As ransomware attacks continue to evolve in sophistication, organizations need increasingly advanced tools to protect their critical data and ensure reliable recovery options. Ahead of Dell Technologies World in Las Vegas, Index Engines has announced a significant update to CyberSense specifically tailored for Dell customers, focusing on deeper detection capabilities and greater control for security teams.
In this exclusive VMblog interview, we speak with Drew Bongiovanni, Technical Product Marketing Manager at Index Engines, about their latest innovations in ransomware detection and recovery. Bongiovanni details how the new release addresses emerging threats like raw disk corruption attacks, introduces custom malware signature capabilities, and enhances visualization tools�all designed to transform recovery from what he calls “a guessing game into a confident strategy.”
With CyberSense’s content-based AI analysis achieving a remarkable 99.99% detection rate, Index Engines continues to differentiate itself in the cybersecurity landscape through its focus on byte-level corruption detection rather than just infrastructure anomalies. Join us as we explore how these new capabilities are reimagining the recovery process for Dell customers facing increasingly complex cybersecurity challenges.
++
VMblog: Index Engines is heading to Dell Technologies World in a few weeks, and I heard you just had a Dell-specific release of CyberSense-can you give us the high-level buzz on this release?
Drew Bongiovanni: Absolutely. We’re excited to be heading to Las Vegas as a sponsor of Dell Technologies World. With the event coming up, it was the perfect time to deliver a release tailored for Dell customers-one that we’ll certainly be chatting with folks about in the expo hall!
Our latest CyberSense release helps support recovery reimagined. We focused on extending detection capabilities to more sophisticated ransomware attacks and giving organizations more control over how they leverage CyberSense against bad actors. This release introduced raw disk corruption detection-a new capability to detect raw disk corruption on virtual machines, which impacts the operating system, making the file system inaccessible and complicating recovery.
It also adds features that give security teams more hands-on tools, like support for custom malware signatures and YARA rules, new alerting thresholds, role-based access control (RBAC), and improved data visualizations.
VMblog: Let’s start with raw disk corruption- that’s a new term for me. Can you explain a bit further what that is and how CyberSense helps?
Bongiovanni: Raw disk attacks are a step beyond file encryption and are typically part of a two-stage playbook. First, attackers hit you with ransomware to encrypt your files. Then they go deeper, corrupting the disk structure itself to render your file system inaccessible. So, they’re not only corrupting your data but covering their tracks to make it harder for traditional tools to even spot the ransomware in the first place.
If the file system within a backup becomes unreadable, CyberSense uses this information, along with other indicators, to trigger an alert to investigate a potential raw disk attack. It gives teams the early warning needed to take a closer look at their backups.
VMblog: You mentioned adding support for custom signatures and YARA rules. What drove that decision?
Bongiovanni: Many teams we work with choose CyberSense for its depth of analysis and accuracy, but they still want a certain level of control-they want to tailor detection to the threats they care about. So, with this release, we’ve given customers the ability to add their own malware signatures and YARA rules into CyberSense.
VMblog: Can either of those actually help during a ransomware recovery?
Bongiovanni: Malware signatures are particularly unique in that they provide forward and backward detection of malware, meaning users can search for signatures in both their existing and future backups. If a customer gets hit with a new variant, they can work with their antivirus company to identify the variant’s signature and scan their backups for it before restoring to make sure they don’t reintroduce dormant malware.
VMblog: While we’re on the topic of detection-can you remind us how CyberSense approaches ransomware detection? It’s a bit different from other tools, isn’t it?
Bongiovanni: It’s a great question because while malware signatures and YARA rules give security teams assurance that they can scan for specific threats, CyberSense is purpose-built to detect ransomware-induced corruption with very high accuracy. Many traditional tools out there focus on prevention or anomaly detection at the infrastructure level.
CyberSense analyzes over 200 content-based statistics per file, not just metadata, using AI that’s trained on real-world ransomware. That means we detect corruption at the byte level-even if the bad guys are using subtle techniques like partial encryption, polymorphic behavior, or slow-moving attacks designed to avoid detection. In the end, CyberSense has a 99.99% detection rate with near-zero false positives.
VMblog: Before we wrap, any other improvements in the latest release worth mentioning?
Bongiovanni: Well, we’re really excited about the enhancements we’ve made to help teams track data trends over time and fine-tune specific alerts to their environment. Teams can now configure threshold alerts by severity level, and better monitor how specific metrics-like changed, deleted, or added files-are trending over time. Those thresholds are also shown on the data graphs in the UI so users can see if metrics are approaching an alert.
We’ve also added new views for some of our custom indicators like Delta Block Analysis (DBA) scores and the Cyber Sensitivity Index (CSI), giving teams a clear view into how CyberSense is analyzing their backups.
VMblog: If someone reading this wants to learn more or see CyberSense in action-what’s next?
Bongiovanni: Our website is a great place to start. You can visit www.indexengines.com/trust. From there, you can access more technical content, request a demo, or just connect with us. We’re always happy to show how CyberSense can turn your recovery process from a guessing game into a confident strategy.
And, of course, if you’re heading to Las Vegas, come see us at Dell Technologies World. We’ll be at booth 561. You can even check out what we’re up to during the conference by visiting: indexengines.com/dtw.
##






