Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Rubrik: Identity Resilience for MSPs: Recovery Beyond MFA

Rubrik
10/07/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Senior Director of Product Management at Rubrik. Malika, thanks for joining. I'm Nawaz. I'm thrilled to be here. Thank you for having me. Why has identity become such a critical part of cyber resilience? Nawaz, that's a really a great question. So today we're seeing a changing landscape. We've seen the surge in identity-based attacks. Actually, 62% of breaches today exploit identity. The way attackers are coming in is now through the front door. There's actually a great report recently from CrowdStrike where if we're looking at big breaches that have happened recently, 82% of detections are now malware-free. And majority of now are based on identity. Attackers are walking in through the front door with valid credentials. Today, the way attacks are happening, it's phishing, stolen logins, forged Kerberos tickets. And what's really interesting is once they're in, on average, it takes less than 30 minutes between initial compromise and lateral movements. So once your attackers are in, they are spreading through your system with the goal being staying hidden, blending in, and waiting for the moment. So when you think about resiliency and recovery, now it's a question about when the attack does happen and when your identity does get targeted, how are you actually going to be able to recover? That's a great way of looking at it. What are organizations usually missing when they think about their identity environment is already protected? Yeah, most organizations think about, hey, I've invested in my MFA providers, I've invested in ITDR solutions, so I'm very much covered from an identity standpoint. But as I mentioned today, when you think about how modern attacks unfold, attacks are now unfolding in a very different way. Attackers usually start with something most companies already know is a weak spot. They're looking at reused credentials, missing MFA, over-permissioned accounts. And from there, it's escalating. It's privileged escalation, forged certs, hidden backdoor accounts. And by the time the attack is actually detected, the attacker isn't just sitting in a foothold anymore. They are effectively part of your environment because if you think about the IDPs that a customer has, AD, Entre, and Okta, they are all wired together. So your attacker now is widespread. And so this is the piece actually most teams don't appreciate. Spotting the attacker now is actually becoming the easy part. Cleanly removing the persistence from your systems is what breaks people. So the question I always ask is, if someone took control of your identity environment tomorrow, what would recovery actually look like? How could you actually go recover clean and confidently say that you have removed the attacker away from your system, out of your system? That's a great way of looking at it. So if identity is compromised, what does recovery actually need to include? Yeah. So when we think about what does recovery need to include, let me talk about a little bit about how recovery is done today so that you have context on what are our customers doing today, right? When a recovery happens today, the options that customers do is A, a lot of times if customers are using elements like AD backup, they're backing up your domain controllers. And when you're recovering back your domain controls, a lot of times when you're recovering back, you're recovering back an environment where your attacker is already in. So you're recovering back all your backdoors, your forged tickets, and you bring your attacker back in. So you're not able to really recover clean, and recovery clean is a very critical component. The second option, which a lot of our customers do, is a full forest active directory forest recovery. Now, Microsoft themselves document how do you do a full active directory forest recovery? This is 150 pages, it's 20 plus manual steps, and there's a high failure rate. I think when we looked at data, it said around there's an 80% failure rate if you do an active directory forest recovery manually. And so this is why Rubrik really got into this space. We wanted to build a solution which talked about one, how do you recover clean and ensure you're able to recover clean confidently. And then second, we are thinking about this manual cumbersome operational process and making it as simple as possible and making this a five-step process. So Rubrik, really that is the Rubrik vision today. It is kind of an end-to-end solution that solves for customers' hybrid identity environments. We go from attack to recovery at machine speed, and we really think about four things. How do we go detect and resolve disruptions? So we integrate with your identity solutions already in the market, like CrowdStrike, Defender, even things like your IGA tools, SailPoint, Workday. We defend with your identity provider, your existing identity systems to kind of ingest their signals, be able to detect what an attacker comes in, be able to pinpoint what is that clean recovery point, so that when you recover, you recover clean, you're eliminating your attacker persistence, and you're minimizing this business disruption. So that is really how we recommend customers looking at recovery, which is thinking about how do you make sure you recover not only fast, but you're recovering clean and removing that attacker from your system. What opportunities does identity resilience create for MSPs? Honestly, there's huge opportunities when we think about identity resilience for MSPs. When we talk to our customers today, let's think about the big IDPs out there, AD, Ontra, Okta. 10 out of 10 Okta customers are not thinking about resiliency and thinking about protecting their Okta environment. 7 out of 10 on the Ontra side, 6 out of 10 on the AD side. So the opportunity here for MSPs is huge because this is top of mind now for customers, because as I mentioned, with the surge in identity- based attacks, it's not about when an attacker comes into the front door, it's about when they come in, what do you do? How can you ensure you minimize business disruption, and how you're able to get your business back up and running with confidence that your attacker is no longer in the building. So this is a huge opportunity for MSPs to really go talk to customers about this on this very relevant top of mind issues. And now as we think about the changing environment, especially with agents coming in, the attack vectors are now only increasing with agents now also coming in. So the boundaries, so we call it, is really removed. You need to think about external threat actors, but you also need to think internally, are there agents now with over-permissive access who can go in and kind of create havoc in your system? So recovery becomes even more of an integral opportunity here. Malika, thank you. This is, I mean, this is great information. Until next time, I'm Nawaz Ali. Thanks for joining MSP Inscript.

TL;DR

  • 62% of breaches exploit identity and 82% of detections are now malware-free, meaning attackers use stolen credentials rather than traditional malware to gain access.
  • Standard MFA and ITDR investments do not address recovery — restoring from a compromised AD backup often reintroduces the attacker's backdoors and forged tickets.
  • Microsoft's manual AD forest recovery process is 150 pages with 20-plus steps and an estimated 80% failure rate, highlighting the need for automated alternatives.
  • Rubrik positions its identity resilience platform as an end-to-end solution that integrates with CrowdStrike, Defender, SailPoint, and Workday to enable fast, clean recovery at machine speed.

Summary

In this episode of MSP Unscripted, Rubrik's Senior Director of Product Management Mallika Swaminathan joins host Nawaz Ali to make the case that identity resilience — not just identity security — must become a core pillar of every cyber resilience strategy. Swaminathan opens with a striking data point: 62% of breaches today exploit identity, and 82% of detections are now malware-free, meaning attackers are walking in through the front door using valid credentials rather than deploying traditional malware. Once inside, lateral movement happens in under 30 minutes, making detection alone an insufficient defense. The conversation then shifts to a critical gap most organizations overlook: investing in MFA and ITDR tools does not guarantee clean recovery. When Active Directory is compromised, standard backup-and-restore approaches often bring backdoors and forged tickets back with them. Microsoft's own documented process for a full AD forest recovery runs 150 pages, involves 20-plus manual steps, and carries an estimated 80% failure rate when executed manually. Rubrik's answer is an end-to-end identity resilience platform that integrates with existing tools — including CrowdStrike, Microsoft Defender, SailPoint, and Workday — to detect attacker persistence, pinpoint a clean recovery point, and automate what was previously a grueling manual process down to five steps. For MSPs, the opportunity is significant: Swaminathan notes that 10 out of 10 Okta customers are not actively thinking about resilience for their Okta environment, signaling a wide-open advisory and service delivery gap.

Chapters

0:00 - Introduction & Guest Welcome
0:17 - Why Identity Is Now the Primary Attack Vector
1:22 - Gaps in Existing Identity Protection
2:46 - What Clean Identity Recovery Actually Requires
5:13 - MSP Opportunity in Identity Resilience

Key Quotes

0:24 "... 62% of breaches today exploit identity."
0:40 "... 82% of detections are now malware-free. And majority of now are based on identity."
2:20 "Spotting the attacker now is actually becoming the easy part. Cleanly removing the persistence from your systems is what breaks people."
3:49 "There's an 80% failure rate if you do an active directory forest recovery manually."
5:27 "... 10 out of 10 Okta customers are not thinking about resiliency and thinking about protecting their Okta environment."

FAQ

What is the difference between identity security and identity resilience?

Identity security focuses on preventing attackers from gaining access — through MFA, ITDR tools, and access controls. Identity resilience goes further, addressing what happens after a breach: how do you detect attacker persistence, identify a clean recovery point, and restore your identity environment without reintroducing backdoors or forged credentials?

Why isn't restoring an Active Directory backup enough after an identity attack?

Because standard AD backups capture the environment as it was — including any backdoor accounts, forged Kerberos tickets, or hidden persistence mechanisms the attacker already planted. Restoring from that backup effectively brings the attacker back in. Clean recovery requires identifying a pre-compromise state and surgically removing attacker artifacts before restoration.


Categories:
  • » Webinar Library » Rubrik
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Data Protection
  • Backup & Recovery
  • Security Operations
  • Best Practices
  • Interview
  • Identity Resilience
  • Active Directory Recovery
  • Cyber Resilience
  • Identity-Based Attacks
  • Managed Service Providers
  • Credential-Based Threats
  • Lateral Movement
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Rubrik: Identity Resilience for MSPs: Recovery Beyond MFA

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      11:00 AM
                      10/27/2026
                      Maximize Security, Value, and Returns on Your Microsoft Investment
                      https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                      https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version