Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Cohesity's 5 Steps of Cyber Resilience Framework

Cohesity
09/01/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


and security teams have confirmed ransomware activity. Every minute of downtime impacts revenue, customer commitments, regulatory obligations, and customer trust. The challenge isn't simply restoring data, it's restoring business operations as quickly and safely as possible. That's why Cohesity approaches cyber resilience through five connected steps. At Cohesity we address this through our five steps of cyber resilience framework, aligned to standards like NIST and MITRE. Starting with step one, protect all your data. Moving to step two, ensuring recoverability. Step three, detect and investigate threats. And step four, practice application resilience. And finally, step five, optimize your data risk posture. Throughout this demo, I'll show you how these capabilities work together and are delivered via a unified platform to help organizations reduce risk, simplify operations, and recover with confidence. Let's start with the foundation and step one of cyber resilience, protect all data. When a cyber attack occurs, recovery starts long before the incident itself. The first step is ensuring that every workload, application, cloud service, and identity system required to run the business is protected. With this ransomware attack, the first question is simple. Do we protect everything required to recover the business? And do we have backups we need to successfully recover the business? Modern applications depend on databases, cloud workloads, SaaS applications, and identity infrastructure. Missing any one of those components can delay recovery and extend downtime. When a ransomware attack disrupts operations, protecting on-prem, cloud, SaaS, and identity data through a single platform helps ensure critical business services remain recoverable without major disruption. So here in Helios, this is your global view. You can see all your clusters across environments, your overall security posture, any threats we've already detected in your backup data. Now if we jump over to Data Protect and we look at cluster management, I can see versions, capacity, and even where upgrades are needed all in one place. From a coverage standpoint, it's broad. If we go under protection, we have coverage such as VMware, AHV, Hyper-V, plus all the major clouds, databases like SQL, Oracle, or MongoDB, NAS systems like NetApp and Isilon, Microsoft 365, physical servers, and hybrid identity infrastructure across Active Directory, Intra-ID, and even Okta. The goal is simple. No blind spots. As the attack spreads, identity services are compromised. Users can no longer authenticate and access critical systems. Even if applications are restored, the business cannot operate until identity services are restored. Now, Active Directory is always where this gets real. Microsoft's own forest recovery guidance is, let's just say, not quick. It's dozens of steps and a massive document. Here we've reduced that to a guided workflow. You select your recovery point. You choose your domain controller, decide whether to restore or promote, and click go. That's it. So instead of hours or days, you're recovering AD in minutes through automated and parallel recovery. And more importantly, you're recovering it clean. This means decoupling AD data from the OS during the recovery process and performing powerful PostgreSQL forensics to close those back doors. This brings identity services back online without bringing the problem back with you. So step one takeaway. We get comprehensive protection across data, applications, cloud services, and identity infrastructure. A reduced storage footprint through efficient data protection, fast, clean recovery of critical identity services, and confidence that all business critical dependencies are protected before an incident occurs. Moving on to step two of cyber resilience. Ensure recoverability. Protection alone isn't enough. In our ransomware scenario, we've confirmed the critical systems were protected. But the next question is whether those recovery copies will be available and uncompromised when the business needs them most. Modern attackers frequently target backup infrastructure to eliminate recovery options. That's why recoverability focuses on ensuring backup data remains protected, immutable, and isolated from the attack. Before an incident occurs, organizations should validate that their backup environment is configured according to security best practices and designed to withstand cyber threats. We focus on three things here. Hardening the environment, making the backups immutable, and maintaining an isolated air gap recovery copy. Inside Security Center, this is where we can find the Security Posture Advisor. Now, the Security Posture Advisor checks clusters for Cohesity Hardening best practices. If any of these settings are not in the most secure state possible, Posture Advisor suggests actions to take to remediate. It continuously checks to see if there's external key management, whether NTP is secure, or are all the configs aligned? If something's off, you'll see it immediately, and more importantly, how to fix it. Let's assume the attackers gained privileged access and attempted to compromise backup infrastructure. Organizations now need a recovery copy that remains isolated from the attack. That's where Fort Knox comes into play. This is your last line of defense. Cohesity Fort Knox provides an isolated, immutable recovery vault that helps ensure organizations can recover clean. Trust data if the primary environment has been compromised by a cyber attack. You can vault data to your cloud of choice, whether that's AWS, Azure, GCP, or another on-prem environment, and you control where it goes. You can choose the cloud provider or on-premises location that best aligns with your security and disaster recovery requirements. When data is allowed to move, you can define controlled vaulting windows that limit when the data can enter or leave the vault, helping reduce the attack surface and protect recovery copies from unauthorized access, and how quickly you can retrieve it. You can configure recovery objectives that meet your business needs so critical data can be accessed when it's time to restore operations. Step two takeaway here. Recoverability is about trust, immutable backups, and isolated vaults, which help ensure organizations always have a clean recovery path, even when primary environments are compromised. Step three of cyber resilience, detect and investigate threats. Before recovery can begin, organizations need to understand the scope of the attack. They must determine what happened, how far it spread, and which recovery points remain safe to restore. At this stage, backups become a valuable forensics record that helps security teams investigate the incident and make informed recovery decisions. We're looking for ransomware encryption patterns, malware hashes, and known indicators of compromise. Here's where we define what happens when something suspicious shows up. Anomaly detections helps organizations identify potential ransomware activity early by detecting unusual behavior in backup data before the threat spreads further and impacts critical business operations. We can alert your SOC. We can automatically trigger threat scans when anomaly is detected. We can trigger additional actions like data sensitivity and classification. When we find something, we show you when it started, where it spread, and what changed between a clean and compromised snapshot. Behind the scenes, we're showing you things like data change rates, entropy, and re-write patterns, as well as files modified between backups. Now why would organizations care about rapid threat hunting? An organization would turn to threat hunting after detecting suspicious activity or ransomware indicators to quickly determine how the attack started, what systems or data were impacted, and which recovery points remain safe to restore. From there, we could scan against threat intelligence feeds or bring your own YAR rules, use hash matching to find known bad threats, and even detonate unknown files in a sandbox, and then summarize everything with a cyber recovery assistant. Step three takeaway here. You're not guessing what happened. You have a clear, data-backed view of the attack and its impact. On to step four of cyber resilience, practice application resilience. The organization has identified clean recovery points and is preparing to restore critical applications. However, restoring directly into production creates risks. Teams need a safe way to validate recovered applications, verify dependencies, scan for threats, and test recovery workflows bringing business services back online. This is where many recovery efforts fail. Rather than waiting for an actual incident to expose gaps in the recovery plan, organizations can continuously validate recovery readiness through clean rooms, staging environments, and automated recovery workflows. During a ransomware attack, these capabilities help ensure recovered applications are clean, functional, and ready for production use. Inside Recovery Agent, we can automate a clean room to begin isolated forensics analysis of our impacted enterprise business critical systems. To set up the clean room, we'll first need to define an isolated network, specify specific compute resources, prioritize selected workloads in a recovery group. Then, we instantly mount the data, scan for threats, test the recovery and staging, and define how production recovery will run. During a cyber crisis, teams don't want to rely on manual runbooks or hundreds of recovery steps. Once that's defined, we can automate it with a blueprint. We can scan, test, and recover. And yes, we can even generate those workflows using AI. So step four takeaway is recovery confidence comes from testing before a crisis, not improvising during one. Step five is cyber resilience, optimize data risk posture. Recovery decisions should be driven by business risk, not just technical priorities. While critical applications may be recoverable, leadership still needs answers. What sensitive data expose? What systems and data should be prioritized for recovery? Are there any regulatory or compliance obligations that must be addressed? Understanding data risk helps organizations make informed recovery decisions, prioritize what matters most, and reduce business and compliance exposure. In our scenario, the security team needs to determine which business critical and sensitive data assets are affected by the attack. In the security inventory, you get a full view of what data exists, where it lives, and how it's being used, whether or not it's properly protected or not. From there, we layer deep discoveries and classifications from DSPM. For example, we can search for an S3 bucket, drill into the insights, and see if it contains financial or health care data, and prioritize it for protection if it has sensitive data. We can even classify historical backup data so you know what you're restoring before you do it. A step five takeaway, you're making smarter recovery decisions based on data sensitivity, not just recovering everything blindly. Once organizations have protected their data, ensured recoverability, investigated threats, validated recovery, and understood their data risk posture, they can leverage that data to accelerate investigations and improve decision making. Throughout a cyber incident, executives, security teams, legal teams, and auditors need answer quickly. Gaia helps teams find information faster by enabling them to define their data sets. And within the data sets, they could set access controls that limit users to what they have access to. They can also explore topics within a data set, ask natural language questions across their data. Using Retrieval Augmented Generation, RAG, Gaia can find relevant content, summarize the information, and cite sources. The result is data that not only supports recovery, but also delivers actionable intelligence when it's needed most. Let's return to the scenario we started with. A ransomware attack disrupted my enterprise's critical business operations, impacted identity services, and raised concerns about sensitive data exposure. Through the Cohesity 5 steps of Cyber Resilience, we protected critical workloads and identity infrastructure, ensured recovery data remained trustworthy, investigated the attack and identified clean recovery points, validated recovery in a clean room before production restoration, prioritized recovery decisions based on business risk and data sensitivity. These steps ensure clean, confident recovery of my business operations with one unified Cyber Resilience platform.

TL;DR

  • Cohesity's Five Steps of Cyber Resilience framework — aligned to NIST and MITRE — covers protection, recoverability, threat detection, application validation, and data risk posture through a single unified platform.
  • Active Directory recovery is reduced from Microsoft's multi-step forest recovery process to a guided workflow that completes in minutes, with forensic decoupling to prevent reinfection.
  • Fort Knox provides an isolated, immutable vault supporting AWS, Azure, GCP, and on-premises targets with controlled vaulting windows that limit when data can enter or leave the vault.
  • Clean room environments and AI-generated recovery blueprints allow teams to validate recovered applications before production restoration, eliminating improvised responses during a live incident.

A Framework Built for Ransomware Recovery

This product demonstration walks through Cohesity's Five Steps of Cyber Resilience, a structured framework aligned to industry standards including NIST and MITRE. The video opens with a realistic ransomware scenario — employees locked out Monday morning, critical systems offline, and security teams scrambling — to frame why a comprehensive, pre-planned resilience strategy matters. Rather than treating recovery as a purely technical exercise, Cohesity positions its framework as a business continuity approach that addresses data protection, recoverability, threat investigation, application validation, and data risk governance through a single unified platform called Helios.

Protection, Immutability, and Threat Detection

The first two steps focus on ensuring nothing is left unprotected and that backup copies remain trustworthy when needed most. Step one covers broad workload coverage — VMware, AHV, Hyper-V, major cloud providers, SQL, Oracle, MongoDB, NAS systems like NetApp and Isilon, Microsoft 365, physical servers, and hybrid identity infrastructure including Active Directory, Entra ID, and Okta. A notable capability is automated Active Directory forest recovery, which Cohesity claims reduces Microsoft's own multi-step guidance to a guided workflow recoverable in minutes rather than hours or days. Step two introduces Fort Knox, Cohesity's isolated immutable vault, which supports vaulting to AWS, Azure, GCP, or on-premises environments with controlled data movement windows to limit attack surface exposure. The Security Posture Advisor continuously checks cluster configurations against hardening best practices and surfaces remediation guidance when settings drift.

Investigation, Validation, and Risk-Driven Recovery

Steps three through five shift from protection to intelligent recovery. Step three demonstrates threat detection capabilities including anomaly detection on backup data, entropy and data change rate analysis, YARA rule support, hash matching against threat intelligence feeds, and file sandboxing — all summarized through an AI-powered cyber recovery assistant. Step four introduces Recovery Agent and the concept of clean rooms: isolated staging environments where recovered applications can be scanned, tested, and validated before production restoration. Automated recovery blueprints, including AI-generated workflows, eliminate reliance on manual runbooks during a crisis. Step five addresses data risk posture through DSPM-powered classification, enabling teams to identify sensitive financial or healthcare data within backup sets and prioritize recovery decisions accordingly. The demo closes with Gaia, a RAG-based AI assistant that allows executives, legal teams, and auditors to query data sets in natural language during an active incident.

Chapters

0:00 - Ransomware Scenario Setup
0:26 - Five Steps Framework Overview
1:09 - Step 1: Protect All Data
4:39 - Step 2: Ensure Recoverability
7:26 - Step 3: Detect and Investigate Threats
9:34 - Step 4: Practice Application Resilience
11:22 - Step 5: Optimize Data Risk Posture
13:08 - Gaia AI Assistant Demo
14:02 - Scenario Recap and Summary

Key Quotes

0:26 "That's why Cohesity approaches cyber resilience through five connected steps."
3:28 "Microsoft's own forest recovery guidance is, let's just say, not quick. It's dozens of steps and a massive document."
3:51 "So instead of hours or days, you're recovering AD in minutes through automated and parallel recovery."
6:15 "This is your last line of defense."
11:12 "And yes, we can even generate those workflows using AI."
12:44 "A step five takeaway, you're making smarter recovery decisions based on data sensitivity, not just recovering everything blindly."

FAQ

What workloads and environments does Cohesity's protection coverage include?

Cohesity covers VMware, AHV, and Hyper-V hypervisors; major cloud providers; databases including SQL, Oracle, and MongoDB; NAS systems like NetApp and Isilon; Microsoft 365; physical servers; and hybrid identity infrastructure spanning Active Directory, Entra ID, and Okta.

What is Cohesity Fort Knox and how does it protect backup data during an attack?

Fort Knox is Cohesity's isolated, immutable recovery vault. It supports vaulting to AWS, Azure, GCP, or on-premises environments and uses controlled vaulting windows to limit when data can enter or leave the vault, reducing attack surface and ensuring a clean recovery copy remains available even if the primary environment is compromised.


Categories:
  • » Webinar Library » Cohesity
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Backup & Recovery
  • Security Operations
  • Threat Intelligence
  • AI & Machine Learning
  • Demo
  • Technical Deep Dive
  • Cyber resilience framework
  • Ransomware recovery
  • Active Directory recovery
  • Immutable backup vaults
  • Threat detection and investigation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Cohesity's 5 Steps of Cyber Resilience Framework

              XStreaminars (watch here)

              • Sep
                03

                Verge.io: Can You Afford Your Next Storage Refresh?

                09/03/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Sep
                  17

                  Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                  09/17/202610:00 AM ET
                  • Sep
                    17

                    Unveiling the AI-Driven Underworld of Automation's Rapid Rise

                    09/17/202601:00 PM ET
                    • Sep
                      23

                      Unseen Data: The Blind Spot in Your Protection Strategies

                      09/23/202601:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/03/2026
                        01:00 PM
                        09/03/2026
                        Verge.io: Can You Afford Your Next Storage Refresh?
                        https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                      • 09/17/2026
                        10:00 AM
                        09/17/2026
                        Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                        https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                      • 09/17/2026
                        01:00 PM
                        09/17/2026
                        Unveiling the AI-Driven Underworld of Automation's Rapid Rise
                        https://www.truthinit.com/index.php/channel/2108/unveiling-the-ai-driven-underworld-of-automations-rapid-rise/
                      • 09/23/2026
                        01:00 PM
                        09/23/2026
                        Unseen Data: The Blind Spot in Your Protection Strategies
                        https://www.truthinit.com/index.php/channel/2087/unseen-data-the-blind-spot-in-your-protection-strategies/
                      • 09/29/2026
                        12:00 PM
                        09/29/2026
                        Embracing AI Adoption While Ensuring Robust Security Measures
                        https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      • 11/19/2026
                        01:00 PM
                        11/19/2026
                        360View: Govern, Secure & Recover Your Microsoft 365 Environment
                        https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version