Stopping Ransomware with Cyberstorage
Download resourcesAbout this session
Eric Bednash, co-founder and CEO of RackTop Systems, argues ransomware persists because defenders suffer 'inattentional blindness', focusing on one area and missing the rest. He dismisses typical five-step ransomware checklists and uses a double-dutch counting video to show how attention on one task hides everything else. Mapping CISA's zero-trust maturity model, he stresses that its fifth pillar, data, is routinely neglected: dividing infrastructure into five buckets (applications, end users, networks, primary unstructured data, backups), he shows MFA protects only two-fifths, network and endpoint tooling three-fifths, and backups only one-fifth, offering recovery not prevention and nothing against data theft. He positions cyberstorage, the Gartner-coined category RackTop pioneered, as active security embedded in storage that profiles user and machine behaviour over NFS, SMB and S3 to detect exposure, destruction, manipulation and theft. Framing data as a continuum across the NIST CSF functions, he plays two silent demos: one surfacing apps running as privileged accounts and insider snooping, another stopping a ransomware attack in under a second, disconnecting only the offending user while others keep working, then one-click restoring files. A detailed Q&A covers data theft versus denial of service, detection mechanics, AI versus machine learning, and disk-level attacks.
Ransomware has become the top concern among security and IT professionals, however solving for that challenge remains elusive as ever. With over $40B in damage caused in the last two years alone, legacy approaches are falling short of mitigating the risk. Edge and endpoint solutions have limited visibility into enterprise data operations, and data protection and backup providers promoting recovery mechanisms like immutable backups typically fall short of complete and timely service restoration. And with new, more destructive strains on the rise, what little impact observer and recovery-based solutions have will quickly soon be neutralized. Cyberstorage is a new approach to solving data centric security problems through active security mechanisms embedded in the Enterprise data plane. This talk introduces the concept of an active security Enterprise file storage system, and how this type of solution can be a simple and effective answer to the Ransomware problem, both today and for the future.
Key takeaways
- Do not equate MFA or network tooling with zero trust; map defences against all five CISA pillars and note that the data pillar covers the 70 to 80 percent of unstructured data attackers actually want.
- Treat backups as recovery, not prevention: they address only one-fifth of the infrastructure and do nothing against data theft, which is the fastest-growing ransomware outcome.
- Add active security at the data plane that profiles normal user and machine behaviour over NFS, SMB and S3 so exposure, destruction, manipulation and theft are detected quickly, not days later from SIEM logs.
- Design for cyber resilience: isolate only the offending user or host during an attack instead of pulling the plug on everyone, so the business keeps operating.
- Audit for enterprise applications and users running with privileged or root accounts on shared data stores; this common hygiene gap is what attackers target to steal data unseen.
Speakers

Eric Bednash is a founder and Chief Executive Officer of RackTop Systems, an innovative data security company who pioneered the fusion of active threat defense and detection into a unified file storage platform, an emerging market known today as… Read moreRead less
Eric Bednash is a founder and Chief Executive Officer of RackTop Systems, an innovative data security company who pioneered the fusion of active threat defense and detection into a unified file storage platform, an emerging market known today as Cyberstorage. A passion-driven entrepreneur and innovator, Bednash brings to his position more than 20 years of experience in the cybersecurity sector, where he designed specialized data security products for the U.S. Intelligence Community, Department of Defense, and commercial enterprises. Bednash co-founded RackTop in 2010 with a simple vision – to enable any organization to protect their data as if it were a national secret. Through his leadership and inventions, he has led the creation of a platform to arm companies with a simplified solution to the most complex Enterprise data protection challenges. RackTop’s technology has been leveraged by numerous organizations spanning a wide variety of global industries – notably in government, energy, financial services, healthcare, higher education, media/advertising, and entertainment. Prior to 2010, Bednash served as co-founder and Chief Technology Officer of Ross Technologies, a mid-sized consulting firm in the Government IT services space focused on developing mission data systems for the U.S. government and held numerous technical leadership roles as a contractor within the National Security industry. He started his professional career specializing in data center systems for Time-Warner Corporation and spent the better part of the dot-com boom in Washington, D.C., where he consulted businesses on the new and expanding internet era. Bednash is a Forbes Technology Council member and a contributing writer for VentureBeat, among other publications, and an Advisory Board Member of Mission Link Next, an exclusive organization focused on accelerating innovation and advancing solutions to solve national security threats. He attended Rochester Institute of Technology, Penn State University and Stevenson University, completing both undergraduate and graduate coursework in Business and Technology Management. He resides in Fulton, Maryland with his family, and is an avid musician and wine collector.

