Cyber Resilience in the AI Era: Why Machine-Speed Attacks Demand Machine-Speed Recovery
Download resourcesAbout this session
Serge Dansereau, senior sales engineer at Rubrik, uses a hypothetical Quebec manufacturer whose warehouse cannot ship after an incident to argue that cyber resilience must be rehearsed, not assumed. Referencing a 27-second reported average breakout time and OpenAI's classification of a recent frontier model's cybersecurity capability as a critical threshold, he argues AI compresses attacker timelines faster than most recovery plans account for, particularly once AI agents with broad tool access and privileged credentials are added to an environment. He works through the mechanics of recovery at scale, using a toy math example (1,000 servers, 30 daily snapshots) to show how scanning, restoring and validating backups can consume more time than expected, and introduces the idea of a minimum viable business: a single, traceable transaction (an order becoming a shipment) that proves a service is genuinely usable again, not just technically restored. He stresses testing recovery during normal operations rather than during a real incident, naming clear service owners, identity dependencies and evidence requirements in advance, and closes with customer examples of faster reporting and scanning using Rubrik's platform.
AI is transforming the network, and we're transforming the firewall to secure it: The Firewall As Part of the AI Defense Plane.
Key takeaways
- Define a 'minimum viable business' transaction per critical service (e.g. an order becoming a shipment) as the actual finish line for recovery, not just backup restoration.
- Test recovery during normal operations, not for the first time during a real incident; run the exercise with the service owner, identity owner and infrastructure owner in the room together.
- Account for AI agents' effective access through connected tools when scoping recovery, since a limited-looking integration can reach far more privileged resources than expected.
- Budget real time for scanning and validating backups at scale; the number of snapshots and systems involved can make recovery far slower than assumed.
- Keep identity recovery in scope alongside data recovery; restoring an identity system before checking for a compromised privileged account can reintroduce the attacker's access.
Speakers

Serge Dansereau is a Senior Sales Engineer at Rubrik, covering the Quebec territory. With over 25 years of enterprise IT experience, Serge has built his career at the intersection of technology and trust, helping organizations protect their data and… Read moreRead less
Serge Dansereau is a Senior Sales Engineer at Rubrik, covering the Quebec territory. With over 25 years of enterprise IT experience, Serge has built his career at the intersection of technology and trust, helping organizations protect their data and business continuity. He serves as the technical quarterback for Quebec enterprises navigating cyber resilience, translating complex technical solutions into real business outcomes for CISOs, CIOs, and IT leaders. His path has taken him through some of the most respected names in data protection and cybersecurity, including Druva, Commvault, EMC, Arctic Wolf, and Microsoft, giving him deep insight into how enterprises protect their environments, recover from attacks, and meet regulatory obligations. Bilingual in English and French, Serge is also a musician, playing keyboards and guitar in two bands, including LoveCat, a Cure tribute band — bringing creativity and curiosity to every customer conversation.

