Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
How to strengthen resilience in less time by automatically discovering and protecting sensitive data.
At Catalyst, Cohesity outlined our vision for Autonomous Cyber Resilience. Agentic workflows to automate the Cohesity 5 Steps of Cyber Resilience©.
While enhancements will continue to be added, the foundational capabilities are available today. In this tutorial, we show you how Cohesity Data Cloud and Cohesity DSPM work together to help you discover and protect all data automatically.
We all know that enterprise data volumes are growing. To keep up with protecting and securing your estate, you need automation. Cohesity DSPM and Cohesity Data Cloud turn classification and risk signals into automatic, ongoing protection decisions. This helps you address gaps in sensitive data protection.
Here’s the workflow:
Figure 1: Cohesity DSPM provides the deep discovery into what assets, sensitive data, apps, and identities (human and agent). That data flows into Cohesity Data Cloud which can then automatically apply policies across the Cohesity 5 Steps of Cyber Resilience©.
With the requirements codified, Cohesity discovers the data, and applies the right policies at a speed and scale that will delight your overworked operations teams.
We designed this new autonomous experience to be simple. Here are key concepts you need to understand:
Object Groups turn sensitivity into structure. An object group is a dynamic, logical grouping of data objects built using context such as risk sensitivity levels. Instead of hand-picking datasets, you define a dynamic group using Cohesity DSPM’s classification and sensitivity tags—for example, everything tagged Financial or Restricted. As new data lands and gets classified, it flows into the group automatically. This way you won’t have to deal with a spreadsheet of asset names that goes stale the day after you build it.
Figure 2: Configure the sensitivity level of your data objects. This becomes the baseline of what Cohesity DSPM discovers, logically groups, and then applies policies to.
Exclusions on your object groups give you even more control. Not every system belongs in an automated workflow—maybe it's a legacy source, a system under change freeze, or something your team wants to keep on manual protection for now. Exclude it globally or at the Object Group level, and everything else still gets protected automatically.
Figure 3: Choose which data objects and systems are excluded from automatic discovery and protection.
Smart Rules turn that structure into automated protection. A smart rule is an automated, protection policy that applies controls to a defined Object Group. It combines factors such as backup frequency, retention, recovery objectives, and more, ensuring critical data is always protected consistently, without manual configuration. Once you create a Smart Rule, you can then attach it to an Object Group, and Cohesity applies it automatically to every object that qualifies. If an object matches more than one rule, priority order decides which policy wins, so there's no ambiguity about which control took effect.
Figure 4: You can attach the policy of your choice to each smart rule you create.
Simulate a Smart Rule or Object Group in action to make sure it works correctly. Before anything gets applied, you can preview exactly which objects would be added, removed, or left unchanged—the drift. That means you can validate the efficacy of a policy change before it happens.
Figure 5: Choose a smart rule to test before you apply it to your live environment.
Use Cohesity Copilot to configure your autonomous protection policies with natural language. Cohesity Copilot is an AI-powered operational assistant that lets IT and security teams interact with the Cohesity Data Cloud using natural language. Ask it to find unprotected sensitive assets, discover unclassified objects, or build an Object Group and Smart Rule. It's the same assistant already doing this work inside Cyber Recovery Assistant—same context awareness, same step-by-step transparency.
Figure 6: Have a conversation with Cohesity Copilot to create a new object rule and smart rule for Autonomous Cyber Resilience.
The outcome is right-sized protection with automation, which improves your security posture and saves you money.
Manual, blanket protection can lead to “overprotection” of low-value, stale, and duplicate data. Automated decisions are more likely to deliver the proper protection policies based on strict rules and criteria. Your "crown jewels" get the strongest protection, while less sensitive data uses less infrastructure over time.
Pair this new experience with what Cohesity Data Cloud already does with global deduplication and compression across your entire protected estate, and you can see how the efficiency gains can compound. You protect the most critical data with the rioht level of protection on an infrastructure built to provide the lowest TCO. Less time spent triaging what to protect, less capacity spent protecting what doesn't matter, more of your IT and security team's attention going towards the rest of their responsibilities.
If you're already running Cohesity DSPM, get started in five easy steps:
1. Decide what stays manual. Build your exclusion list first—the systems and sources that should keep using conventional protection. Not all data needs or should have the same treatment. Since the Smart Rules are based on context, for certain systems, that context may not change that frequently, or you need specific protection coverage. For example, the data in a database may be constantly changing, but the protection policy needs to stay consistent. If you have any other specific requirements for manual protection, you can still do so. Everything else becomes eligible for automation.
2. Define an Object Group. Use the sensitivity, classification, or staleness tags that matter—such as PII, financial data, or IP—to your risk model.
3. Attach a Smart Rule. With the protection policy and priority that reflects business criticality.
4. Simulate before you commit. Check the drift, confirm the right objects are in scope, then apply.
5. Let it run and re-verify. Sync DSPM data on your own cadence, so Smart Rules keep evaluating against current classification, and check Security Center Inventory to confirm protection status matches intent.
Data growth isn't slowing down. And the risk posed by AI to your data is only growing. Every new pipeline, every new agent, every new SaaS connector is another way for sensitive data to land somewhere unprotected before anyone notices.
Static protection policies and manual review queues were never going to keep up with that curve. The organizations that stay resilient will be the ones whose protection decisions scale automatically with their data, informed by what that data is and how much risk it carries.
Already running Cohesity DSPM? Check out these new automated capabilities in Cohesity Cloud Services (CCS) deployments.
Learn more:
Written By
Isabelle Yang
Product Marketing Manager
Subhash Kotkar
Staff Product Manager