Loading
October 01 2026

Cohesity strengthens cyber resilience capabilities for self-managed deployments

Cohesity Data Cloud’s self-managed control plane adds threat hunting, identity resilience, and recovery orchestration for sovereign, regulated, and air-gapped environments. 

Cyber Resilience Capabilities

October marks Cybersecurity Awareness Month, and this year CISA's theme, "Securing the Next 250," calls on organizations to strengthen the systems critical operations depend on. 

Organizations have long appreciated the deployment flexibility of Cohesity Data Cloud. Run our cyber resilience platform in your data center, manage it from your cloud tenant, or let Cohesity run it for you as a service. This flexibility also extends to the Helios control plane: use our control plane in the cloud, or run it in your own air-gapped environment.

Recently, we’ve seen a wave of data-sovereignty requirements push regulated and public-sector buyers toward deployments they own and operate inside their own walls. Demand for self-managed, sovereign environments is climbing, and you shouldn’t have to trade resilience for control.

This update to the Helios self-managed control plane for Cohesity Data Cloud delivers. If you run a self-managed deployment, you can now cut your exposure to destructive attacks and speed incident response and recovery without sending a byte outside your control.  

Threat protection enhancements come to your control plane 

Your backup copy is your last line of defense, and adversaries know it. This release brings expansive new threat protection capabilities to your self-managed control plane. Use these features to uncover malware that could be lurking in your backup data. Here are the three capabilities you’ll want to enable:

  • Threat scanning powered by Sophos: Cohesity Data Cloud embeds antivirus detection from Sophos to help catch polymorphic malware that evades signature-based tools. The engine inspects backup data during ingest, before restoration, and after an indicator of compromise or YARA match fires. This way, you can clean your backup data and prevent malware from detonating. It's included as part of Cohesity Data Cloud Enterprise Edition, with no separate license required.
  • YARA threat scanning: Write your own YARA rules to hunt for the specific threats your team cares about. Run scans based on these rules to help identify specific malware patterns or file behaviors, enabling more precise, customized detection across your deployment.
  • Rapid threat hunting: Scan backups for known malicious files using SHA-256 hashes from built-in and custom threat intelligence feeds.
  • Threat scans for FortKnox self-managed deployments: Run threat scans against the data in your air-gapped vault to ensure they are clean in incident response scenarios.

Build and run a threat scan cadence that works for your organization and take a big step forward in your resilience posture.

Practice application recovery in your self-managed deployment

Finding the threat is only part of the job. The Cohesity 5 Steps of Cyber Resilience© provides actionable guidance for strengthening your resilience posture. 

You need to get back to a trusted state as soon as possible when an attack hits. Manual recovery simply takes too long, and costs too much. Those runbooks in a binder, the restore steps stuck in one engineer's head, lead to days of coordination delays while the attack impacts your business.

Cohesity RecoveryAgent replaces manual runbooks with orchestration you rehearse and trust. You sequence restores, validate in a clean room before you reconnect, and cut the risk of dragging a threat back into production. Repeatable workflows give you consistent results—so recovery becomes a practiced procedure, not a scramble. What took days of manual coordination becomes a workflow you run and validate on demand.

Administrators managing air-gapped, sovereign, disconnected environments can now run RecoveryAgent.

Strengthen identity resilience with fully automated Active Directory Forest Recovery (ADFR)

If ransomware or a wiper attack takes down your identity systems, everything upstream stops working. Authentication fails, users can’t log in, and every other recovery effort ends up waiting on your identity systems to come back first. Rebuilding an AD forest manually can take a skilled admin weeks. A single misstep can require a restart of the entire process, or bring a compromised account or backdoor exploit right back.

Cohesity now brings fully orchestrated Active Directory Forest Recovery (ADFR) to the self-managed control plane. Instead of opening a separate ADFR console mid-incident, operators can now run an automated rebuild of an AD environment directly via the Cohesity Data Cloud in the RecoveryAgent section of the console. 

Start by replicating your ADFR backups and server configuration into Cohesity Data Cloud, where they’re held immutably. Recovery orchestration reads from that copy. From there, the orchestration workflow is delivered as two prebuilt blueprint templates (automated runbooks) that run in order:

  • Provision and register: Provisions the ADFR server from a virtual machine template, then register your AD forest using the backup and server configuration that are both held in Cohesity Data Cloud.
  • Deploy and recover: Provision the domain controllers defined in your ADFR recovery plan, install the ADFR agent on each, and recover the AD forest to the recovery point you choose.

Once Active Directory is back in a trusted state, you can work through the rest of your response plan and bring critical business services that make up your Minimum Viable Company back on a foundation you trust.

To learn more about these updates, check out this in-depth blog, here.  

More operational, security, and usability improvements

We’re also releasing useful enhancements to the self-managed control plane to increase speed, bolster security, and simplify day-to-day operations:

  • Disaster recovery: If your control plane goes down, you can bring it back through an active/standby setup, with a predictable recovery time of under three hours.
  • Cascaded replication: Multi-hop replication across sites used to mean writing and maintaining Python scripts. Now you can set up cascaded replication and archive-from-replica policies through the control plane directly, replacing a manual, error-prone process.
  • Configurable data retention: Set expiration dates for data retention in the control plane. This delivers more control over data retention for governance requirements and predictable capacity management.

Get started today

Ready to put these new capabilities to work?

 

Any unreleased services or features referenced in this blog may not be made generally available on time or at all, as may be determined in our sole discretion. Any such referenced services or features do not represent promises to deliver, commitments, or obligations of Cohesity and may not be incorporated into any contract. Customers should make their purchase decisions based upon services and features that are currently generally available.

Written By