Cohesity’s Five Steps to Cyber Resilience in a Post-Mythos World

On the opening day of the 70th edition of the IT Press Tour in Palo Alto, Cohesity CEO Sanjay Poonen asked a room of technology journalists to start where most security conversations prefer to avoid. The attacker is already inside. The breach has happened. So, what comes next?

It was a useful way to frame a briefing shaped by the arrival of Anthropic’s Claude Mythos earlier this year. The model developed for cybersecurity and other advanced research famously found and exploited unknown vulnerabilities across major operating systems and web browsers during testing.

Project Glasswing initially restricted access to vetted defenders, giving participating organizations time to find and repair weaknesses before the capabilities became widely available.

Cohesity joined that program and gave Mythos access to its source code. Poonen said selected customers also tested Cohesity binaries, allowing the company to compare what the model found in source code with what customers could discover in deployed software.

Discover and protect every workload

Cohesity’s first step sounds basic: know what the organization owns and make sure it is protected. In practice, this is where many recovery plans begin to fail. Enterprise data is spread across virtual machines, databases, file systems, cloud services, SaaS applications, identity platforms and, increasingly, AI agents with their own memory, configuration and state.

Poonen linked this work to the idea of a “minimum viable bank,” a phrase developed through conversations with large financial institutions. Every organization should be able to name its own minimum viable company: the smallest set of systems, data, and people required to resume an acceptable level of service. This turns backup coverage from an infrastructure inventory into a business priority.

The first workloads restored should be the ones that let the company serve customers, take payments, communicate, and make decisions.

Keep an isolated copy that remains recoverable

The second step is cyber vaulting. Cohesity’s framework calls for immutable copies, strict administrative controls, and an air-gapped or logically isolated vault. Its FortKnox service implements that idea. The principle extends beyond any single product. A backup connected to the same credentials, management plane, and network as production can become another target during an attack.

Isolation creates a recovery option that is harder for an intruder to alter or delete. But an isolated copy is useful only if the organization knows how to reach it when normal identity services and administrative tools may be unavailable.


Search backups for threats before restoring them

Scan backup data for anomalies, malware, and other indicators of compromise. Attackers can remain inside an environment for weeks before encrypting or deleting anything. A recent backup could contain the same malicious code, altered configuration, or stolen credential path that caused the incident. So, restoring quickly from an infected copy could risk restarting the attack.

Recovery teams must identify a point in time that is both recent enough to limit data loss and clean enough to trust. This requires threat hunting across backup history, with findings shared between security and infrastructure teams. It also requires alot of restraint. The pressure to bring systems online can be intense during a P1 incident, but a fast reinfection is not a recovery.

AI can help examine larger volumes of data and identify suspicious patterns, although Cohesity’s own presentation offered a sensible warning about its role. AI agents are probabilistic. Backup platforms and other systems of record must provide deterministic confirmation that a copy exists, a control is enabled, or a configuration has changed.

A human remains accountable for approving consequential actions. The useful model is an agent proposing, a trusted system verifying, and a person deciding.

Rehearse application recovery in a clean room

Move the conversation beyond restoring files. Cohesity advocates rebuilding applications inside an isolated clean room, using a blueprint that records configurations, scripts, dependencies, and tests. The application must then prove it can perform the business task it was built for.

Cohesity product officer Vasu Murthy used a banking example. Bringing the components online is not enough. Can the restored bank accept a deposit and reflect it correctly in the account? The same test applies elsewhere. Can a hospital retrieve a patient record, can a retailer complete an order, and can a manufacturer release a production job?
This is where recovery time objectives meet reality.

Clean-room exercises also bring security and IT operations into the same process. Security needs evidence that the threat has been removed. Operations needs a practical sequence for returning services to production. Business owners need to confirm that the recovered application behaves correctly. The result should be a repeatable recovery outcome, not a hopeful collection of scripts.

Continually assess what changed and what was missed

Cohesity describes the final step as optimizing data risk posture through ongoing discovery, classification, and assessment. Poonen noted that step five can become step one, because the environment does not stay still. New applications appear, data moves, agents are created, and business priorities change.

Continuous assessment should also measure whether recovery plans still match the business. A system considered secondary last year may now support revenue, regulatory reporting or customer identity.

Recovery becomes a board-level capability.

Could your company prove, today, that its minimum viable operation can be rebuilt from clean data by people who have practiced the process? If the answer depends on an untested runbook or the availability of one experienced administrator, you might have backups but not resilience.

Cohesity’s five steps do not promise immunity, but they do offer a disciplined cycle of discovery, isolation, investigation, rehearsal, and reassessment. In a post-Mythos world, the winners may be decided less by who claims the strongest wall and more by who can restore a trusted business before the damage becomes permanent.

I will be inviting Cohesity back onto the podcast, so if there are any questions you would like me to ask, please contact me to be a part of the conversation.