Backup Restores Data. Cyber Resiliency Restores Trust.
Traditional backup gets you data back. Cyber resiliency gets you trust back — and in 2026, that’s the only outcome that matters. James Blake, VP of Global Cyber Resiliency Strategy & Consulting Services at Cohesity, joins Alan Shimel on Techstrong TV to draw a hard line between BCDR and cyber resiliency, and to explain why the biggest use of backup today is not natural disasters or hardware failures — it’s recovering from a cyber incident. James walks Alan through the rise of wiper attacks from nation-states, hacktivists, and disgruntled insiders, the collateral damage exposed by NotPetya, and why threat actors now target backups first so victims have no choice but to pay. He also unpacks Cohesity’s Ransomware Resiliency Workshops — half-day simulations that put C-suite executives through worst-case scenarios with imperfect information — and makes the case that when recovery fails, it’s almost never the technology. It’s the people, the roles, and the responsibilities.
Transcript
Hey everyone. Welcome back here to Techstrong TV. My next guest is James Blake.
James is the VP of Global Cyber Resiliency Strategy, Response, and Consulting Services over at Cohesity, and that's a mouthful. We're going to get him to explain that, but first, let's welcome James to our show. James, great to have you on here.
Hope all is well with you. Thank you very much. Yeah, they just keep giving me more to do, and my title just gets longer and longer.
Your titles are growing, right? I hope they're paying you by the letter there or something. But, James, before we get into your current role at Cohesity, let's hear what you did before that.
I always like to understand where our guests come from. So- Yeah ... if you don't mind, share a little.
Yeah. So, it's only the last few years that I've really been working for vendors. I spent most of my time on the other side of the table, just like a lot of your listeners.
So, prior to being at Cohesity, I was at another data management company called Rubrik, where I was one of the- Sure ... responsible for the pivot to security of that organization and similarly with ServiceNow. So I used to be the strategist for security at ServiceNow globally.
But before that, I was the head of cyber risk and then later transformation for one of the largest banks in the world, JP Morgan Chase. Sure. And 10 years before that, I built SOX.
So I built SOX at the world's largest retailer, the world's largest tech firm, the world's largest software company, one of the world's largest oil companies. Dealt with dozens of incidents all over the world, wiper attacks, ransomware attacks, traditional kind of data exfiltration, and fraud attacks as well. And for my sins, before that, I was a CISO as well, so totally responsible for security at Mimecast, where I started as one of the first couple of dozen employees all the way through to our IPO.
So nearly a decade, led the entire security approach at that very large European software as a service vendor. So I guess what you're trying to tell us is you're fairly new to the industry, huh? Yeah.
I've been around for a while, right? The no hair shows the more incidents you deal with, the less hair you have. The less hair you got.
Yeah, that should say something about both of us. But James, that's an amazing journey, and thanks for sharing that. Few people I think can top that, right?
You've really had your finger on the pulse of what's been going on here in the cyber world for a long time. Not going to say how long, because we don't have to. But, congratulations.
Let's talk about the present role, though. There is a lot there. What exactly is it you're doing at Cohesity?
So I work for Cohesity. If you're not aware of the company, we are a data management company. So some people say backup and recovery, but it's gone way beyond that because once you've got all that data in one place, you've got a lovely scalable platform, you can do multiple things with it.
So you can use it to power AI, but the side of it I look after is the cyber resiliency. So the biggest use of backup these days is not to deal with traditional BCDR events. It is because there has been some form of cyber incident.
So I look after three elements of the business. The strategy, so advising as an operational practitioner, someone that's spent a lot of their time using tooling like this to both respond and recover from attacks, advising on what features we should put in the products and how they will be used by our customers, and the strategic value they have. The second thing I look after is our incident response team.
So we've had hundreds of attacks over the last couple of years where we've been the last line of defense, and my team have been on the phone with those customers, helping them during that response and recovery process. So we get to see a lot of things that fail, and often, well, almost always, it's not the technology. It's the approach.
It's the people. It's the roles and responsibilities that let organizations down. And for that reason, we invested a lot of time in developing a proactive consulting organization where those experienced incident responders that have got the scars from all those incidents can go into those customers ahead of that incident and make sure they don't fall down any of those traps, and get ahead and have the best possible resilience they can.
So I'm both before an incident and after an incident, and there's a lot of lessons there. Yes, there is. Yeah, God knows there is.
James, we've mentioned Cohesity a few times, and you did a good job of saying, hey, a lot of people knew Cohesity from the backup and DR space, and I wish the world was that simple still, right? That you could just kind of put it in that package and there you go. But as you said, Cohesity's doing a lot of different things.
Spoke a little bit about those that you touch on. But, bigger picture in Cohesity, would you use the term, was it data management or... Right?
Yep. Yeah. Data management.
That's basically what we do. If you think about- An organization these days, it has data spread everywhere, knowledge spread everywhere, in emails, in documents, in SharePoint sites, in photos, and everything else. And all that data is being backed up.
So, if you go back 10 years, we were building data lakes. We were replicating the data to a secondary place. More storage, less governance, because we were scattering it all around.
And these days, look at AI. What's happening with AI now is everyone is diasporing data, that good governance and control, into little pockets of the organization, and they're connecting it to models, who knows what model. And we're busy trying to implement things like SASE to try and control that diaspora of data if it goes outside of the organization.
But we've taken a slightly different approach. The biggest effort involved in things like AI and leveraging the value in that data is transformation and loading of that data. And if you think about it, as a backup vendor, we've already done that.
We've already put that data in a hyperconverged fast platform where we can exert strong controls over who can access it and which models can access it. It makes sense to leverage that data rather than duplicate effort, transforming and loading that into the models, bringing a model to the data rather than your data to the model. It's a much better security governance mechanism.
And then from the cybersecurity angle that I do, a lot of people think about recovery. They don't actually think about the value that we have in security, in incident response. The logs that never made it to a SIEM are sat in your backups.
The EDRs routinely evaded in attacks these days, and I think almost every single attack I've dealt with, the customer has up-to-date security tooling. It's just they're really good at evading it, using vulnerable device drivers and techniques like that. We can't be evaded because you're not on the endpoint.
And also, we don't just look at the now like an EDR. We've got the entire history of the potential attack timeline in the backups, where we can see the deltas, the changes, the persistence mechanisms, the malware, the indicators of compromise. So we made a huge amount of effort into, BCDR, which is the third element, our history, is about restoring data.
And the only variables in that, speed of pipe, speed of backup solution, and speed of disk. In a cyber incident, much more complicated. 15 stages of an attack, hundreds of techniques.
You've got to investigate to know what to remediate, to bring things back. So BCDR is about restoring data. We're about restoring trust and making sure when you bring things back, you don't get hit again.
I love it. James, I listen to you talk. I've been in cyber a long time, 25-plus years.
I love the way you talk about it because for too many people, cyber is bad guys, good guys, and the impossibility of it, or just the enormity of the mission, let's call it. You're bringing humanity to it a little bit and making it in bite-sized chunks that we understand and things that we need to do. If you don't mind, I want to talk about wiper attacks now.
Mm-hmm. And you and I understand what we mean by a wiper attack, but there might be people out here. We have a big cyber audience, but we have other people.
Not everyone knows what we mean by a wiper attack. How would you describe a wiper attack? Well, there are two types of destructive cyber attacks.
There's ransomware, which everyone's familiar with, which is basically an extortion attack. And then there is a wiper attack. And a wiper attack, there's no negotiation.
They are just destroying your data. And that can be for a number of reasons. It can be political.
It could be a disgruntled employee, for instance, inside of the organization. And typically, wiper attacks are conducted by nation-states. So, it is opposing nation-states conducting them.
The two largest users of wiper attacks at the moment are Russia and Iran, both of which have a bit of a beef with the West at the moment. And so the amount of these wiper attacks that we're seeing is actually going up. So, a wiper attack conducted by nation-states or their proxies, so it could be another organization or even a hacktivist that is in agreement with the political outcomes of that nation-state, and obviously, those threat actors tend to have quite good tradecraft.
So it is, in some regards, much difficult to protect through than your typical smash-and-grab ransomware-as-a-service. And that restoration of trust typically has to go through a few more steps and a bit more rigor, because they tend to maintain persistence much deeper than your average ransomware attack. Agreed.
I just want to make it really simple for the folks out there. When we say wiper, they're wiping. They're wiping your data.
Gone. Your database, your records, everything, your crown jewels, gone. IP, gone.
And now, of course, some people are sitting out here and say, "Well, I keep a copy on my hard drive. " Yes and no. Maybe that saves your bacon, maybe it doesn't.
Depends how good you are at backing it up and how much it's backed up, and so forth. And I will say, James, I've heard of incidents where wiper attacks are part of ransomware. " So it can be used for financial gain like that.
And you do see that. Look, you could see it from smash-and-grab or gangs in Eastern Europe or something like that. You could also see it from nation-states like a North Korea or an Iran where North Korea, well, before they started selling their drones and their troops to everyone, North Korea brought in a lot of their hard foreign currency from ransomware and other cyber attacks.
So it's a real thing, and I think what I want to talk about, James, is this is no longer confined to Russia attacking NATO allies or Iran attacking Western allies or Israeli allies or what have you. It's grown beyond that, like some of these examples that I'm talking about. Can you expand on that?
Yeah. There's so much good stuff in what you just talked about there. So just very quickly, a couple of points you touched on.
The first one is, yes, if you think about it, a ransomware attack, if you don't pay the ransom, is a wiper attack. Once the encryption key's gone, there's no hope of getting that data back, right? The second thing being that it's getting a little murky right now.
So ransomware and wiper attacks, there's a bit of overlap, right? So we saw groups like Conti. When Ukraine was invaded, Conti are a ransomware group, and they said that they were supporting Russia's outcomes in the war, so they would target deliberately organizations of allies, right?
So that's a ransomware group specifically targeting organizations because they're of an opposing state. Now, where does that sit? Is that geopolitical, or is that traditional criminal activity?
It's a bit of both, really, to be quite honest. And, obviously, because the Conti group were Ukrainians, Belarusians, and Russians in majority, the group actually imploded, right? Because some people were against the supporting of Russia- Yeah ...
and all of their internal chat logs got published by a disgruntled internal person. We got to learn a lot about their tradecraft from that. So we're in this situation now where ransomware groups can pledge alignment to the geopolitical aims of a nation state actor.
We've also seen false flag activities, right? There was a wiper attack that came out a couple of weeks ago where there is no, it's dressed up as ransomware, but there is no decryption key, right? There's no way to decrypt the data.
It's just fake. And NotPetya was that. So NotPetya came after the original invasion of Crimea, and it was targeted at Ukraine.
But look at the global chaos it caused. Maersk being one of the largest organizations, but I dealt with dozens of organizations that were just collateral damage. They weren't the target, but they just happened to be hit by the impact of these attacks.
So that's the second thing to consider, false flag collateral damage. The first one, these proxies, these people that are aligned. And then the third one we're seeing is nation-states are actually getting into organizations using their advanced tradecraft, and then they are handing it over to a ransomware gang to encrypt everything, to get rid of the evidence, right?
And so effectively, you never even know that the espionage has taken place because you just think you've been attacked by a ransomware gang. So, we live in a very interesting world. And mention North Korea, there's one chap in particular who works for the state security agency.
And you mentioned the attacks, how they make revenue by seizing cryptocurrency exchanges. That's largely how they make their revenue at the moment. Yeah.
Dipping their toes in ransomware. But this chap's moonlighting in the evening, he's taking his tooling home from his day job and sitting at home and running a ransomware empire from North Korea. So those of us that work in threat intelligence, it's getting more complicated to put these people in nice, clean compartments, because there's just so much fuzziness and overlap at the moment.
A target-rich environment, as they say. Right? It's crazy.
James, we're almost out of time. For people who want to stay on top of this, maybe find out more about Cohesity, where can they go? Yeah.
com. We've got full information there. The one thing that we do, we are very much about trying to believe that cyber resilience is an operational capability- Not just the product.
So we invest an awful lot of time in education and running things called ransomware resiliency workshops, where you can turn up for half a day and experience a real-life ransomware attack. So we- How cool is that? Yeah.
We see people's blood pressure go up when they're in it. They take a senior executive role, and basically, I've created a set of scenarios from all those incidents I've seen and created the worst possible prepared customer. And you will play a part as an executive in that team, and you will see how you're forced by circumstances to make difficult decisions with imperfect information.
And this is something I experience inside of almost every customer that I'm trying to help. That's the reality of ransomware incidents. You've got no phones, you've got no door access control system.
You've got no trust in your security tooling. How do you start? How do you collaborate?
How do you work in that kind of environment? And those lessons learned are great. com website, have a look and hunt out if there's a ransomware resiliency workshop taking place near you.
And always, if you want to know how to get ahead of this, and you want some services to evaluate where you are now, my team are always there to help you with that. Love it. James Blake, thanks for coming here on Techstrong TV.
I hope to have you back on soon. Thank you very much. Actually, are you going to be at Black Hat?
I'm not, but someone from my team is. So, Jonathan Mayer- We'll be doing videos there. We should have someone reach out.
Maybe we'll do something with Black Hat news around us. But James, thank you again. Thank you for watching.
We're going to be back with more Techstrong TV content in just a moment. We're going to take a quick break.