As Black Hat USA 2026 approaches, one theme keeps surfacing in conversations with security leaders: the identity crisis brewing inside enterprise AI deployments. Organizations are rolling out autonomous agents at a breakneck pace, often treating them as software rather than accountable actors with their own identities — a gap that leaves security teams unable to detect anomalous behavior, audit incidents, or recover cleanly when something goes wrong. To dig into this and other pressing issues heading into Las Vegas, VMblog caught up with Dr. Joye Purser, Global Field CISO at Cohesity, ahead of the company’s debut as a platinum sponsor at this year’s show.
In this exclusive pre-show Q&A, Purser unpacks why resilience — not just prevention — has become the defining discipline in cybersecurity, and why nearly every CISO she talks to now names agentic AI as a top-tier risk. She also shares hard data from the front lines of incident response, including why re-infection occurs in roughly half of post-incident recovery efforts, and what organizations still get wrong about network isolation and threat actor removal. From post-quantum cryptography timelines to the realities of software supply chain trust, Purser offers a candid, experience-driven look at what’s keeping security leaders up at night — and what attendees can expect at Cohesity’s booth #4543, including live demos, executive meet-and-greets, and a lineup of Black Hat week hospitality events.
++
VMblog: For readers who may not be familiar, give us the elevator pitch — who you are, what you do, and what genuinely sets you apart in today’s crowded cybersecurity market.
Dr. Joye Purser: Cohesity helps organizations protect, secure, and get more value from their data. We started by solving one of enterprise IT’s hardest problems: protecting data at scale. Today we offer an AI-powered data security platform that helps organizations strengthen resilience, speed recovery, and reduce IT costs. Our experience in real recovery scenarios is a major part of what sets us apart. We know what is at stake when critical systems go down, and that perspective is why banks, communications providers, hospitals, and other critical infrastructure organizations rely on Cohesity as a trusted partner. Today, Cohesity serves customers in more than 140 countries, including more than 70% of the Fortune Global 500, with a secure-by-design platform built to scale across on-premises and cloud environments.
VMblog: Black Hat attendees are a discerning crowd. What booth experiences, live demos, or hands-on activities are you bringing to Las Vegas that will cut through the noise and leave visitors with something they can’t stop thinking about?
Purser: The need for cyber resilience has never been more urgent. Five Eyes, the intelligence alliance that includes the United Kingdom, Canada, Australia, New Zealand, and the United States, recently declared that in the age of Frontier AI, “cyber resilience is integral to advancing business continuity, market confidence, and long-term value.” At Cohesity’s booth #4543, attendees can stop by for hands-on live demos of our cyber resilience solutions including: Threat Protection using Google Threat Intelligence and Sandbox Analysis, data isolation and recovery with Cohesity FortKnox, and cyber recovery orchestration with Cohesity RecoveryAgent. On-demand recorded demos covering identity resilience powered by Semperis and the Cyera integration with Cohesity DataProtect will also be available at the booth.
Cohesity leaders will be on hand to dig into customers’ toughest challenges. In addition to myself, Cohesity executives who are attending include: Brian Spanswick (CIO), Swami Ramany (GVP Product Management), Aditya Vasudevan (GVP Customer Cyber Resiliency Services and head of Cohesity’s CERT), and Rob Sadowski (VP Product & Solution Marketing). Beyond the booth, join us for a Happy Hour with Google on Wednesday, Aug. 5 at Swingers (Mandalay Bay), the Neat & Secure CISO Reception with Cyera (Four Seasons Penthouse), and the Agent Ready After Party at Eyecandy Bar & Lounge (Mandalay Bay). For more details on these activities and to request a meeting before the show, please visit here.
VMblog: What’s your Black Hat origin story? Longtime exhibitor or fresh face on the floor? What keeps your company coming back — or what made 2026 the year to finally plant your flag here?
Purser: This is Cohesity’s first year as a platinum sponsor. Yes, Black Hat originally was “a hacker conference,” but we believe that effective countermeasures need to be visible and in the room. Understanding how threats evolve helps us keep our products and platforms two steps ahead of that threat, so we study the threat landscape carefully.
VMblog: If a CISO walks away from your booth remembering exactly one thing about your company, what do you want that to be?
Purser: Cohesity is the leader in cyber resilience: the number one choice for keeping data protected and recoverable when it matters most. We’ve been recognized as a Gartner® Peer Insights™ Customers’ Choice for Backup and Data Protection Platforms eight times in a row.
VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors — whether that’s agentic AI attacks, identity-based intrusions, critical infrastructure targeting, or something else — is your solution most directly built to address?
Purser: Our focus is on resilience: specifically, the ability to respond and recover quickly, and with minimal impacts to business continuity, following an incident. In this way, we’re prepared to meet any threat vector – even insider threats – with advanced alerting and tactics to protect the crown jewels.
VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for — and with — autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?
Purser: Agentic AI doesn’t just introduce new attack surfaces; it fundamentally changes the identity problem. Enterprises are deploying AI agents at scale while treating them as software, not assigning identities. Every agent needs a unique, tracked identity, just like every human user. Without that foundation, you cannot detect anomalous behavior, audit what happened, or recover cleanly when something goes wrong. At Cohesity, we solve this through continuous exposure assessment, identity threat detection and response, and fast, verifiable recovery to a clean state, whether the actor is a human employee, a compromised service account, or a rogue AI agent. Every identity, human or not, must be accountable.
VMblog: The post-quantum cryptography migration is well underway for some organizations and barely started for others. Where should companies realistically be in that transition today, and what’s your honest assessment of how complex the road ahead still is?
Purser: Organizations in positions of high customer trust need to begin preparing now. They need to scrutinize their supply chains, validating quantum-safe encryption and other technical controls are either in place or planned within the next seven years.
VMblog: “AI-native security” is quickly becoming the new “next-gen.” What does that phrase actually mean at your company, and how do you demonstrate real differentiation beyond the marketing language?
Purser: Cohesity built AI into its data protection platform long before it was a buzzword. Our patented entropy monitoring technology “learns” the overall patterns of data movement across your environment and flags anomalies the moment they appear, whether that’s usual data exfiltration or any other high-risk activity.
VMblog: Are you unveiling any major product announcements, partnerships, or research findings at Black Hat 2026? Can you tease it or give us a preview?
Purser: Cohesity REDLab will be releasing its threat intelligence report for Black Hat USA. REDLab rigorously tests the real-world resilience of Cohesity’s products using live malware, advanced exploits, and modern attack techniques. For more information, please visit cohesity.com/trust/redlab.
VMblog: Identity has become the new perimeter — and attackers know it. How has your approach to identity security, authentication, or access management evolved, and what are organizations still getting dangerously wrong?
Purser: Cohesity partners with Semperis on identity security, integrating best-in-class capabilities to ensure identity can be recovered and validated under the most stressful conditions. An organization can recover their data, but if identity isn’t restored and trusted, the risk of re-infection is high.
VMblog: What’s the most significant cybersecurity blind spot you’re seeing across your customer base right now, and how does your technology address it?
Purser: During post-incident recovery, we see that re-infection by the threat actor occurs about half the time. Two root causes stand out. First, the recovery environment failed to be protected via network isolation, leaving it exposed. Second, the threat actor was not removed from the victim’s network and remained dormant, waiting to disrupt recovery efforts. Deploying a clean room and ensuring teams are properly trained to handle these scenarios helps to reduce this risk.
VMblog: Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden rather than add to it?
Purser: Post-incident recovery is neither simple nor instant. However, data and profit losses can be minimized with an investment in protecting and recovering your data. In fact, regulated industries must annually report on how they are protecting that data; and cyber insurers require it. Save the pain by doing it right the first time.
VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?
Purser: Agentic AI: understanding it and securing it. This means assigning identities to AI agents and having alerts and kill switches in place for when they behave unexpectedly. Nearly every CISO I speak with identifies this as a top-tier risk right now.
VMblog: The conversation around software supply chain security has matured significantly — but has enterprise practice kept pace? What’s the current state, and where are the gaps that still keep you up at night?
Purser: I continue to have concerns about the level of trust buyers place in their software vendors. Supply chain security goes well beyond compliance, or even software bills of materials. Buyers should assess the internal security programs of critical vendors, to determine if mature organizational structures and competent leaders are in place and attuned to risks.
VMblog: Looking toward 2027 and beyond, what emerging threat or technology inflection point do you think the industry is still not taking seriously enough?
Purser: The emerging threat that I see is that posed by rogue agents. Agents are being created and given autonomy, without identities. Identity assignments, along with control policies are among the ‘guardrails’ that define what areas they can access and what areas they cannot access. Recent news about the agent that deleted a startup company’s production database and backups, serves as a stark reminder of failure to mitigate the risks accompanied by autonomous AI.
VMblog: Beyond the product pitch, what’s one piece of hard-won, actionable security wisdom you’d hand to every practitioner who stops by your booth?
Purser: Resilience requires not only technology, but also people and process. Adequate preparation, like having a digital jump bag ready, is essential. Red-teaming, pen tests, and exercises that include the recovery environment are must-do.
VMblog: Are you hosting any exclusive networking events, hospitality suites, or invite-only dinners during Black Hat week? How should interested attendees get connected?
Purser: Yes! Please join us for a Happy Hour with Google on Wednesday, Aug. 5 at Swingers (Mandalay Bay), the Neat & Secure CISO Reception with Cyera (Four Seasons Penthouse), and the Agent Ready After Party at Eyecandy Bar & Lounge (Mandalay Bay). For more details on these activities and to request a meeting before the show, please visit here.
VMblog: What’s the most creative or unexpected giveaway your booth is bringing this year?
Purser: Black Hat attendees can stop by Cohesity’s booth and enter for a chance to win a WHOOP band. WHOOP tracks sleep, strain, stress, and heart health around the clock, giving individuals a complete picture of their health to make smarter decisions every day.
VMblog: For the first-timer navigating Black Hat for the first time — what’s your best advice for getting maximum value out of the week without burning out by Wednesday?
Purser: If you’re a security executive, prioritize both the briefings you want to attend and engagements that will expand your trusted, professional network. Trust-based relationships are gold in the security industry; I learned that from my days as a CISA field executive.
VMblog: When the industry gathers again at Black Hat 2027, what do you think will be the defining cybersecurity conversation that dominated the year?
Purser: The defining conversation will be storytelling about rogue agents. The only topic that may top it will be how attackers begin chaining AI tools to find and exploit long-standing software vulnerabilities at a scale and speed defenders haven’t faced before. 2026 is going to be a bumpy ride for security defenders.
##






