Loading

Cyber resilience for the financial services industry

Overview

For a bank, data is the business and trust is the product. Every transaction, payment, and customer record depends on data that's available, accurate, and demonstrably protected. That dependence is now the primary target: ransomware crews go after backups first, because a bank that can't recover is a bank that pays.

The numbers back this up. Our global cyber resilience research found that 77% of financial services firms suffered a material cyberattack, 87% reported revenue loss, and 93% faced legal or regulatory fallout. Yet only 5% could demonstrate mature cyber resilience. Over 80% of the incidents Cohesity responded to last year involved a compromised identity provider, and the average breach in financial services now tops $5.9M (IBM, 2024).

If you're the one tasked with recommending a cyber resilience platform, this is the gap you need to close. Not just backing data up but guaranteeing you can detect an attack inside your data, isolate a clean copy, and bring the minimum viable bank back online fast enough to satisfy customers, executives, and examiners alike.

Here are the problems you're solving for:

  • Backup-targeting ransomware. Attackers hit recovery data first. Legacy, mutable backups are a single point of failure, and prevention alone is insufficient. 
  • Tightening regulations. NYDFS Part 500, DORA, Sheltered Harbor, GLBA, and PCI DSS all demand provable recovery, MFA, RBAC, NPI encryption, and audit evidence. 
  • Sprawl. Most banks juggle 3 to 5 point products for backup, archive, DR, vault, and search— and data doubling every 18 months means costs and attack surface grow right alongside it.
  • Recovery you can prove. Systems need to come back in the right order, on a schedule you can demonstrate, not hope for mid-incident. 

Key Benefits

  • Increased resilience 
  • Rapid recovery 
  • Superior total cost of ownership 
  • Proven compliance on-demand 
 

Who We Work With

  • Retail, commercial, and investment banks 
  • Credit unions and building societies 
  • Neobanks and digital-first challengers 
  • Capital markets, exchanges, and broker-dealers 
  • Payment processors and FinTechs 
  • Insurers and asset managers 

How Cohesity Data Cloud strengthens cyber resilience for your bank 

The Cohesity Data Cloud is an AI-powered data security platform that converges backup, recovery, threat detection, data classification, identity resilience, and cyber vaulting on one hardened foundation. Instead of stitching together point products, your team manages resilience as a single discipline from a unified control plane—across on-prem, cloud, SaaS, and edge. The portfolio comes together around four outcomes. 

1. Modernize backup and recovery 

The Cohesity Data Cloud accelerates and simplifies protection for core banking systems, trading and payment platforms, customer databases, M365, and cloud-native sources—with global deduplication, policy-based automation, and a single UI. Consolidating silos shrinks both cost and the attack surface you must defend. 

2. Detect threats and respond fast 

  • AI-powered anomaly detection scans data on every backup for the telltale signs of ransomware, so you catch an attack in the data itself. 
  • Threat protection empowers you to detect and investigate threats, so you can reduce your risk from destructive cyberattacks. Cohesity Data Cloud includes industry-leading scanning powered by Google Threat Intelligence and Sophos. 
  • Clean room recovery and the digital jump bagTM help you rebuild your minimum viable bank, even in a worst-case scenario. 
  • Cohesity Identity Resilience (powered by Semperis) recovers Active Directory, the #1 single point of failure in financial-sector incidents. 
  • Cohesity CERT (Cyber Event Response Team) works alongside your incident-response partner of choice when it matters most. 

 

Other vendors require separate management consoles for backing up on-prem and cloud data, which is no better than having separate vendors. With Cohesity, we can centrally manage all data—virtual machines, file shares, Microsoft 365 data—from a single pane of glass. Knowing we can protect any future on-prem or cloud workloads without buying a new solution is even better.” 

— Luke Schwingler, Director of Technology, First Bank & Trust 

3. Isolate a clean copy and reduce risk 

Cohesity FortKnox provides an isolated, air-gapped cyber vault: a last line of defense. It’s backed by a multilayer defense architecture (immutability, WORM, quorum, Cohesity-managed KMS, MFA, and granular RBAC).  

4. Prove compliance to examiners 

  • NYDFS 23 NYCRR Part 500: MFA, configurable RBAC, NPI encryption at rest and in flight, SIEM integration for backup anomalies, automated asset inventory via the Security Center, and Cyberscan vulnerability scanning (with Tenable). 
  • DORA (in force 17 Jan 2025): supports the preparedness, protection, detection, response, and recovery outcomes across DORA’s five pillars, with tested, evidenced recovery. 
  • Sheltered Harbor, GLBA, PCI DSS, GDPR: immutable vaulted copies, data governance, automated retention, and audit logs that speed independent audits. 

Make the economic case 

Consolidation onto Cohesity Data Cloud reduces licensing, rack space, power, and cooling, and cuts the admin hours spent on audit prep. It also lowers the exposure that drives 20–40% year-over-year cyber insurance increases for unprepared institutions. Nationwide replaced legacy data protection with the Cohesity Data Cloud and saved $2M annually while increasing resilience. This is the kind of proof point that anchors an internal business case. 

It’s time to strengthen your cyber resilience with Cohesity Data Cloud  

Legacy backup tools were built to restore files, not to survive a targeted attack. Cohesity Data Cloud aligns to industry best practices, detects threats inside backup data, recovers application-aware workloads in the right order, and keeps a cyber-vaulted copy for the worst case, all at the lowest TCO in the industry.  

Take the next step 

Build your cyber resilience recommendation on evidence. Request a Ransomware Resilience Workshop with Cohesity solution architects, or take the complimentary Compliance Evaluation aligned to DORA’s five pillars and NYDFS technical controls. 

Learn more at cohesity.com/solutions/finance.

Figure 1: our customers
Loading