Opens in a new tab
vmblog logo 2024 wht (updated)

How VMware Cloud Foundation Enables Cyber Resilience for the Modern Private Cloud – VMblog QA

Share: 

David Marshall | Published: May 5, 2025

 

We live in the era of cyber warfare. Our crown jewels now live in a data center, and our ability to prevent, withstand and recover from attempts to steal them is tested every day. This problem isn’t new, but despite years of effort, organizations continue to struggle to effectively enforce true cyber resilience. The question is why?

VMblog sat down with Yoomi Hong, head of product marketing for core infrastructure in the VMware Cloud Foundation Division at Broadcom, to discuss the current state of cyber resilience and how the VMware Cloud Foundation (VCF) private cloud platform is uniquely engineered to bridge the gap between prevention, detection and recovery.

VMblog:  Cyber resilience is an issue most organizations today seem ill-equipped to address, and C-Suite execs continue to lose sleep over it. Why do you think that is?

Yoomi Hong:  We’ve seen a paradigm shift in the way cyberattacks operate, and organizations are simply not ready. Cybercriminals are constantly working to develop new attack vectors, different ways to remain undetected, increase the blast radius of the attack and encrypt or steal as much data as possible to maximize their payout chances. With the rise of AI/ML, these attacks have become smarter and harder to detect, and this exposes victims to increased damage because they are either unaware of the tools they need to fight back or believe that the measures they have in place will protect them.

VMblog:  What exactly is the paradigm shift we’re seeing?

Hong:  The paradigm shift we’ve seen has been the introduction of fileless malware. These attacks leave no malicious file behind, leverages legitimate tools and protocols, works in-memory, and is undetectable through the traditional file-scanning methods like traditional AV that IT teams are used to relying on. Most attacks today are fileless in nature.

VMblog:  Why are these fileless attacks so effective, and thus dangerous?

Hong:  They’re dangerous because most organizations today continue to operate under the misconception that file signature scans will detect ransomware infections. For fileless attacks he only way to detect and contain them is by powering on workloads in an isolated environment and running Next-Gen Antivirus analysis. Monitoring how the data within the live workload behaves over time allows IT teams to spot malicious activity that indicates the presence of infection. The integration of these types of advanced detection tools into traditional disaster recovery deployments is not easy, and we’ve seen many organizations struggle to implement this successfully.

VMblog:  So how does a private cloud enable stronger cyber resilience?

Hong:  That’s a great question, and I’ve had this conversation with many of our customers. When it comes to cyber resilience, the key benefits a private cloud delivers when compared to public cloud are increased visibility and control of the infrastructure, a more granular customization of security and compliance controls, and a smaller attack surface as the number of users is significantly lower.

VMblog:  How does VMware Cloud Foundation uniquely enable cyber resilience for your customers?

Hong:  The most important benefit that sets VMware Cloud Foundation apart is the ability to deliver cyber resilience end-to-end as part of a single private cloud platform that spans three key areas: Infrastructure Hardening, Lateral Security and Cyber Recovery. These three areas are core to the NIST framework, which defines cyber resilience as an organization’s ability to prevent, detect, withstand and recover from ransomware attacks.

VMblog:  Why is infrastructure hardening important, and how does VMware Cloud Foundation achieve this?

Hong:  Infrastructure hardening involves any security or control mechanism that is implemented into the infrastructure to prevent attackers from coming in. Examples include identity federation, at-rest and in-transit data encryption, automated patching, monitoring and auto-remediation of compliance drifts. VMware Cloud Foundation infrastructure comes hardened out-of-the box, which dramatically simplifies the implementation, monitoring and control of security measures and ultimately delivers more reliable, comprehensive protection to the customer.

VMblog:  What are the unique capabilities VMware Cloud Foundation enables for lateral security?

Hong:  vDefend Distributed Firewall and Advanced Threat Prevention enable strong distributed lateral security across VCF sites with microsegmentation, signature and behavior-based detection, correlation of threat campaigns based on similar indicators of compromise, and zero-day threat detection with malware sandboxing. In addition, vDefend recently announced the introduction of Intelligent Assist, which delivers GenAI-powered assistance that gives SOC admins visibility and context into threats, streamlined implementation of security policies and simplified triage.

VMblog:  Can you tell our readers more about Cyber Recovery?

Hong:  Absolutely. Cyber recovery is a crucial last line of defense and it’s often overlooked or misunderstood. Many believe that cyber recovery is the same as DR, but that is a misconception. Ransomware recovery requires advanced capabilities such as restore point selection guidance and validation with aggressive detection of both file-based and fileless malware, dedicated recovery infrastructure with built-in network isolation to prevent lateral movement, and full automation of this step-by-step iterative process at scale. All these added components usually need to be manually integrated, are provided by different vendors, and this piecemeal approach ultimately exposes organizations to increased damage.

VMblog:  How does Broadcom address Cyber Recovery in VCF environments?

Hong:  About a year ago we announced the general availability of VMware Live Recovery (VLR), an Advanced Service for VCF. VMware Live Recovery combines enterprise-grade disaster recovery with purpose-built cyber recovery under a unified management experience for VCF sites on-premises and in the cloud. VLR integrates all the necessary components to enable secure cyber recovery from start to finish into an automated workflow that guides users through all stages of the process. Recovery infrastructure can also be easily provisioned from the product UI, unlike other approaches where the customer is left on their own to set up, secure and manage this themselves. 

VMblog:  We are seeing a shift in purchase behavior where organizations choose platforms versus best-of-breed security products. What would you say to organizations who are on the fence about making that leap to a platform approach as they consider adopting VCF?

Hong:  The VMware Cloud Foundation platform offers the best of both worlds. Customers can benefit from the tight integration while still getting access to best-of-breed products. We are the only vendor in the industry that can enable cyber resilience end-to-end across infrastructure, security and recovery, and this is something our hundreds of thousands of customers greatly appreciate. There are significant benefits to integrated operations, and cyber resilience is an area where the joint value of the platform delivers superior value than the sum of its parts. 

VMblog:  What would your advice to CISOs and business leaders who are looking to strengthen their organizations’ cyber resilience be? Where should they start?

Hong:  A key challenge today relies on bridging the gap between prevention, detection and recovery, which requires close collaboration between security and infrastructure teams. To get started, leaders should run an exhaustive gap analysis of their infrastructure and consider a holistic approach to cyber resilience to remove unnecessary hurdles and allow IT teams to smoothly operate.

##