Intelligence – CyberSense
PowerProtect Cyber Recovery is the first solution to fully integrate CyberSense, enabling smarter data recovery from cyber threats—all within a secure recovery environment. CyberSense goes beyond standard metadata-based solutions; through comprehensive content analysis, it detects data corruption post-attack with 99.99% accuracy, facilitating fast and intelligent recovery.
CyberSense utilizes immutable backups to monitor data changes in real-time, employing AI-driven machine learning to detect signs of corruption indicative of ransomware attacks. The system identifies mass deletions, full and partial encryption, and other suspicious changes within the infrastructure (like Active Directory, DNS, etc.), user files, and databases that may result from advanced attacks.
With customizable threshold alerts, CyberSense enables rapid response to detected corruption. An alert dashboard and post-attack forensic reports help quickly assess the scale and impact of an incident, including identifying a clean copy of data needed to restore critical systems. The analytics also determine if a dataset is intact and suitable for recovery or if it has been suspiciously altered, rendering it ``suspect`` and potentially unusable.
CyberSense analytics is a powerful tool that evaluates the integrity of backups without needing to restore them. It analyzes the entire content of critical files rather than just metadata, providing superior data analytics without exposing storage to additional risks.
Dell Technologies offers flexible recovery options to meet data resilience requirements. Recovery procedures are primarily based on standard processes but also account for special conditions across various scenarios. Recovery is integrated with the incident response process; after an event, the response team analyzes the production environment to determine the root cause. CyberSense provides investigative reports post-attack, helping to understand the extent and scope of the incident and providing an overview of the most recent valid backups before data corruption occurred.
When the production environment is ready for data recovery, Cyber Recovery provides the necessary management tools and technology for actual data restoration. It automates the creation of recovery points, which are used both for data restoration and security analytics.