Infinidat on Cyber Resilience in the AI Era: Rethinking the Role of Storage

A hospital chain across Georgia, South Carolina, and northern Florida lost roughly 25 facilities for three days after a cyberattack, forcing staff to divert critical patients and tell EMTs not to bring anyone in. A credit union in Silicon Valley was down for three weeks. An East Coast city stayed offline for 24 days. Those outcomes happen when recovery takes days instead of seconds, and that's the problem Infinidat built its business around solving.

At The Six Five Summit: AI Unleashed 2026, David Nicholson spoke with Eric Herzog, Chief Marketing Officer at Infinidat, a Lenovo company, about how AI is changing the cyber threat landscape and why storage resilience needs a seat in enterprise cybersecurity strategy.

Herzog's central argument is that AI workloads get attacked exactly like the traditional workloads they're replacing. Cybercriminals go after the data, whether it's flowing through Oracle and SAP or through a newly automated AI-driven supply chain process, and treating AI as somehow immune is a mistake he sees enterprises making right now.

His second point is more specific: storage itself is routinely left out of SOC and SIEM coverage. Security teams watch the edge, the network, and the applications running on top, but the storage layer, including backup, rarely gets the same scrutiny until an attack has already happened.

Infinidat's answer is automated cyber protection that ties directly into SIEM and SOAR platforms like Microsoft Sentinel and IBM QRadar, so a flagged threat automatically triggers immutable snapshot scans without a manual step in between.

When Herzog needed a concrete proof point for what that speed actually buys a company, he pointed to a live demonstration in July where Infinidat recovered 9.8 petabytes of data in four seconds, backed by a guarantee of recovery in one minute or less regardless of data set size. He contrasted that against roughly a decade ago, when recovering even a thousandth of that volume could take up to a full day.

Key Insights:

🔹 AI workloads are not a protected category. Herzog argues cybercriminals target AI-driven supply chain, finance, and HR processes the same way they targeted Oracle, SAP, Mongo, and Cassandra workloads, because the target is always the underlying data.

🔹 Storage is commonly excluded from SOC and SIEM coverage. Herzog says most security operations centers monitor the edge, network, and applications but don't extend that same scrutiny to primary or backup storage until after an attack occurs.

🔹 Infinidat's automated cyber protection connects directly to SIEM and SOAR platforms. When Microsoft Sentinel or IBM QRadar flags a threat, the integration automatically triggers immutable snapshot scanning without manual intervention.

🔹 A live July demonstration recovered 9.8 petabytes in four seconds, backing Infinidat's guarantee of recovery in one minute or less regardless of data set size, compared against roughly a decade ago when recovering a thousandth of that volume could take up to a day.

🔹 Real-world downtime cases make the stakes concrete. A regional hospital chain was down three days and had to divert critical patients, a credit union was down three weeks, and a city on the East Coast stayed offline 24 days after cyberattacks.

Herzog's closing pitch treats data as the one constant across every workload a company runs, which means cyber protection and rapid recovery need to cover AI pipelines and legacy systems like Oracle and SAP equally, not one or the other.

Watch the full video at sixfivemedia.com, and subscribe to our YouTube channel so you never miss an episode.

Catch more Six Five Summit: AI Unleashed 2026 sessions at sixfivemedia.com/summit.

Disclaimer: Six Five Media is for information and entertainment purposes only. Over the course of this video, we may discuss companies that are publicly traded, and we may reference their equity share prices. Nothing discussed during this webcast should be considered investment advice or a recommendation to buy or sell any security. We are not investment advisors, and you should not rely on this content as financial advice. Six Five Media collaborates with technology companies and industry leaders to produce research-driven interviews and multimedia programming for enterprise technology audiences.

Eric Herzog:
We guarantee recovery no matter what size the data set is in one minute or less. In fact, in early July, we did a live demonstration and we recovered 9.8 petabytes in four seconds. No one else can do that.

David Nicholson: 

Hi everyone, and welcome to The Six Five Summit, AI Unleashed 2026. For this cybersecurity spotlight, we'll be exploring how AI is changing the cyber threat landscape and what it means for enterprise resilience. Joining me is Eric Herzog, Chief Marketing Officer at Infinidat. Eric, welcome to The Six Five.

Eric Herzog: 

Dave, thank you very much. We love talking about cybersecurity for all workloads, particularly for AI. And we really appreciate Six Five including us in this virtual event.

David Nicholson: 

Yeah, absolutely. Well, it's not just you that enjoys talking about this, apparently. Every CIO and CTO that I talk to have two things that are top of mind in this era of AI. The first is cybersecurity. The second is tokenomics, if you will. But we're going to focus on that more critical one, cybersecurity, today. If you accept that AI is reshaping pretty much every aspect of enterprise technology, including cybersecurity, How has AI changed the nature of cyber risk? And why should people be thinking differently about resilience?

Eric Herzog: 

Well, the way we view it is AI is a transformational workload. By the way, the cyber criminals know that too. And since you're going to use AI for your supply chain or your finance or for HR, If you're using a traditional workflow and workload software, Oracle, SAP, Mongo, Cassandra, they're going to go after that. So just because you dramatically automated it by using AI doesn't mean they're going to say, oh, it's AI. We won't try to attack it. So they will. Remember, the important thing about enterprise storage whether it be AI or even the old style workloads, it's all about the data and they're after the data. So if they're going to disrupt your supply chain, if you're an auto manufacturer and you're using AI for a supply chain, they're going after that AI workload for supply chain. Just like three years ago, if you were using a traditional workflow with an Oracle or SAP config, they'd go after that too. AI is this incredible transformational tool, but it also means it's another attack vector for them to come after. And some people think that if it's AI, it's somehow impervious to attack. And that's wrong. It's just as subject to attack as all the old traditional workloads were.

David Nicholson: 

Yeah, and those attacks are becoming faster and more sophisticated. So what are organizations doing to move beyond traditional prevention in that case? What are you seeing talking to CIOs and chief information security officers?

Eric Herzog: 

So first of all, the first thing is storage often is overlooked. They look about the edge. They talk about the network. They talk about the servers that are running those applications or workloads. And when you think about the SIEM and the source software or most SOCs, they don't even look at storage. So A is making sure that storage becomes part of your corporate cybersecurity strategy for all workloads, especially AI. That's item number one. Secondly, you've got to do is make sure that you're being proactive. For example, you can use AI and ML technology to scan your immutable snapshots that you take, which mean they're unchangeable, not deletable. So in this case, using AI to help you, right? And you want to make sure that you're really executing cybersecurity on your storage devices. Most enterprise storage is not having cybersecurity done to it until there's the attack. Oh my God, we have to recover this. By the way, when I say the storage, I'm also talking about backup workloads, Dave, because just because using AI to do that supply chain or that finance, you're still backing up the data, right? So they're going to go after the cyber criminals are going to go after when you back up that AI workflow, just the way you'd back up if that workflow was running in SAP. So they're going to attack the primary storage and that secondary backup storage. So you've got to make sure they make comprehensive plans to include both of them so that they get included and you deploy cybersecurity technology in your storage estate, not just in your regular data center, which is what SimSor and most security operations center SOCs do. They don't usually look at storage infrastructure in any way, shape or form.

David Nicholson: 

Yeah, it's interesting you mentioned that because yes, absolutely, storage is usually not the first thing people think of when they think of cybersecurity, but backup, recovery, business continuance have always been part of cybersecurity. And Infinidat has always been involved in this space, but how have you evolved in the face of the changes that AI has brought to the table?

Eric Herzog: 

So I think the first thing is, when we talk to our customer base and our channel partners that work with them, A, you need to be proactive. You need to determine what workloads and what data sources that go into that AI workflow you're going to protect. You set up your immutable snapshots. We do provide the capability with our automated cyber protection that we can integrate with SIMSOR or SOC. So if Microsoft, Sentinel, or IBM create our senses and attack, we can automatically start kicking off snapshots and start scanning those snapshots of those AI workflows. So you need to make sure that you're integrating across your data center and tying storage in. It's done with a simple API. And when the SOC or the SimrSor software sees a threat, we automatically start taking proactive action. There's no text. There's no email. There's no phone call. You just configure it. And as you add more storage, you change it and add that additional storage. If you want to change how you're responding to the SimrSor cyber threat, you can change that. But then once you've configured things or change that config, everything is automated. Again, AI is an automated workflow. In this case, by having the SIEM and source software, the SOC talk to the storage, you're automating that workflow. So that's a very important thing. Obviously, we also provide the capability with our automated cyber detection of when you think you've had an attack, looking for an immutable snapshot that in the storage world is known as the known good copy. So we can set up a fenced forensic environment Whether it be AI workflow or traditional, you set up a fence forensic environment, you bring in snapshots and use our automated cyber detection, which uses AL and MI technology to scan for malware or ransomware or any other anomalous patterns in that snapshot. So then you can do a rapid recovery. We guarantee recovery no matter what size the data set is in one minute or less. In fact, in early July, we did a live demonstration and we recovered 9.8 petabytes in four seconds. No one else can do that. But it's all automated, right? AI is automated. Your reaction needs to be automated. You need to make sure you're doing the right protection. And we would argue that while our automated cyber protection, which interfaces to the SimSource SOC is great, you probably should figure out what data sets are feeding into your AI workflow and taking snaps and scanning on a regular basis. Don't wait for the crisis. Scan twice a week or something like that. We have one customer in the finance sector. They take immutable snapshots every 15 minutes. Now, most companies can't do that. But if you're not taking immutable snapshots of those critical data sets that feed into your AI workflow, once a day, you're making a huge mistake. And you're being reactive. Yes, we integrate with the simmer the soar, but the simmer the soar has to see the threat. And remember, the threats are not King Kong pounding his chest screaming. They're all done like the super, super secret spy, Jason Bourne. Right? Way underneath the radar. That's how they do things. And as you already pointed out, some of the cyber detection consulting firms have pointed out that AI can be used to dramatically accelerate the time. So instead of an average time of an attack taking 22, 24, 26 days, now you could execute in 30 minutes to 60 minutes that cyber attack if you're the cyber criminal. And that's a big deal.

David Nicholson: Yeah, I want to go back to something. Because it's very easy to say you can recover, what was it? Nine something petabytes of data and in what period of time?

Eric Herzog: 

Four seconds.

David Nicholson: 

Okay. So numbers like that are impossible for the human brain to truly understand. It's like when we say, oh, it's a, it's, it's a hundred light years away. What does that even mean? We're not capable of truly understanding that. Let's say 10 years ago, Eric, how long would it take to recover one one thousandth of that amount of information?

Eric Herzog: 

It would have taken as long as a day. And in fact, when you look at people who do cyber in the storage community, most of them talk about taking a half a day to a day just to get to a known good snapshot. It's in their technical documentation. So the fact that we can do it, remember, the question is not if you'll be attacked, it's when and how often. So if you're going to be attacked, your AI workload, your old-style workloads, because remember, they're going to coexist for a number of years. So you're going to have the AI workload over here, the traditional Oracle over here. They're going to attack at all, right? You've got to recover. You don't want to be, and there's been several public things. So there was a city in the East Coast. They were down for 24 days. I happened to be in Silicon Valley. There was a local small credit unit. They were down for three weeks after a cyber attack. That puts you out of business, right? There was a hospital chain, sort of a regional chain in the Southeast, in Northern Florida. And in Georgia and up through South Carolina and they like 25 hospitals, they were shut down for three days. So imagine you need surgery or God forbid you're in a car accident, they have to rush you to the emergency room, and they can't turn the stuff on. Because everything's computerized right the x ray machine. the EKG, the EEG, everything is controlled by computers. So they were down for three, and they were moving critical patients. Not only do they have to tell the EMTs and the fire department, please don't bring anybody to these 25 hospitals, the most critical patients, they had to farm them out to some other hospital, all from a three-day cyber attack. So you really need to be prepared for this. And by the way, most people are prepared for the disaster, right? You and I both live in Northern California. There really are earthquakes. Okay. There really are tsunamis in Asia. There really are hurricanes, right? And of course the most common form of data loss still is fire. Despite all the fire suppression, the sophisticated data centers, fire still destroys more data. Remember when the fire happens, the storage array and the servers that also have storage in them, they're not immune to the fire. It burns it up just like it burns up the walls and burns up the desks. It burns everything. So that's why it's important that you bring cyber to the storage and make sure you're continually doing things like the immutable snapshots. And then when you have an attack, you don't want to be three weeks down. You don't want to be three days down in this healthcare case. And these are all public things that people could Google and they'll see the articles. And I'm not even touching the iceberg of what it costs companies when they're down. And I don't mean just paying the ransomware, but what it takes to get back up. Lost business. Every company is 24 by 7 by 365. Even Herzog's Cigar Store. Right? 365 by 24 by 7. Everything is. So, every time you're down, you're losing money, or you're losing customers, or God forbid in healthcare, you could be losing patients. right? Or critical services, let's say it was the police. Let's say it was all of Northern California and every police department, fire department was down and a fire started in your house or my house. That's a problem because how are they going to get there? You're going to have to drive to the fire station. Hey, can you follow me over to my house? You can't pick up the phone because systems are down. So cyber threats are real and they're going to go after all workloads. And AI is a prime target because it's so new people will think, Oh, wait, maybe I don't need to incorporate. And I don't mean just on the storage side. I mean, just overall. And they let it fly like it's no big deal. And they use cyber for badness on the cyber criminal side, which means everything is accelerated. So it used to take one weeks to months for them to infiltrate. Now they can do it sometimes in 30 to 60 minutes. That is scary stuff, which is why you need to have a continuous protection mentality. And then when you have an attack, you want to have as rapid recovery as possible with good data, because recovering bad data means you just reinfected with the malware or ransomware, right? And that's not going to help you.

David Nicholson: 

Yeah, what's fascinating in all of this is in this sort of era of AI, we focus on this idea that data is at the center of everything. Yeah, we all understand that. But we're thinking about data training models, and we're thinking about hallucinations. And then we think, oh, These models are going to be able to uncover vulnerabilities so quickly. This is a huge cybersecurity challenge. It's a huge cyber threat. People take their eye off of the ball, off of the data ball, which is the storage. layer, the storage realm. And the irony there is that we all accept also that something like 95% of the real value of AI is locked up in private data that can eventually be reasoned over. And so Everyone knows that data is at the center of all of this, but somehow a lot of folks have taken their eye off of the storage ball. As I would say, if you had just a couple of minutes with a CIO or CISO, and they're looking at their security strategy over the next few years, you've already gone through a lot of things that they should focus on, but give me your quick elevator pitch on what you'd smack them across the face with when you've only got seven floors in the elevator worth of their time.

Eric Herzog: 

Is data not the lifeblood of your company? Of course it is. You thrive on data. You manage data. Everything you do revolves around data, including those AI workloads. They pull data, they automate, they think, but they still look at data. They don't just make the data up, which I guess they do, that's hallucination. So if you don't have cyber across your AI workflows and the data sets that feed into those workflows, you're leaving yourself open to a cyber threat. And by the way, the cyber criminals use AI to attack you, just like you're using AI to automate your space. So you need to make sure that AI workflows, all the data sources that feed into those workflows, and in your older workflows that you still have with Oracle or SAP or Mongo or Cassandra, all need to have cyber built into them and rapid recovery built into them to keep your data safe and keep you going.

David Nicholson: 

Eric, there is nothing better than a ride in an elevator to the penthouse with you. I wanna thank you for joining us for this Cybersecurity Spotlight.

Eric Herzog: Dave, thank you for having Infinidat present on Cybersecurity for AI Workloads.

David Nicholson: 

To our viewers, don't forget to hit subscribe, follow us on social media, and check out all our Six Five Summit content at sixfivemedia.com forward slash summit. See you next time.

Speaker

Eric Herzog
Chief Marketing Officer
Infinidat

Eric Herzog is the Chief Marketing Officer at Infinidat, a Lenovo company. Prior to joining Infinidat, Herzog was CMO and VP of Global Storage Channels at IBM Storage Solutions. His executive leadership experience also includes: Senior Vice President of Product Management and Product Marketing for EMC’s Enterprise & Mid-range Systems Division, and CMO and Senior VP of Alliances for all-flash storage provider Violin Memory.

Eric Herzog
Chief Marketing Officer