Transcript
and security teams have confirmed ransomware activity. Every minute of downtime impacts revenue, customer commitments, regulatory obligations, and customer trust. The challenge isn't simply restoring data, it's restoring business operations as quickly and safely as possible. That's why Cohesity approaches cyber resilience through five connected steps. At Cohesity we address this through our five steps of cyber resilience framework, aligned to standards like NIST and MITRE. Starting with step one, protect all your data. Moving to step two, ensuring recoverability. Step three, detect and investigate threats. And step four, practice application resilience. And finally, step five, optimize your data risk posture. Throughout this demo, I'll show you how these capabilities work together and are delivered via a unified platform to help organizations reduce risk, simplify operations, and recover with confidence. Let's start with the foundation and step one of cyber resilience, protect all data. When a cyber attack occurs, recovery starts long before the incident itself. The first step is ensuring that every workload, application, cloud service, and identity system required to run the business is protected. With this ransomware attack, the first question is simple. Do we protect everything required to recover the business? And do we have backups we need to successfully recover the business? Modern applications depend on databases, cloud workloads, SaaS applications, and identity infrastructure. Missing any one of those components can delay recovery and extend downtime. When a ransomware attack disrupts operations, protecting on-prem, cloud, SaaS, and identity data through a single platform helps ensure critical business services remain recoverable without major disruption. So here in Helios, this is your global view. You can see all your clusters across environments, your overall security posture, any threats we've already detected in your backup data. Now if we jump over to Data Protect and we look at cluster management, I can see versions, capacity, and even where upgrades are needed all in one place. From a coverage standpoint, it's broad. If we go under protection, we have coverage such as VMware, AHV, Hyper-V, plus all the major clouds, databases like SQL, Oracle, or MongoDB, NAS systems like NetApp and Isilon, Microsoft 365, physical servers, and hybrid identity infrastructure across Active Directory, Intra-ID, and even Okta. The goal is simple. No blind spots. As the attack spreads, identity services are compromised. Users can no longer authenticate and access critical systems. Even if applications are restored, the business cannot operate until identity services are restored. Now, Active Directory is always where this gets real. Microsoft's own forest recovery guidance is, let's just say, not quick. It's dozens of steps and a massive document. Here we've reduced that to a guided workflow. You select your recovery point. You choose your domain controller, decide whether to restore or promote, and click go. That's it. So instead of hours or days, you're recovering AD in minutes through automated and parallel recovery. And more importantly, you're recovering it clean. This means decoupling AD data from the OS during the recovery process and performing powerful PostgreSQL forensics to close those back doors. This brings identity services back online without bringing the problem back with you. So step one takeaway. We get comprehensive protection across data, applications, cloud services, and identity infrastructure. A reduced storage footprint through efficient data protection, fast, clean recovery of critical identity services, and confidence that all business critical dependencies are protected before an incident occurs. Moving on to step two of cyber resilience. Ensure recoverability. Protection alone isn't enough. In our ransomware scenario, we've confirmed the critical systems were protected. But the next question is whether those recovery copies will be available and uncompromised when the business needs them most. Modern attackers frequently target backup infrastructure to eliminate recovery options. That's why recoverability focuses on ensuring backup data remains protected, immutable, and isolated from the attack. Before an incident occurs, organizations should validate that their backup environment is configured according to security best practices and designed to withstand cyber threats. We focus on three things here. Hardening the environment, making the backups immutable, and maintaining an isolated air gap recovery copy. Inside Security Center, this is where we can find the Security Posture Advisor. Now, the Security Posture Advisor checks clusters for Cohesity Hardening best practices. If any of these settings are not in the most secure state possible, Posture Advisor suggests actions to take to remediate. It continuously checks to see if there's external key management, whether NTP is secure, or are all the configs aligned? If something's off, you'll see it immediately, and more importantly, how to fix it. Let's assume the attackers gained privileged access and attempted to compromise backup infrastructure. Organizations now need a recovery copy that remains isolated from the attack. That's where Fort Knox comes into play. This is your last line of defense. Cohesity Fort Knox provides an isolated, immutable recovery vault that helps ensure organizations can recover clean. Trust data if the primary environment has been compromised by a cyber attack. You can vault data to your cloud of choice, whether that's AWS, Azure, GCP, or another on-prem environment, and you control where it goes. You can choose the cloud provider or on-premises location that best aligns with your security and disaster recovery requirements. When data is allowed to move, you can define controlled vaulting windows that limit when the data can enter or leave the vault, helping reduce the attack surface and protect recovery copies from unauthorized access, and how quickly you can retrieve it. You can configure recovery objectives that meet your business needs so critical data can be accessed when it's time to restore operations. Step two takeaway here. Recoverability is about trust, immutable backups, and isolated vaults, which help ensure organizations always have a clean recovery path, even when primary environments are compromised. Step three of cyber resilience, detect and investigate threats. Before recovery can begin, organizations need to understand the scope of the attack. They must determine what happened, how far it spread, and which recovery points remain safe to restore. At this stage, backups become a valuable forensics record that helps security teams investigate the incident and make informed recovery decisions. We're looking for ransomware encryption patterns, malware hashes, and known indicators of compromise. Here's where we define what happens when something suspicious shows up. Anomaly detections helps organizations identify potential ransomware activity early by detecting unusual behavior in backup data before the threat spreads further and impacts critical business operations. We can alert your SOC. We can automatically trigger threat scans when anomaly is detected. We can trigger additional actions like data sensitivity and classification. When we find something, we show you when it started, where it spread, and what changed between a clean and compromised snapshot. Behind the scenes, we're showing you things like data change rates, entropy, and re-write patterns, as well as files modified between backups. Now why would organizations care about rapid threat hunting? An organization would turn to threat hunting after detecting suspicious activity or ransomware indicators to quickly determine how the attack started, what systems or data were impacted, and which recovery points remain safe to restore. From there, we could scan against threat intelligence feeds or bring your own YAR rules, use hash matching to find known bad threats, and even detonate unknown files in a sandbox, and then summarize everything with a cyber recovery assistant. Step three takeaway here. You're not guessing what happened. You have a clear, data-backed view of the attack and its impact. On to step four of cyber resilience, practice application resilience. The organization has identified clean recovery points and is preparing to restore critical applications. However, restoring directly into production creates risks. Teams need a safe way to validate recovered applications, verify dependencies, scan for threats, and test recovery workflows bringing business services back online. This is where many recovery efforts fail. Rather than waiting for an actual incident to expose gaps in the recovery plan, organizations can continuously validate recovery readiness through clean rooms, staging environments, and automated recovery workflows. During a ransomware attack, these capabilities help ensure recovered applications are clean, functional, and ready for production use. Inside Recovery Agent, we can automate a clean room to begin isolated forensics analysis of our impacted enterprise business critical systems. To set up the clean room, we'll first need to define an isolated network, specify specific compute resources, prioritize selected workloads in a recovery group. Then, we instantly mount the data, scan for threats, test the recovery and staging, and define how production recovery will run. During a cyber crisis, teams don't want to rely on manual runbooks or hundreds of recovery steps. Once that's defined, we can automate it with a blueprint. We can scan, test, and recover. And yes, we can even generate those workflows using AI. So step four takeaway is recovery confidence comes from testing before a crisis, not improvising during one. Step five is cyber resilience, optimize data risk posture. Recovery decisions should be driven by business risk, not just technical priorities. While critical applications may be recoverable, leadership still needs answers. What sensitive data expose? What systems and data should be prioritized for recovery? Are there any regulatory or compliance obligations that must be addressed? Understanding data risk helps organizations make informed recovery decisions, prioritize what matters most, and reduce business and compliance exposure. In our scenario, the security team needs to determine which business critical and sensitive data assets are affected by the attack. In the security inventory, you get a full view of what data exists, where it lives, and how it's being used, whether or not it's properly protected or not. From there, we layer deep discoveries and classifications from DSPM. For example, we can search for an S3 bucket, drill into the insights, and see if it contains financial or health care data, and prioritize it for protection if it has sensitive data. We can even classify historical backup data so you know what you're restoring before you do it. A step five takeaway, you're making smarter recovery decisions based on data sensitivity, not just recovering everything blindly. Once organizations have protected their data, ensured recoverability, investigated threats, validated recovery, and understood their data risk posture, they can leverage that data to accelerate investigations and improve decision making. Throughout a cyber incident, executives, security teams, legal teams, and auditors need answer quickly. Gaia helps teams find information faster by enabling them to define their data sets. And within the data sets, they could set access controls that limit users to what they have access to. They can also explore topics within a data set, ask natural language questions across their data. Using Retrieval Augmented Generation, RAG, Gaia can find relevant content, summarize the information, and cite sources. The result is data that not only supports recovery, but also delivers actionable intelligence when it's needed most. Let's return to the scenario we started with. A ransomware attack disrupted my enterprise's critical business operations, impacted identity services, and raised concerns about sensitive data exposure. Through the Cohesity 5 steps of Cyber Resilience, we protected critical workloads and identity infrastructure, ensured recovery data remained trustworthy, investigated the attack and identified clean recovery points, validated recovery in a clean room before production restoration, prioritized recovery decisions based on business risk and data sensitivity. These steps ensure clean, confident recovery of my business operations with one unified Cyber Resilience platform.