Opens in a new tab
vmblog logo 2024 wht (updated)

Cohesity Bets on “Assume Breach” as Frontier AI Models Start Hunting Its Own Code and Agents Become the Newest Workload to Protect

Share: 

David Marshall | Published: October 7, 2026
assume breach frontier ai models

During the 70th Edition of the IT Press Tour in Palo Alto, Cohesity CEO Sanjay Poonen and Chief Product Officer Vasu Murthy explained why the company that holds the world’s backup data has provided its source code to some of the top AI models around, and what it plans to do about the thousands of agents about to land on every enterprise network.

Sanjay Poonen is great at breaking things down into clear and understandable numbers. To that point, at this week’s IT Press Tour, he told a room full of journalists that Cohesity protects roughly 200 exabytes of data for about 12,000 customers. To make that number actually mean something, he put things into perspective and used the Library of Congress as a measurement standard. Two hundred exabytes, by his math, equates to the contents of a million Library of Congresses. Think about that for a moment.

That’s a lot of sediment. Poonen’s word, not mine, and it stuck with me. Every bank, hospital, telco and government agency Cohesity serves leaves a time-stamped layer of its history in immutable backups, layer on layer, like soil. The job is keeping that soil clean and safe. Increasingly, the job is also digging for gold in it.

We spent the better part of two hours with Poonen and Murthy as part of IT Press Tour #70, and the conversation kept circling back to one question: what happens to the last line of defense when the attackers, and the tools used to find holes in software, start moving at machine speed?

Here’s what we learned.

Where Cohesity Stands Today

Before getting into the news, a quick refresher for anyone who hasn’t followed the company closely. Poonen describes Cohesity as a cross between a security company like CrowdStrike or Palo Alto Networks and a data company like Snowflake or Databricks. Protect the data first, then get insight out of it.

The numbers he shared set the stage:

  1. About 12,000 customers, with the focus on the Global 2000. Poonen said roughly 70 percent of the Global 500 are Cohesity customers.
  2. About 200 exabytes under protection, concentrated in five verticals: banks, public sector, healthcare, telco and tech.
  3. About 18 months since the Veritas acquisition closed. Poonen says the two product lines now share one file system underneath and one management plane on top, which he described, in the most memorable burger metaphor I’ve heard at a briefing, as a bun at the bottom, a bun at the top, and a choice of patty in the middle.
  4. A company that is now, in his words, a “profitable growth company” on a path to $2 billion in ARR. He believes it will be the fastest in its space to get there.

On the question every Press Tour member asks (the IPO), Poonen smiled and gave the answer he gives every year. It’s a possibility, advisers are in place, and he won’t name a timeframe.

Handing the Keys to the Super Intelligent Models in Tech

Earlier this year, Anthropic announced Project Glasswing and an unrestricted cyber-focused model called Mythos. Access started with roughly ten companies, and CrowdStrike and Palo Alto Networks were the two security vendors in that first group. Cohesity wasn’t, at least not at first.

Poonen explains why that bothered him, and, more to the point, why it bothered customers. Some of them, including U.S. government agencies and banks, were already getting Mythos access themselves. Their message was blunt. Cohesity is their final backstop. If Cohesity’s code has a hole, and an attacker finds it before Cohesity does, there may be nothing left to recover from.

So Poonen called Anthropic’s CEO, Dario Amodei, and the customers made their own calls. The result, according to Poonen, is that Cohesity became the first company in its space to get access.

Two Approaches, One Goal

What Cohesity did with that access is interesting. The security research team turned Mythos loose on the company’s source code. Meanwhile, a couple of customers (Poonen wouldn’t say which) ran the same model against Cohesity’s compiled binaries, which they have because the software runs in appliances they own. Comparing the two sets of findings told Cohesity how much a determined outsider could find without the source.

Poonen used a hospital analogy, and it worked. If you suspected something on your skin was serious and knew the best scanner in the region was at a hospital in Santa Clara, you’d go there, whatever it cost. Then you’d get a second opinion elsewhere.

That second opinion came from OpenAI (GPT-5.5 at the time, now 5.6 Cyber), then Google’s Gemini 3.5 Cyber, then Nvidia. His early read: Mythos is ahead of GPT-5.6 Cyber for this purpose, with OpenAI a close second. And everything found, Poonen said, is getting fixed.

“I went to the best three hospitals, I looked at myself, and I’m cancer-free. It’s the same way here.”
— Sanjay Poonen

Open Weights and a Very Short List

The Nvidia conversation took a different turn. Jensen Huang’s team is enthusiastic about open-weights models, which matters to European customers building sovereign AI with models like Mistral, and Poonen says Cohesity was the first in its category to back that approach. He plans to test open-weights models such as GLM and Kimi, but with a rule: his first sniff test is whether Amazon Bedrock has certified the model. A new drug, he said, ought to be FDA-approved before you take it.

He also gave us his shortlist of AI companies that matter to Cohesity: Nvidia, Anthropic, OpenAI, Google. Nvidia and Google just so happen to be investors in the company.

And what about the product angle? Poonen confirmed that Cohesity is building new products on top of these adversarial models. He wouldn’t say what, other than stay tuned “in the next few weeks and months.”

Assume You’ll Get Hit

If you’ve followed the cyber resilience conversation for a while, none of this will sound new. What struck me is how plainly Poonen frames it now.

Think of the NIST framework as two halves. The left side is detect and protect, which is where Palo Alto Networks (firewalls) and CrowdStrike (endpoints) live. The right side is recover. Cohesity lives on the right, and it starts from a blunt premise: the attacker will get in.

“Assume breach,” Poonen said. He compared it to earthquake drills in California. Whether you work on the fifth floor of a small building or the 50th floor of Salesforce Tower, you practice, because the elevators won’t work when it happens.

Agentic attacks, he argued, make that practice more urgent. They’re cheaper to launch, faster, and available to gangs as well as nation-states. He didn’t stop at banks, either. Hospital intensive care equipment, power plants, water plants and chemical plants all sit on networks now.

Cohesity’s answer is a multi-step cyber resilience model that covers protecting every workload, vaulting, scanning, recovery in a clean room, and applying lessons back to protection. Poonen calls it a mix of product, practice and people.

The model grew out of conversations with large banks, including some that have spoken publicly at Cohesity events, who asked a very simple question: if the entire bank goes down, what’s the minimum viable bank?

The Brake and the Accelerator

Poonen also pointed us to a Cohesity blog post he wrote in answer to Dario Amodei’s essay, “We Must Pace the Frontier.” Amodei’s argument is that AI capabilities are advancing faster than alignment, interpretability and evaluation can keep up. His plan starts with independent evaluators who get ongoing, employee-like access to the frontier labs, so someone outside can verify how those labs operate.

Poonen’s post doesn’t pick a fight with that. He says he agrees with the principle: the ability of AI to act shouldn’t advance faster than our ability to make it safe, and pacing doesn’t mean stopping progress. His objection is about timing. Companies are already deploying copilots, coding assistants and autonomous agents, employees are already experimenting, and adversaries are already using AI to sharpen their own operations. “Enterprise adoption will not wait for a global agreement on pacing,” he writes.

In the room, he gave us the version with wheels. Slowing the frontier is a brake, and a car with only a brake never leaves the parking lot. Innovation is the accelerator, and it should keep going. But you also want seat belts and airbags, so a crash is something you walk away from.

“Pacing can make the frontier safer. Resilience is what keeps the enterprise running when safety controls fall short.”
— Sanjay Poonen

Safety Is Not the Same as Recovery

Here’s where the written version goes further than what he said out loud. The post draws a clean line between AI safety and what Poonen calls agent resilience. Safety work tries to reduce harmful or unintended behavior. Resilience assumes some failures, attacks and surprises will still happen anyway, and gets the business ready to come back from them.

Think about everything an enterprise already has in place. Governance sets policy. Observability records behavior. Security tools flag anomalies, and people approve the big decisions. None of that puts a business back together after an agent corrupts data, deletes files or rewrites its own memory. “Traditional controls ask whether an agent should be allowed to act,” Poonen writes. “AI resilience asks what happens next.”

He also widens the threat model, and I think that’s the most interesting part of the post. Poonen floats the term “agent-state attack” for multiple agents that discover, decide and act together at machine speed, and he argues that kind of automation narrows the edge nation-states have long held over criminal gangs. But the villain isn’t always an outsider. A fully authorized agent can do real damage because of a faulty objective, poor context, compromised inputs or too many permissions.

His advice is to treat every agent as a privileged identity. That means least-privilege access, short-lived credentials, traceable actions, clear boundaries and a reliable way to stop it. Even then, he points out, a properly authenticated agent can still make the wrong change. Which is why he calls recovery “the control that must still work when an earlier control fails.”

He doesn’t argue for handing everything to the machines, either. Low-risk containment and recovery can be automated, he writes, but decisions with big business, legal or safety consequences should stay in human hands. The post also credits Vasu Murthy with six principles for using agents safely, starting with “humans authorize before agents act” and ending with “the agent itself is now something you have to recover.”

For boards, he boils it down to three questions, which he capitalizes for emphasis. If an AI-related incident disrupts the business, can we RESTORE critical operations to a trusted state? What can our AI systems ACCESS and CHANGE? And how fast can we work out what changed and RECOVER? The answers, he says, should come from tested capabilities, not a policy document. The post closes by pointing readers to a Cohesity Catalyst virtual event for more on its Agent Resilience work.

During the IT Press Tour Q&A, we asked the obvious follow-up. If the internet is the risk, why not disconnect everything? Poonen’s answer was that governments already do it, and Cohesity’s Fort Knox cyber vault does a version of it. The third copy of your data sits disconnected, in a bunker, while the first two copies live in your network. But you can’t run a bank, or the world, without wires and connections. So you get the best of both.

Agents Are the Newest Workload

If Poonen set up the why, Vasu Murthy covered the how, and his half of the session was the part I’d flag for anyone running infrastructure.

Poonen had already planted the idea. An agent, he said, is like a Mini Cooper. A SAP deployment is a bus. You still wouldn’t build a Mini Cooper without brakes. Agents hold prompts, vector databases, MCP connections, and memory. That’s state, which means it’s data, and data is Cohesity’s business. He predicts a world with as many agents as employees, and he said one major tech company told him they already have that.

Murthy built on it with a three-part argument.

Three Ingredients, Not One

First, he said, AI isn’t enough on its own. Agents are flexible but can’t tell instructions from data, which means they can be hijacked. You also need deterministic systems, such as databases, backups and firewalls, that fail in predictable ways. And you need humans, because when an agent makes a mistake, somebody has to be accountable. You can’t put an agent in jail.

Murthy shared a story that I suspect will be repeated at a lot of security conferences. Someone built an agent to triage email. An attacker sent a message with hidden instructions in white text on a white background, telling the agent to forward copies of similar emails to a new address and not to tell the user. The agent complied. Its memory had been corrupted.

How do you fix that? You don’t patch it. You reset its memory, like something out of a science fiction show.

“Agents are extremely flexible. But they cannot be relied on as your bedrock of running your business.”
— Vasu Murthy, Chief Product Officer, Cohesity

What Cohesity Is Doing About It

Murthy laid out three ways Cohesity is applying AI, which I’ve kept to a short list because they really are distinct:

  1. AI inside the product. Cohesity is rebuilding its interface around the five resilience steps, so an administrator can see at a glance whether a backup exists, whether there’s an air-gapped copy, and whether threat protection is on. Then AI helps run it. In a demo, Claude connected to Cohesity through an MCP server, flagged that a payment platform lacked an air-gapped copy, proposed a fix, and waited for Murthy’s approval before turning on vaulting. The confirmation came from the product itself, not from the agent. About a dozen NetBackup and DataProtect customers are testing this model.
  2. Backup for agents themselves. Cohesity has just launched protection for agents on Amazon Bedrock. It discovers the agents, backs up their memory, configuration and access controls, and lets you restore just the piece you need. Murthy said agent memory is small enough to back up roughly every five minutes. There are some 25 agent platforms in play (Bedrock, Vertex AI, Microsoft’s, OpenAI’s, Workato, Boomi and Adobe, to name a few), so discovery is, as he put it, a problem of plenty. Integrations with ServiceNow and Datadog let those tools detect a mass deletion and ask Cohesity, over MCP, which recovery points exist.
  3. Backup data as fuel for AI. The data Cohesity already holds is classified, snapshotted and governed. Murthy’s pitch is to expose it to AI systems with zero copies, through a catalog and semantic layer, rather than building a separate data platform. Cohesity’s catalog connects with Databricks and Microsoft Fabric, and Murthy estimated savings of around 40 percent on infrastructure. A Dutch customer spoke at the company’s Catalyst event about using this approach.

The Uncomfortable Questions

When asked whether prompts sent to Anthropic from the demo are secure, Murthy was candid. Today it’s a trust relationship. Some Anthropic models offer enhanced privacy, but for frontier models like Mythos, the lab monitors usage for obvious reasons. You can’t verify that your inputs aren’t used for training. He noted that in the U.S., anything submitted to an LLM doesn’t carry attorney-client privilege, and pointed to growing interest among large companies in isolated, open-weights deployments.

On identity, he said that today the agent inherits the user’s permissions, which won’t last. Agents will get their own identities with limited rights. Some large customers already say no privileged operation may be performed by an agent, only by a human using a separate privileged account. Considering that someone could simply delete the backups, that seems sensible.

Running the Company on Tokens

One of my favorite stretches of the session came when the conversation shifted to how Cohesity itself uses AI, because Poonen was refreshingly frank.

All of the roughly 5,500 employees get access to an AI tool. Poonen tracks usage the way you’d watch a utility bill. He compared a powerful model to a very expensive light in a room, and he’s the one paying for it. Engineers and security researchers are the brightest bulbs. Coding is done heavily on both OpenAI’s Codex and Anthropic’s Claude Code, and he keeps asking which one engineers prefer. Last year it was Claude Code, he said, and now some say Codex is catching up.

At his own executive table, there’s an empty chair, the thirteenth seat, for an AI advisor. He feeds it documents and asks its opinion. It’s one more whisper in his ear, he said, not the decider.

The workforce message was direct. Poonen told us that when someone leaves, he can replace that person with another person or with tokens, and often it’s both. He tells engineers openly that if they aren’t using AI, they’ll be replaced by someone who does, possibly within months, not years. QA is going to be reshaped first. He pointed to Jensen Huang’s radiologist example, where AI made scans cheaper and more of them got ordered, so more radiologists were needed. He’s optimistic about society overall, though he doesn’t pretend nobody gets displaced.

There was a practical payoff, too. Cohesity has filed a patent on using agents to build its workload connectors. Show an agent how the Oracle connector works, and it gets roughly 80 percent of the SQL Server connector done. A human finishes and ships it. The company’s product rule is quality first, then time, then features, and Poonen says he’ll ship late to fix a vulnerability.

The release cadence reflects it. On-premises software now ships four times a year instead of once. Security and AI releases land about every two weeks, and cloud releases move monthly.

The Rest of the Roadmap

Murthy threw out a few other priorities, and they’re worth listing because several of you are probably living them right now.

  • VMware alternatives. The past year brought heavy investment in OpenShift, OpenStack and Nutanix AHV, with Proxmox coming.
  • Sovereignty and MSPs. Everything Cohesity does can be deployed on-premises, and Murthy said a Dutch customer is running the full stack, with GPUs and Nvidia models, in its own data center. Managed service providers are a big push this year.
  • Quantum. Poonen says he’s watching it closely. With IBM, also an investor, Cohesity has done early work on quantum-safe encryption for the vault.

On the question of what comes after agents, Poonen admitted he didn’t see this wave coming so fast. He’s also watching the cloud-versus-on-premises cost debate return, this time with GPUs and token pricing.

The Takeaway

I’ve sat through a lot of backup briefings over 20-plus years, and the genre used to be about speed, dedupe ratios and recovery time. This one was different. The headline wasn’t a feature. It was a posture.

Cohesity is telling customers that attackers will get in, AI will make it faster, and the thing that determines how bad the day gets is whether the data, and now the agents, can be restored quickly and cleanly. Whether you buy every claim made or not, the logic holds together. Cohesity is putting its own source code through the toughest scrutiny available. It’s building for a world where agents have memory worth backing up. And it’s trying to turn a decade of dormant backup data into something useful.

##