Cyber resilience is the ability of an organization to anticipate, withstand, respond to, and recover from cyber disruption while continuing to deliver critical business services.
The real test is no longer whether an organization can prevent every attack. That is unrealistic. The real test is whether it can keep operating, restore trusted services, protect critical data, and preserve confidence when an attack succeeds.
That is why cyber resilience is the outcome every modern business should seek. Digital business now depends on data, identity, applications, infrastructure, software supply chains, and third-party services. When these are disrupted, the impact is not limited to IT. It becomes operational, financial, regulatory, and reputational.
In the UK, the cyber incidents at retailer Marks & Spencer (M&S) and motor manufacturer Jaguar Land Rover (JLR) in 2025 underline this point. In both cases, business operations were severely disrupted. M&S had to pause online orders, while JLR had to manage a halt to manufacturing operations and the impact across a broader supply chain. These events show why resilience is a business requirement.
Against that background, progress by Cohesity since its merger with Veritas should be judged on whether the combined company moved closer to being able to help organizations restore trust in business operations, not just restore data.
The answer appears to be yes, with the important qualification that execution at customer scale remains the real proof.
From backup to operational cyber resilience
A key message from Cohesity is the move away from backup as an infrastructure category toward cyber resilience as an operational capability.
Backup has traditionally been seen as a recovery mechanism. It answers the question whether data can be restored. Cyber resilience asks a broader question. Can the business restart safely, securely, and quickly enough to limit damage?
Cohesity is talking about its platform in terms of this broader idea. Its five-step cyber resilience framework covers data protection and identity resilience, cyber vaulting, threat protection, cyber recovery orchestration, and data and Artificial Intelligence (AI) security posture management. This approach brings protection, recovery, security, and risk posture into one operating model.
This is also where the Veritas merger becomes more meaningful because of the opportunity to combine Cohesity’s modern data platform and AI-led approach with Veritas’s enterprise-grade data protection heritage, workload coverage, and customer base. Eighteen months on, Cohesity Data Cloud is becoming the common platform for that combination.
The platform vision is built around four layers. The data platform provides the foundation. Data protection ensures data can be protected and recovered. Data security helps reduce risk and recover from attacks. Data insights aim to unlock value from unstructured data, including for Generative AI (GenAI) use cases.
In practical terms, that means bringing together Cohesity NetBackup and Cohesity DataProtect for broad workload protection, Helios for centralized management and operational visibility, FortKnox for isolated cyber vaulting, RecoveryAgent for cyber recovery orchestration, threat protection for detection and investigation, identity resilience for protecting one of the most critical recovery dependencies, Gaia for AI-enabled insight into enterprise data, and Data Security Posture Management (DSPM) for understanding and reducing data risk.
This approach is correct. Cyber resilience depends on knowing what data exists, where it sits, how critical it is, how it is protected, whether it is clean, and how it can be recovered in the right sequence.
Platform integration matters
Cohesity says the Veritas integration was completed in less than nine months and points to six major releases in the past year, including DSPM, identity capabilities, Gaia, RecoveryAgent, Helios for NetBackup, and Gaia on premises.
It is worth noting that Cohesity is not presenting the combined portfolio as two product families under one corporate owner but as a route toward one control plane, broad workload coverage, flexible deployment, and common cyber resilience outcomes.
The distinction between the control plane and the data plane is also important. Cohesity’s claim that these can be independent and can be delivered as Software as a Service (SaaS) or on premises is relevant for regulated and complex organizations. Many large enterprises need centralized management, but they cannot always allow data to move freely into public cloud services. The ability to separate management from where data is processed and stored is therefore a practical resilience and sovereignty feature.
The simplification of consumption also matters. Cohesity is moving toward service tiers and specialized bundles. Complexity is the enemy of operational readiness. A solution that is too difficult to understand, deploy, license, or rehearse will not deliver resilience in a crisis.
Restoring trust, not just data
One of the strongest messages from Cohesity is that recovery is about restoring data, while cyber resilience is about restoring trust.
After a destructive cyberattack, organizations need more than a backup copy. They need confidence that the copy is clean. They need to know which systems to recover first, and which identities can be trusted. Not only that, but they need clean rooms, staging rooms, runbooks, communication paths, and tested recovery workflows.
Cohesity’s cyber resilience services appear to recognize this. Its approach is built around education, preparation, and support. Workshops help customers understand destructive attacks. Assessments benchmark current resilience. Digital Jump Bag and Clean Room workshops help define practical response and recovery workflows.
Using the Minimum Viable Company (MVC) approach, Cohesity aims to help organizations to identify the smallest trusted set of services needed to keep the organization legally, operationally, and commercially alive. This is at the heart of cyber resilience.
PwC partnership adds business resilience context
The strategic collaboration between PwC UK and Cohesity is significant. Announced at the Cohesity Catalyst on Tour event in London by Karen Penman, Digital & Cyber Resilience Partner at PwC UK, the partnership combines PwC’s cyber, risk, and resilience capabilities with Cohesity’s data security and recovery capabilities.
This is important because cyber resilience cannot be delivered by technology alone. Boards and executives need to answer business questions. Which services are most critical? How confident are we in recovery? What data and systems are essential?
Professional services firms can help translate technical resilience into business resilience. Technology providers can supply the platform, telemetry, protection, recovery, and automation. The strongest approaches will combine both.
The PwC partnership therefore fits the broader market direction. Resilience is becoming an operating model, not a product category. It requires governance, secure recovery technology and processes, crisis management, and regular testing and exercising.
Sovereignty as part of resilience
Cohesity is also addressing sovereignty in a pragmatic way. Its position is that data should remain under customer control wherever it needs to live. That includes on-premises, sovereign cloud, and hybrid deployment options.
The on-premises model is particularly relevant. Cohesity says customers can run the platform in their own datacenter so data never leaves infrastructure they control. In the strongest version of this model, processing and storage remain on premises, encryption keys remain with the customer, Cohesity has no access, and offline maintenance can be available where required.
This is not just a compliance point. It is a resilience point. Organizations in critical sectors may need recoverability under attack, but they may also need jurisdictional control, operational independence, supply chain transparency, and confidence that sensitive data is not exposed through a public cloud dependency.
Cohesity’s sovereignty message is therefore aligned with European regulatory and geopolitical realities. The key is that sovereignty must not be reduced to data residency. True sovereignty also includes control, transparency, recoverability, encryption, operational continuity, and exit options.
AI, agents, and the next phase of resilience
Cohesity’s AI strategy is also evolving. The company is not positioning itself as the control tower for all enterprise AI or agentic activity. Instead, it is focusing on protecting agentic infrastructure and the data that agents manage.
AI agents will increasingly act on enterprise data, call services, trigger workflows, and influence operational decisions. They will also create new risks. Resilience therefore requires trusted data, protected workflows, governed access, and the ability to recover the systems and data that agents depend on.
Cohesity’s approach is to partner with AI and agent platforms rather than force customers into a separate AI experience. Cohesity Maestro extends this direction by making Cohesity Data Cloud capabilities accessible through the Model Context Protocol (MCP). The idea is to let external AI tools and agents query telemetry, trigger recovery actions, access protected data insights, and orchestrate workflows under existing controls.
This headless approach is pragmatic. Enterprises are already standardizing on AI platforms. Security and infrastructure tools need to work where users and agents already operate. However, agentic resilience must be governed carefully. Role-based access control, authentication, auditability, policy enforcement, and human oversight remain essential.
Conclusion
The Cohesity and Veritas merger was always going to be judged on execution. Eighteen months on, there are credible signs of progress.
The combined company has moved beyond the language of portfolio consolidation and is now presenting a clearer platform strategy around Cohesity Data Cloud. The integration of NetBackup, DataProtect, Helios, FortKnox, RecoveryAgent, Gaia, identity resilience, threat protection, and DSPM gives the company a broader foundation for cyber resilience.
The strategic direction is also well aligned with market demand. Organizations need to protect data across hybrid and multi-cloud environments. They need to recover from destructive attacks. They have to know what data is sensitive, which services are critical, and what recovery sequence will keep the business alive. They need sovereignty options. They need AI support, but they need it with governance and control. They need preparation and rehearsal, not just recovery after the event.
The incidents at M&S and JLR show why cyber resilience is now a board-level concern. Cyberattacks now stop orders, affect factories, disrupt supply chains, and test public confidence. The question is not whether organizations have backups but whether they can restore trusted business operations fast enough to limit harm.
Cohesity is working to address that question. Its progress is visible in platform integration, service simplification, recovery orchestration, sovereignty support, AI-enabled data insight, partner alignment, and customer examples of resilience at scale.
The remaining challenge is evidence at scale. Cohesity must continue to show customer success in terms business leaders understand. The proof will be whether customers can prepare better, recover faster, restore trust more confidently, and keep critical services running when cyber disruption becomes real. That is the true measure of cyber resilience.
Cohesity is not the only vendor in this market; you can find a detailed evaluation of this and other vendors in our Leadership Compass Cloud Backup for AI-Enabled Cyber Resilience.
To explore best practices in securing and governing human and non-human identities at scale, join us at AIdentity & Non-Human Identity Impact Day 2026 in Munich, Germany, on October 6.