This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

From Disruption to Breach Recovery: Closing Gaps in Cyber Resilience

Download resources

About this session

Mike Preston, a staff technical marketing architect at Rubrik, argues that despite years of rising spend on perimeter security, attackers keep getting in, so recovery deserves as much investment as prevention. He explains why a 'cyber RTO' differs from a traditional backup restore: responders must scope an attack, find the point of infection across on-prem, cloud and SaaS, assess sensitive-data impact, and confirm backup data is clean before restoring it, since reintroducing malware causes reinfection. He positions Rubrik as a converged, API-first, zero-trust platform with immutable backups that layers anomaly detection, sensitive-data classification and a Mandiant-fed threat-hunting service on top of standard backup, plus a newer identity-resilience module mapping Active Directory and Entra ID risk to MITRE ATT&CK. A colleague, Jean, demos locating malware-infected files and exposed sensitive data within seconds, scanning nineteen thousand backup snapshots for a zero-day signature in about two minutes, agentless VM backup, SharePoint coverage, and granular Entra ID recovery, closing with audience questions and named references to CIBC and BMO as customers.

Attackers only need one gap to get in—and when they do, the clock starts ticking. Every minute counts as ransomware spreads, identities are compromised, and business grinds to a halt. The difference between containment and catastrophe comes down to removing threats quickly and recovering with confidence. To combat this escalating threat, a truly cyber-resilient solution is imperative. This session will explore how Rubrik helps security teams close that gap by combining robust data protection with cyber recovery and identity resilience. We’ll cover how immutable recovery points, anomaly detection, and integrated threat intelligence accelerate investigations, while monitoring and restoring identity systems like Active Directory and Entra ID prevents reinfection and restores trust. Join us for a live demonstration of the Rubrik platform. You will see firsthand how aligning recovery with security operations strengthens defenses, shortens attack timelines, and ensures your organization can bounce back stronger from ransomware and insider threats.

Key takeaways

  • Before restoring after an attack, confirm the backup point you are recovering from is clean; restoring backups that still contain attacker tools or malware causes reinfection.
  • Define a 'cyber RTO' separately from your standard RTO: it must account for scoping the blast radius, finding the point of infection across on-prem/cloud/SaaS, and assessing sensitive-data impact before recovery even starts.
  • Extend backup-time scanning to cover both known threats (IOC/YARA feeds) and zero-days by re-scanning historical snapshots retroactively once a new signature becomes available.
  • Treat identity systems (Active Directory, Entra ID) as a recovery target in their own right, with visibility into stale accounts and near-real-time tracking of privileged changes, not just as a byproduct of data backup.
  • Test your Active Directory forest recovery process before you need it; Microsoft's own guide runs about 150 pages and is described here as error-prone under pressure.

Speakers

Mike Preston
Mike Preston
Staff Technical Marketing Architect · Rubrik
Mike Preston is a Staff Technical Marketing Architect at Rubrik who enjoys all things coding, writing, and speaking. Prior to Rubrik, he spent 15 years in operations where he strived to automate and orchestrate as much as possible. With formal… Read moreRead less

Mike Preston is a Staff Technical Marketing Architect at Rubrik who enjoys all things coding, writing, and speaking. Prior to Rubrik, he spent 15 years in operations where he strived to automate and orchestrate as much as possible. With formal education focused on development, coupled with his operational experience, he strives to bridge the world between development and operations. He blogs on blog.mwpreston.net as well as various other tech-related news sites. He is the Toronto VMUG Leader, a VMware vExpert, and the author of Troubleshooting vSphere Storage. You can find him on Twitter @mwpreston talking about all things tech, hockey, and maple syrup!

Resources

Tags

More from GoSec 2025

Also from Mike Preston

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.