Cohesity on the New Era of AI-Powered Cyber Resilience
For decades, cybersecurity success has been measured by prevention. Sanjay Poonen argues that scorecard no longer matches the threat environment. Attackers are moving faster, agentic AI is multiplying the ways systems can fail, and boards are asking a more urgent question: How quickly can we recover?
Patrick Moorhead and Daniel Newman speak with Sanjay Poonen, CEO and President of Cohesity, for this Cybersecurity Spotlight session at The Six Five Summit: AI Unleashed 2026, to unpack why business resilience is replacing pure prevention as the industry's defining metric.
Poonen reframes Benjamin Franklin's familiar maxim for the current threat landscape: "An ounce of prevention is as important as a pound of resilience." He walks through Cohesity's Five Steps of Cyber Resilience framework, designed to help organizations restore what he calls a "minimum viable entity." The approach begins with identity protection, adds air-gapped cyber vaulting and threat scanning, and extends through application recovery and security posture management across data and AI.
He also explains how Cohesity is addressing agentic AI risk directly: integrating with agent control towers such as ServiceNow instead of building the control layer itself, using immutable backups to restore data an agent deletes accidentally or maliciously, and treating agents as decomposed applications whose component state also needs protection.
Poonen points to Cohesity's participation in Anthropic's Project Glasswing as evidence of how seriously the company approaches its own security posture. Through the initiative, Cohesity received early access to a frontier cybersecurity model to help scan its codebase and remediate vulnerabilities before broader release. The conversation closes with why data security and data protection are converging into a single operating model as AI increases both the value and the exposure of enterprise data.
Key Insights:
🔹 Business resilience is overtaking prevention as the industry's core metric. Poonen argues recovery speed matters as much as blocking attacks, since no organization can assume it will stop every breach.
🔹 Cohesity's Five Steps of Cyber Resilience framework targets a "minimum viable entity." The steps run from identity protection through air-gapped data copies, threat scanning, agentic application recovery, and security posture management.
🔹 Agentic AI introduces new resilience requirements. Cohesity partners with agent control towers rather than building its own, uses immutable backups to recover from agent-caused data deletion, and now backs up the state of agents themselves as decomposed applications.
🔹 Data security and data protection are converging into one operating model. As AI expands both the value and the exposure of enterprise data, organizations increasingly need visibility, classification, threat detection, protection, and recovery working together rather than as separate functions.
🔹 Recovery speed has become a board-level issue. Poonen points to the gap between what large enterprises like major banks can spend on security and what a hospital or school district can afford, making resilient, well-rehearsed recovery plans essential across every size of organization.
Sanjay Poonen’s closing argument is that the organizations best positioned for what comes next are the ones treating resilience as a practiced discipline, not a hope.
Watch the full video at sixfivemedia.com, and subscribe to our YouTube channel so you never miss an episode.
Check out all of the Six Five Summit: AI Unleashed 2026 content at sixfivemedia.com/summit.
Disclaimer: Six Five Media is for information and entertainment purposes only. Over the course of this video, we may discuss companies that are publicly traded, and we may reference their equity share prices. Nothing discussed during this webcast should be considered investment advice or a recommendation to buy or sell any security. We are not investment advisors, and you should not rely on this content as financial advice. Six Five Media collaborates with technology companies and industry leaders to produce research-driven interviews and multimedia programming for enterprise technology audiences.
-
Sanjay Poonen:
We have to take an assumption that the bad guys have an open source version of that already. The importance of resilience is only growing. You have to assume that you're going to get used. And ask yourself, how fast can you recover?
Patrick Moorhead:
Welcome back to the Six Five Summit 2026. We are unleashing AI, or at least that's the theme of the entire summit. And I think it's pretty clear what the benefits of AI are, but you need to make sure that you are you have the proper governance and you have the proper security to balance out all those benefits. Daniel, this has been a topic all over the Six Five pod and the Six Five Summit. I'm really glad we're talking about it a lot.
Daniel Newman:
Yeah, security is only going to continue to get bigger. We saw there was this wave of sort of belief that AI was going to be security. And I think what we've come to realize is that AI is just massively increasing the size of the attack surface, the threats, the risk. And it's going to, I think, unleash a exponential growth opportunity for our cybersecurity industry. AI could bring some of the fragmentation out of it, as you and I talk a lot about on our shows. But as it brings it all together, we know that keeping data safe, keeping workloads secure, governed, sovereign, security is going to have a big role to play.
Patrick Moorhead:
That's right. Enterprises are really having to rethink the way they think about data protection and recovery. And I am pleased to introduce Sanjay Poonen to help us unpack this. Sanjay is the CEO and President of Cohesity. He's been on the show multiple times. Sanjay, it's great to see you, my friend.
Sanjay Poonen:
Thank you, Patrick and Daniel. Always great to see you and congratulations on the continued success of Six Five. Thank you so much.
Daniel Newman:
It's been great. And yeah, you've been with us Sanjay over the years. I think, you know, we've got a half a dozen of these summits now in the books and you've done a number of them. And of course, you've been on the show many times over the years. It's been great to watch Cohesity grow. We'll continue to track that. So let's start off talking a little bit about, you know, cybersecurity broadly, right? We've spent decades building cybersecurity really around prevention, but the reality is, you know, we're not going to stop everything, right? We've gone in these waves of trying to stop everything to knowing they're going to break in, but maybe only letting them break in so far. And then how do we handle the threats, resolutions, get back, but like, you know, we are measured this industry by how well organizations can prevent attacks, but that's not realistic. So talk about security, business resilience, and why that maybe is a better measure of success.
Sanjay Poonen:
Yeah, Daniel, I would say I'd adapt the Benjamin Franklin line a little bit and say the following. A ounce of prevention is as important as a pound of resilience. So if you think about the NIST framework, the NIST framework has detect and prevent on the left-hand side and recover, remediate on the right-hand side. And an entire industry of these great security companies like CrowdStrike, Palo Alto, Zscaler and others have focused on the left-hand side, whether it's the endpoint in the case of CrowdStrike or the firewall in the case of Palo Alto or web gateways like Zscaler. That's all detection prevention. We need those. That's sort of the ounce of prevention. But in the mythos style, post mythos world, an agentic attack is going to come at us in a more deadly fashion and a faster fashion. So everything, you know, Entropiq's doing a good job. We're part of Project Glasswing. Some of our customers have been testing our code with binaries when it started. So we're well inside the tent on what we see with these incredible models. And Anthropic and the U.S. government has protected that from the outside world. But we have to take an assumption that the bad guys have an open source version of that already. So if that attack's going to come at you faster, the importance of resilience has only grown. You have to assume that you're going to get breached and ask yourself, how fast can you recover? The pride of our platform has been speed of cyber recovery, supersonic speed of recovery. So what we've kind of spent a lot more time now is that, coming back to the Benjamin Franklin line, the pound of recovery. and resilience, and how do you think about the framework for cyber resilience? We have a five-step cyber resilience. We'll talk all about that on your show today. But that has now become of even more paramount importance, because if you think of some of the critical infrastructure in the United States, banking, utilities, hospitals, things of those kinds, some of them have a fairly heavy amount of spend in security. For example, JP Morgan publicly stated, I think their budget's $17 billion. They spend the highest of anybody in security of any bank. But a hospital or a school district can't afford that. We have to keep this country safe, and in the same way, we've got to keep the entire world safe.
Patrick Moorhead:
Yeah, it's interesting. I feel like we're in the fourth inning of security and data protection. First inning was perimeter defense. The second one was, you're going to get in, but we're going to get you out quickly. And the third was, we know you're going to get in, we're going to try to get you out, but we may not. Let's limit the damage. that you're doing, and that's some of your success that really delivered on the third inning. Fourth inning is all about speed and scale, right? And AI really accelerates that. Where do you see AI making the biggest difference for organizations too? As you look at, you always have to have an economic reason for people to come in, for both attackers and the defenders.
Sanjay Poonen:
Well, Patrick, I'm glad you used a baseball analogy because in cricket, there are only two innings and baseball, there's nine innings. So yes, we might be in the second or third or fourth inning of a baseball game. Yes, we're the early innings of cyber. As you well point out, I don't know if it's the middle innings or nearly, but it was certainly not in the end game because there's so much more. And you just go to some of these big shows like RSA, you'll see how innovation is continuing to flourish. Our view is, just like any other major invention in the history of mankind, whether it's the discovery of fire, or the discovery of electricity, or the electric engine, or electricity, there's an offense and a defense. There's good and bad in this. And we have to think about AI in just the same way. How are we using our offense to make us better people, better society, save lives, productive? And what are we going to do on defense to protect it? Fire can be used as an incredible part to keep us warm, to cook, but can also tear down and arsonists can use it to basically tear down buildings. So how do we think about it on offense? We were one of the early adopters, but I talked to CEOs and asked them every single time, you know, Fortune 500 CEOs, I'm on the board of Philips, we examine how can we use AI to help our employees be more productive? And in the case of MedTech and biotech companies like Philips, how can we save lives? We're very excited about that. So if you think about, we were some of the first in our industry to adopt AI in a whole scale way in engineering, typically for a software company, engineering and sales and marketing are the big places we adopted Cursor. Now we're all in on Cloud Code. We are actively involved with Anthropic, OpenAir and Google because they are the three primary frontier labs. And then sort of finding out how they play out in the public clouds, AWS, Azure and Google. And, you can go department to department. In my company, All Hands, I feature often every functional department, and I pick a leader to demo how they're using AI to make them productive. And, you know, you'll get the head of HR talking about how an AskHR chatbot now is being helpful to help you get faster information and benefits. Our support team was one of the first teams to adopt it because the support teams are always full of knowledge bases, and it's a perfect problem for generative AI to search those and summarize it and give it not just to our support engineers, but to customers directly. Engineers, obviously, are productive. I'm talking to some of our best engineers, and you know the foundation of this company are folks who came from companies like Google, some of the best of the best. I'm watching them setting off multiple agents, setting their jobs done. And now when they may have had junior engineers doing some of that work, it's now being done by agents. Now let's talk about the bad and how we protect that comes to where Cohesity plays. We think about agents in a couple of ways. One is they could maliciously or, you know, to accidentally delete data. And we announced in February, March, earlier this year at our Catalyst event, a partnership with companies like ServiceNow that have an agent control tower that become the place where you register, manage, secure, observe those agents. We don't need to be the agent control tower ourselves. Some of our competitors are trying to do it. We think that's a mistake. But we partner with the companies like ServiceNow who have an agent control tower. Amazon, Google, Microsoft, and others are also doing that. And then when that agent does something malicious and it detects, it sends us a signal, which we've tightly integrated with the agent control tower. And if you think about immutable backups, like what we do, it's just a historical copy of everything you've had for the extent of time. In many cases, at banks, it's forever. And if it deleted data today, it might be a Wednesday. We get you yesterday's copy or however frequently you had that. That's an example of being able to take care of a malicious or an unintentional error that an agent made. We're starting to see these types of agentic mistakes where data deletion becomes the outcome that we want to prevent. But an agent itself, the second part of what we can do on defense, is an agent itself has state. If you think about a big application 30 years ago, it was the company I worked at, SAP, a big application. It had HANA, it has NetWeaver, it has many of those components. An agent is just a smaller application that has state. It has a vector database, it has the MCP servers. We've decomponentized an agent into 10 or 12 subcomponents, and we've now built the resilience of that, or a backup of that agent. So those are some of the ways in which we are practicing offense and defense in this agentic area. And then a final thing I would say is, and we can talk more about this if you'd like, being very close to Anthropic and Mythos and being one of the early participants in Mythos preview, we were in the second wave. The first wave were these 10, 15, 20-odd companies, including NVIDIA, JP Morgan, CrowdStrike, Palo Alto. We were in the next wave of about 100 companies. And now we're able to, it's like getting a high intense scan of your body. in a very radioactive place, only a few people should go in there. But we're now able to both binary scan our code, which our customers can do, but then source code and guarantee to our customers, we have the most vulnerability protected software in the industry. That's very powerful. And we think it is wise for those models to be guarded so the bad guys don't get to them.
Daniel Newman:
Well Sanjay, you covered a lot of ground there and definitely it's great to hear from those that are close to the most, we'll say close to the frontier. This has caused a ton of stress for every business right now and every leader. And as you suggested, it's no longer just a CISO challenge, it's at the board and it's at the CEO. So let's talk about a different shift though. AI is forcing companies to think much more seriously about the data itself. Right? Where it is, who can access it, how it's protected, you know, data security and protection are basically converging into a single operating model. And I think that's something you've talked to us about a lot over the years, but why is this the moment? Like you said, you've talked about it, but it seems to really be happening now, you know, AI fueled.
Sanjay Poonen:
Yeah, I think that if you think about, we have a framework we pioneered called the Five Steps of Cyber Resilience to achieve what we call a minimum viable entity. And what we mean by a minimum viable entity is if you assume you're going to go down completely, let's say a bank or a federal agency, what do you do to recover your organization or your company? Hence the term entity. And I think, yes, if you think about that, the number one thing we talk about there is, for example, protecting your identity infrastructure. That's so important because once your identity goes down, you don't have email, you don't have your directory infrastructure. But many of the other sub steps are security steps. For example, threat protection, cyber vaulting, security posture management, and hence this sort of blurriness now of data protection and data security. They're very similar verbs, protection, security, they're similar things. So quite frankly, to the CEO on a board, they may not know the subtlety of data protection means immutable backups and so on and so forth, and security means many of these other more sophisticated things. Are you taking care of my data and protecting me from the bad guys so I'm safe? So we tend to, as we talk to certain CEOs, but even inside IT, typically we, underneath the IT, have an infrastructure person, a security person, and then the third person that's emerging, an AI officer, a CTO, a CISO, and a chief AI officer that we have to sell to. So that blurriness of protection and security, Daniel, I acknowledge is actually happening, and it's to our advantage. And then as you think about many of these areas, this topic was sort of an infrastructure, maybe a storage topic 20 years ago. And it's now transformed into something because of resilience, because of cyber attacks, whether it was Colonial Pipeline or SolarWinds or any of the MITOS type attacks that people think about. Every large Fortune 500 organization at the board level in the United States, but I know outside the United States too, is absolutely scared that one of those headlines that came in the Wall Street Journal and New York Times about some other famous company could happen to them. And they want to make sure, especially the audit committees inside those boards, because I've served on them, We want to make sure that there is a cyber component on every audit committee that's ensuring that they are advising and governing to ensure that their firm stays out of the headlines.
Patrick Moorhead:
So Sanjay, it seems pretty clear that in the age of enterprise and genetic AI, we really are looking at it at a different model there. And it kind of feels like we say that every three years. And I think that that's, that, that is valid because, um, things are changing so quickly. It seems like, you know, once every month, uh, we seem to be moving here and the, and the rate and the pace of change is truly is, uh, accelerating. And that's not a. a marketing point here, but let's try to simplify this. How would you define the organizations that are best prepared for the next generation of cyber threats? Maybe this is a checklist for the board of directors that to simplify this, it needs to check all the boxes.
Sanjay Poonen:
Yeah, I think it's exactly that five-step cyber resilience framework that achieves a minima via entity. So I'll cover them very quickly, but we have an entire website and we have a sort of a cyber event response team, we call it CERT, that helps people in a small consultative study and then eventually, of course, leads to them implementing our products. Number one is to protect all your workloads, but the most important of that is identity. That's number one. Step number two is to have three copies of your data with the third copy being a cyber vault that's disconnected from your network. We call that air gap. Number three is to threat protect, scan, protect all those to assess that there's any sleeper cell malware sitting in that first, second, or third copy of data. Number four is to practice application recovery in an agentic fashion, hopefully, across your applications, not just agents. And number five is security posture management of your data and AI. So what does that mean? You're looking for classified information, and you want to know, is that information got personal information, PII inside it, or is it data that you don't care about? Sometimes that step five is actually step one, and then the entire cycle repeats itself. So that five steps I described, we have a methodology around it. We invented it. We described this to customers. Now, of course, there might be variants of this that other consulting firms and so on also. But those five steps distill down what we think are the necessary steps to create a minimum viable entity if you get hit. And then we come back to where I started off our dialogue at the beginning of the show, which is assume you're going to get hit. And then you want to tell your board, if we get hit, Here are the applications. Maybe we have 100. In the case of some of the banks, they have 5,000 or 6,000 applications. Here are the applications that need to come back in an hour. Here are the applications that need to come back in a day. Here are the apps that can come back in a week. And here are the apps that can come back in a month. You segment all your applications in that fashion and make sure in a practice rehearsal, think of that just like you're practicing fire drills or earthquake preparedness. You practice what happens in a cyber attack and how do I ensure, you may not be able to do all your apps, but at least the apps that need to come back in an hour a day, you've rehearsed them to ensure, maybe not at the grand scale of the entire bank going down or the entire federal agency going down, but you simulate it. and ensure you're ready for that, hopefully, day that never happens. But then you can go and tell your board, if it does happen, we've practiced this, we're ready, and here's how we get back on our feet in supersonic speed.
Daniel Newman:
Well, Sanjay, hyperscale and hyperspeed, right? And so we're going fast. And of course, every company wants to embrace and take advantage of all of these technologies. making sure it's secure, making sure you can bring all your applications back online and knowing that it's more likely an if, a when than an if when it comes to whether or not a breach is going to happen. And obviously AI is only making that an exponentially bigger challenge, but opportunity for you and the industry to solve. So I want to thank you so much for joining us here for this cybersecurity spotlight session at the Six Five Summit 2026 AI Unleashed. Look forward to having you back in soon.
Sanjay Poonen:
Thank you, Patrick and Daniel. There were other topics like Maestro I didn't get to cover, but please read our website. There's a ton of innovation that we've announced in recent days and weeks. I really appreciate the opportunity to join you today.
Daniel Newman:
I hear Sanjay, an opportunity for your team and our team to figure out when we do the next interview. Let's do it again. And everyone out there hit that subscribe button. Follow us here on social media. Check out all of the Six Five Summit content, sixfivemedia.com slash summit. See you all here soon.
Speaker
Sanjay Poonen leads Cohesity as Chief Executive Officer and President, driving the company's mission to protect, secure, and provide insights into the world’s data so that the largest organizations in the world can rely on Cohesity for their resilience. A proven business executive with more than 25 years of experience scaling multi-billion-dollar enterprises, Sanjay brings a rare combination of technical depth, global sales leadership, and strategic vision to Cohesity.
Prior to Cohesity, Sanjay served as COO at VMware, where he oversaw sales, marketing, services, and alliances—helping double the company's revenue from approximately $6B to $12B. He was instrumental in architecting VMware's landmark cloud partnerships with AWS, Microsoft, Google, and Oracle, and led the End-User Computing business, including the acquisition of AirWatch. Prior to VMware, Sanjay served as President of SAP, leading Applications, Industries, and Platform teams across engineering and sales, contributing to growth from approximately $10B to $20B in revenue. He began his career as a software engineer at Microsoft and Apple.
Sanjay serves on the Supervisory Board of Philips and the Board of Snyk. He holds two patents, an MBA from Harvard Business School (Baker Scholar, top 5%), a master's degree in Management Science and Engineering from Stanford University, and a bachelor's degree in Computer Science, Math, and Engineering from Dartmouth College, where he graduated summa cum laude and Phi Beta Kappa.


