, collapsing response time from days or weeks to minutes.

The CISO's Expanding Remit and the Apple Corollary

Chad introduces what he calls the 'Apple Corollary' — the observation that people prefer to buy things that work with other things they have already bought — as a framework for understanding why Pure Storage's integrated ecosystem resonates with both IT and security buyers. As CISOs increasingly take ownership of disaster recovery alongside traditional incident response, the convergence of security and IT at the board level is reshaping purchasing decisions. Chad argues that rapid, demonstrable recovery — on the order of minutes rather than hours or days — materially reduces business impact: less revenue downtime, reduced brand damage, and the ability to replay transactions. He also raises a striking forensic observation: attackers who encounter Pure technologies providing indelibility and rapid recovery have been known to abandon their efforts because the likelihood of extracting a ransom payment becomes too low to justify the attempt. This positions resilience not just as a recovery tool but as an active deterrent. The episode closes with a discussion of blast radius management as a universal principle applicable to cybersecurity, change control, and infrastructure upgrades alike.

Everpure Resilience Service and Community Edition Access

Chad provides practical guidance on accessing the Everpure Resilience Service Community Edition through Pure One, Pure Storage's management and catalog platform. Users with a Pure One account can navigate to the Pure Protect tab, request the Community Edition with a few clicks, and gain access to assessment tools that help size environments, qualify workloads for AWS native execution, and estimate inter-site network bandwidth requirements. For organizations without an existing Pure One account, the recommended path is to engage a sales engineer directly. Chad signals that significant product investment is planned for the second half of the year, with additional capabilities being built into Pure One and the broader Everpure Resilience portfolio. The episode reinforces that the as-a-service model is not simply about subscription pricing — it is about leveraging real-time telemetry to reduce resolution times, simplify operational complexity, and ensure that recovery is continuously tested and provably ready rather than a theoretical capability that only gets validated during an actual incident.

Chapters

0:00 - Intro and Cyber Landscape
1:03 - StorReduce Acquisition and MDP Origins
5:15 - Denver Conversation
8:05 - Career Journey: Sysadmin to Field Architect
14:45 - Origin of Everpure Resilience Service
23:45 - CISOs Taking Over Disaster Recovery
27:00 - Rapid Recovery as Ransomware Deterrent
29:10 - Apple Corollary and Ecosystem Integration
31:18 - Clean Rooms, IREs, and DR Explained
36:18 - Everpure Resilience Service Deep Dive
50:19 - Hot Takes: Blast Radius and Change Control
57:26 - Community Edition Access and Wrap-Up

Key Quotes

1:56 "Back in 2018, modern data protection was an application of the Flash technology that we'd built that we realized, hey, we can do something much more performant than what anybody else had done, especially on the restore side."
2:07 "We've seen probably 100X growth in that business since we started there."
27:13 "They're admitting that they will be attacked, that there will be an event, and that if they can recover fast — now fast is somewhat subjective, but I would say within a couple hours, maybe within tens of minutes — that type of recoverability saves the board a lot of grief."
28:03 "If they come in, they see that they've got pure technologies that provide indelibility, that provide the rapid recovery, that allow them to bring entire application stacks or data centers back fast, they'll turn around and leave. And why do they turn around and leave? Because it's so unlikely for them to get any payment out of it, that it's not worth their time."
29:10 "I call it the Apple corollary — people like to buy things that work with other things they've bought."
30:21 "Your response time has gone from days, hours, weeks, months, whatever it is, to minutes. And that's what the board's looking to see from these events."
34:31 "If you can recover 10,000 virtual machines in a DR event, you're going to be able to quickly and easily do five for a clean room or 100 for an IRE type of thing."
56:27 "In today's parlance, it really needs to be about managing the blast radius. Whether it's cybersecurity, whether it's change control, whether it's rolling new upgrades — you have to control what is the potential impact, because there's always going to be something that is not considered or unpredictable."

FAQ

What is the difference between a clean room, an Isolated Recovery Environment (IRE), and traditional disaster recovery in Everpure's framework?

According to Chad Monteith, these are 'personality variations' on the same underlying technology rather than fundamentally different systems. A clean room is a small, fully network-isolated environment — typically covering a handful of VMs — used for forensic investigation or targeted recovery with no external connectivity. An IRE covers a larger subset of the environment, typically used for broader incident response and validation. Full disaster recovery addresses entire data center restoration. Because the same flash-based constructs underpin all three, an organization capable of recovering 10,000 VMs in a DR event can just as easily provision five VMs for a clean room or 100 for an IRE, with the differences being configuration and automation parameters.

How does the Everpure Resilience Service Community Edition work and how can organizations access it?

The Community Edition is accessible through Pure One, Pure Storage's management platform. Users navigate to the Pure Protect tab within the Pure One catalog and submit a request with a few clicks. The platform includes assessment tools that help organizations understand sizing requirements, determine whether their VMs qualify for AWS native execution, and estimate inter-site network bandwidth needs. Organizations without an existing Pure One account should contact their Pure Storage sales team or a solutions engineer to get set up. Once the request is processed, Everpure provides supporting documentation and onboarding resources.

Why are CISOs increasingly taking ownership of disaster recovery, and what does that mean for how organizations should evaluate recovery platforms?

Chad explains that CISOs taking over DR reflects a broader organizational acknowledgment that attacks are inevitable and that recovery speed is now a board-level metric. When recovery can be demonstrated in minutes rather than days, the business impact of an incident — revenue downtime, brand damage, transaction loss — is materially reduced. This convergence means security leaders are now evaluating storage and recovery platforms not just on backup performance but on SOC integration, automated clean room and IRE provisioning, and the ability to present provable, tested recovery SLAs to the board. Everpure is actively building these security integrations into its roadmap to serve both the traditional IT buyer and the emerging CISO buyer.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Backup & Recovery
  • Security Operations
  • Zero Trust
  • Technical Deep Dive
  • Webinar
  • Cyber resilience
  • Isolated Recovery Environments
  • Ransomware recovery
  • Flash storage
  • CISO and IT convergence
  • Disaster recovery automation
  • Clean room environments
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Everpure: Cyber Resilience Evolution: From Backups to Recovery

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    19

                    Becoming Agent Ready: Insights from Cyera's Expertise

                    08/19/202612:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 07/28/2026
                      01:00 PM
                      07/28/2026
                      Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                      https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                    • 07/29/2026
                      04:00 AM
                      07/29/2026
                      Real-Time Strategies for Safeguarding Against Prompt Injections
                      https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                    • 07/29/2026
                      01:00 PM
                      07/29/2026
                      Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                      https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready: Insights from Cyera's Expertise
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version