So AI is moving really fast and when something breaks the impact can spread even faster. Hello, welcome to E Speaks. I'm Corey Knowles. Today we're going to talk about why resilience is becoming essential as AI moves deeper into enterprise operations. Joining me today is Vasu Murthy, Chief Product Officer at Cohesity. We're going to discuss how AI is reshaping risk, why recovery matters just as much as detection, and what it takes to build systems businesses can actually trust at scale.
Vasu, thanks for being here. >> It's great to be here. Thanks for having me, Corey. >> Awesome. Well, we're sure glad. I guess to get started, let's say we'll start kind of broadly. What do you think enterprises are underestimating most about resilience as they move AI from experimentation into production workflows? >> So back in the day in 2007 when cloud was new, nobody thought cloud needs needed backup. Okay? And 10 20 years down the line and now everybody knows and it's actually a big market.
What happened in the cloud is going to happen in AI. Just that it's going to be months and not years. And what really means is if your AI agents are going to be your applications, they need to be protected. They got to be brought back up. If they if something was taken down, you should be able to bring back up and that is resilience. And today in all the noise about experimentation, this is taking a backseat. People are not thinking about it yet.
And as they put these agents in production, as they start doing useful things, this will definitely be something they wish they had already planned for. Or at least they'll scramble to get get this fixed. And so I think that's the most important thing about resilience for agents. >> They sure will because, you know, we see a lot of we see stories every week now where someone's lost everything. >> Yeah, yeah, yeah. In fact, there are there are two sides to this coin, right?
So, agents themselves can be, you know, shut down and you know, you got to you know, you got to bring them back up or they just get corrupted. And of course, the agents create, you know, sometimes chaos at machine speed. Yeah, there are a lot of activity at machine speed, but uh chaos at machine speed and you should be able to recover from them. Both of them is really the other two two sides of the coin of resilience. >> Yeah, 100%. So, how does AI change the nature of operational risk compared with more traditional enterprise software environments? >> Yeah, so two things.
AI operates at extremely faster speeds. So, previously, you know, um I was talking to a a bank in another country, not in the US right now. And turns out every end of the day, there's a reconciliation process happens between all the money that got paid out and all the money that uh got was received and stuff. And still there are people doing it. Uh but imagine if the number of transactions goes 10x. >> Mhm. >> People there, can they do it? No. So, if you're going to have 10x more changes happening in your system, to be able to find something is wrong, it like takes more than people.
It's going to be at machine speed, right? Compounding on that factor is the AI agent is non-deterministic. It is not an algorithm which has specific bugs you can go fix it and then that case never happens again. So, it is non-deterministic and it doesn't really have a very good understanding of people and intentions. So, it is an agent because it has agency. >> Mhm. >> But, it doesn't know our intentions. And so, it will do things that are surprising sometimes.
And so, you now have this probability of things that it will do something you never thought it would. And now it's doing it 10 times faster or 100 times faster. >> Oh, for sure. Well, you've talked about enterprise AI resilience as something that's even broader than cybersecurity alone. What does that framework include and how should leaders be thinking about it holistically? >> People thought of backing up stuff for many reasons. One of them being beyond cybersecurity, right?
So, when people make mistakes, you want to be able to bring the data back. There are natural disasters that bring data center down. You know, 9/11 is the biggest example that got everybody to do disaster recovery drills, even though some banks did it already before that. But, cyber is another dimension. So, you know, holistically should be looking at all the ways that your data or your applications can be brought down, your business can be brought down, and have a plan to how to bring it back.
And that goes into this notion of minimum viable entity or company, which means, you know, what's the minimum business you need to run? And as we talk to customers, we're doing so much more about what that entails. And we need tools to be able to help them do that. And that's why, in fact, there's one more dimension to risk holistically, right? Where do cyber attacks ultimately where do they originate from? And turns out, big set of proper and so nation-state actors.
Now, there are some parts of the world that is kinetic warfare, all right? But, the repercussions of that are actually happening on networks. You know, Striker was attacked you know, from a hacker group that was based in Iran. Right? And so, our businesses are now suddenly in the forefront of the war. It's just happening in the cyber dimension. So, these are all the reasons why the risk profile is way bigger. Yes, cyber attacks are a part of it. There are some It's deliberate nation-state actions that are being done.
There's natural disasters, tsunamis, not even the getters. So, there's the whole bunch of issues that we need to deal with deal with. >> You sure are. A lot of organizations still focus really heavily on threat detection. Why is detection alone unlikely to be enough in AI-driven environments? And what has to happen after detection to restore that trust? >> Corey, great question. I mean, we should absolutely need detection because with millions of attacks happening on enterprises on daily basis, like billions aggregate on a daily basis, if you can't detect them and prevent them, that's it, right?
We're all We'll all be up in smokes. Now, it's very important, but we also need to understand that some of them are going to succeed. >> Yeah. >> Right? And in fact, they're going to succeed at more frequency than before. You know, the time between vulnerability being discovered and being exploited is shrinking. >> Mhm. >> And so, there's going to be more zero day where, you know, and vulnerability is known, but it's not being patched. And so, the risk of a breach is actually higher.
Unless we play defense with agents and, you know, you know, patch to my patch everything plainly and quickly and responsively and use AI for defense, even then, there's going to be some that get through, right? Some that get through. And And when you when they do, they can wreak havoc. I mean, they can just bring the whole business down. And that is why recovery and resilience needs equal amount of emphasis as detection and prevention. We did a survey of 3,000, you know, CISOs across the world.
We found out the spend on detection is actually way more, like I think it's 5x than the spend on recovery. But you know what? There's There's a less than actually it's more than one in five chance in a year somebody gets attacked. >> Wow. >> In fact, 75% of the respondents said they have been attacked and and there was there has been a breach. So, it is going to happen no matter what, you better be prepared to be able to recover. >> That's right.
You've emphasized coordinated signal-driven recovery. What does that look like in practice, especially when AI systems, core data, and automation workflows are all interconnected? >> Yeah, coordinated recovery, right? So, then you want to recover you want to recover first of all quickly a minimum set of businesses. Then we talked to customers, turns out the most important things they want to bring up payroll. Like if you don't pay your people, and they have to do the work. >> That's right. >> Got to pay your suppliers.
You should be able to invoice your customers. Who are the biggest customers? Who are the major customers? What are the critical applications that run your business? So, we need to understand these things. Underlying is a bunch of infrastructure. Take Active Directory or identity for example, that needs to be up uh before anything else can happen. Then you bring the identity, you want to make sure the bad guys are not in there can log in again. Turns out like you know, yeah, incident responders parachute in, they bring up stuff.
And we've had instances where the bad guys logged into the incident response calls. Yeah. Is it Is it Is it like shocking? >> Oh my gosh. >> A lot of companies have this Active Directory recovery. Oh yeah, what is Active Directory recovery? Let's restore the backups of Active Directory you know, from 2 days ago. But turns out they infiltrated like in this case of Striker was in there 41 days ago. Um and unless you know how to detect and and eliminate those credentials, the bad guys are calling in in the incident response, so they can actually get get back in there.
So, that requires coordination. That requires coordination um you know, between the experts that know how to recover AD from the CISOs and the and and the data team that is recovering it. Then you got to bring up the rest of the applications, but even then the applications needs to be malware free. So, you need to find the right copy that doesn't have malware. They have to make sure you bring it up in a clean room, and you can test it and making sure it's all clean, and it's all coming up right.
And then you go recover in production. This requires a lot of coordination and automation. And what we've been doing is helping customers practice this. Right? So, you do a practice this whole thing bringing back, cleaning it up, you know, bringing the applications again, you know, back in a clean room, testing it. That's why That's why we say it takes a lot of requests a lot of coordination. Right? So, you if you have practiced it, you then you know the kind of how it looks like, then you can do um it hopefully sooner and quicker with less uh anxiety uh than you would if you just did it for the first time. >> Yeah, and I think that's that's very important because you know, like you mentioned a few minutes ago with the the patch gap.
I mean, we're going from months and months to potentially hours in some cases. Like, you know, you need to be ready or you could be, I assume, on the wrong end of a stick trying to figure out how to rebuild everything and start from scratch. >> Yeah. I mean, yeah, it's definitely a brave new world, but, you know, everybody's been talking about mythos and chatbots and Open AI is coming with their 505 for security. It can chain multiple vulnerabilities together and go breach.
And so, it's very important for us um to have AI on our side to defend against that. >> Yeah, absolutely. Absolutely. For IT and security leaders who might be listening, what are the foundational capabilities they should have in place before they scale AI more aggressively across a whole business? >> Uh great question, Corey. So, we at any point of time are helping more than a dozen customers cover cover than customers actually to recover from cyber attacks, real attacks.
And we have learned over the years and we've had what's called a five-step framework. And so far, the five-step framework people have been applying for regular um you know, infrastructure pieces like your databases and your applications and files and so on. And the same thing actually applies to agents. So, first of all, you must have backup your agents. Your agents have a lot of state. Uh of course, you got to backup everything in your in your infrastructure.
Number two, you got to make sure the backups are recoverable. Like, how easy that is to say. Of course, your backup can be recovered, but turns out backups are are the first target for any attacker. And so, keeping backups secure and recoverable actually is an open-ended question, right? So, what kind of air gap do you need and where do you put it and how do you make sure it's it's recoverable? And it's a whole theory and practice behind that. Uh we provide cyber vaults to help with such things on from the cloud.
Then you got to still detect and investigate threats. So, there are multiple ways to detect and investigate threats. And so, you got to have the best signatures and and indicators of compromise. You need to have the best scanning tools. And you got to scan the backups. Why? If something happens zero day, it might have happened yesterday. So, you go back into yesterday's backup and see if it was attacked, right? So, how far back? And when you when you you have indication of that, you should be very quickly go and scan your system and say, "Hey, where could this be?" Can we detect it in our backup?
Was it two days ago? Was it in all the Linux systems, Windows systems? So, you need a threat hunting capabilities such that. So, so those So, they're very critical. Number four is really practicing. Like I already talked about that. So, you should be able to then you have all the basic stuff, your data can be recovered, you can detect threats. And you actually found out there was there was actually a breach. So, now you how are you going to recover?
You should be able to practice that including active directory, right? Every from identity onwards, you practice bringing up the whole thing in a clean room and make sure you have a report saying, "Yeah, typically it takes me like 45 minutes to recover these critical apps." Having that, you know, is super critical. The last thing is it is never static. Your environment is constantly changing in the cloud. So, you're going to be scanning the entire environment periodically making sure the you know, sensitive data is not in the right place.
You're backing up everything you should. Suddenly, there's a new application that was launched in the cloud with AI. And are you backing it up? You got to be able to do that, right? And so, this is the this is a continuous loop of actions, and all of that apply to AI agents as much as applies to your databases and applications. So, you should be able to back up AI agents, be able to detect threats in it. Threats for AI actually are much bigger, not just malware, like prompt injection. >> Mhm. >> It could be prompt injection, or that your data gets corrupted.
So, all of this apply to the agent equivalent, and that's what we've been working to get it to our customers. >> It's really Yeah, and some of those are going to be hard problems to solve if if they can't even, like prompt injection. >> They are. >> Is is a real thing. >> Yeah, actually there's an example of a hard problem, right? The example of a hard problem is how do you find out agent made a mistake? Okay? So, agents are operating at machine speed, so you can't have people scanning that.
So, you got to have some automation, maybe some other agent scanning all of that. And when it finds out that it made a mistake, how do you find out the best course of action to fix it? You need another agent to do that. >> Yeah. >> In a way, it's not turtles all the way down. There's probably a human somewhere, but at the at the at the operating speed, you need to be able to detect it, you need to be able to figure out what the plan to fix it, and fix it. >> Yeah. >> And what we've done is look, we are not the only company that can find out all these errors and detect them, but we are the company that can recover them because that's what we're built for.
Like, you know, we we have a copy of all the data, we know what to back up, everything is there with us. And so, we are partnering with everybody, and the major ones like ServiceNow, Datadog, Google, Microsoft, AWS of course given. They're all building systems to put some checks and balances, guardrails. Nvidia, for example, as we use in their guardrails, too. And so, we are using their, you know, anybody who can actually find these errors, hey, here is a way for you to recover from us, but we are the resilience platform, and anybody can really use securely this resilience platform to bounce back. >> Wow. >> So, that's that's our plan. >> I I want to circle back for just a minute to the the minimum viable company concept you mentioned and how that's that's been getting more attention of late.
How does that shift the way organizations think about recovery priorities in an AI heavy environment? >> So, it really brings back to the business. Ultimately, it's a business prerogative. Like if if a CEO finds that the company's down because of a cyber attack, what are the core business components that needs to be up immediately? Why? Because we ultimately it's it's a test of how can the business survive and thrive post the incident? So, whatever is needed for them to survive and thrive.
If it's an energy company, they need to make sure they can still buy the energy and they can still distribute it to the people. They must be able to find a way to bill the people later, pay their employees. And so, defining that is actually a business problem. It's not just a technical problem. Then you find the in a business the infrastructure the IT infrastructure that powers that. And do you should be able to then codify that and practice recovery, right?
When you have AI as a part of the whole thing, it's another component. I mean, I don't think AI fundamentally changes it because ultimately the business needs to run, the application needs to run, people need to communicate, people need to get stuff done. But today, if AI doesn't fit in in that box of things because people don't know how to back up AI. To actually read it somewhere and found out that there are like 12 different places where the AI state gets preserved.
It's in files, it's in a system memory, it is in the system prompts, it is in the credentials and tooling and permissions. And so, there's a whole places. It's not like one thing. Like if a VM I'm I'm bringing it up or the network where you can save the config and bring it up. Today, it's not designed to be backed up and restored well. And so, that is something that we've have putting a lot of effort in They're using AI to build a AI backup tool.
So >> Amazing. That's so amazing. That's very much a time we've reached where where the AI helps build the thing. I guess the best part of it is that the good guys and the bad guys have the tool. At least you have equal weapons. >> We want to have better weapons. The good guys must have better weapons. And on our board we are very proud to have Kevin Mandia. And he has he has started a new startup which actually is making sure the good guys have better weapons and of interest it was super cool stuff.
And it's beyond what I understand. But then Kevin has been one of the pioneers in the cybersecurity industry. And I am so proud to have him on our board. >> That's awesome. So looking ahead as AI becomes more and more embedded in our day-to-day operations with everything we touch, what will separate organizations that scale AI confidently from the ones that struggle? >> Such a good question. I mean we everybody is going through this, right? So I know my job and product's job is not going to be the same as it was last 20 years. >> Yeah. >> Right?
And and we are learning a few lessons in this process. And I think ultimately it comes down to people. Yes, there's an organizational thing, but ultimately it comes down to people. If you have people who are using AI to learn and and really be be able to understand better and to be able to have bigger impact on their own using AI, then you're going to have a successful company. But if you have people who will use AI and delegate to it, you're not going to be successful.
Why I'm saying that? See, ultimately we have to own the output. We provide the intention. Right? We provide the judgment. And ultimately that's what we are here for, to define what to do and to be able to say what is right, what is wrong. AI can do that today. At least today I don't see the foreseeable future. But if you don't exercise a judgment and then there is also a tendency for people to use AI, produce AI slop. And say, "Oh, here's like somebody took a meeting minutes and said, 'Hey, here's the meeting minutes, but it's AI generated.'" As if like I washed my hands of the way, you know? >> Yeah. >> You you go deal with it.
Yeah, here is like a couple of pages of bucket load of stuff you go read. >> And send it to your boss who hasn't read it. >> Yeah, exactly. So that that is the failure mode. Versus yes, AI gets us started really fast, gets me 80% there. But the rest 20% I got to go through line by line and make sure it's mine. Because ultimately we make the judgment call of what you know, what we are communicating and what we are doing. And if we have the intentionality and the judgment, I think we're going to be fine.
Um we're going to learn a lot more. We're going to be the masters of the business with the all the mundane is taken care. It's like you know, somebody said, "Now everybody has this room full of really brilliant interns. They can do whatever you want. What do you have them to do?" So the question is like, "What do you tell them? And how do you check what they did?" Everybody we have to elevate ourselves to this place where we can actually be very critically judgmental.
Judgmental is kind of a interesting way to really put it, but we have to put our taste, we have to put our knowledge of what is right, what's wrong. And and on top of it and then I think we're going to be super successful. >> I agree. I agree. I think that is spot on. Vasu, thank you so much for joining me today. This has been a great conversation. >> Yeah, thank you. It's a pleasure mine. >> Where can people go to learn more about Cohesity and the work you're doing? >> Uh cohesity.com and we have a whole bunch of blogs and follow us on LinkedIn.
We'd love to engage with you, our customers. In fact, we learn so much about what's going on by talking to our customers and so always happy to listen. >> Excellent. So I think a key takeaway from today's conversation is that as AI becomes more operational, resilience becomes a business necessity, not just an IT concern as it has maybe been thought of in the past. We're going to have to pivot. >> Spot on. >> Yeah. Exactly. Well, thanks so much for watching e Speaks everyone today.
For more interviews, enterprise tech insights, visit eweek.com and be sure to like, subscribe, and follow for more conversations with industry leaders. Thanks for watching.
This transcript was generated automatically from the
video's captions and may contain errors.