Analyst(s): Fernando Montenegro
Publication Date: September 28, 2026
Cohesity’s Agent Resilience extends backup to the state of AI agents, starting with Amazon Bedrock. We see a sensible extension of what backup does well, in a crowded field where rollback in general will need to evolve to better capture agent actions.
What is Covered in this Article
- Cohesity Agent Resilience protects an agent’s memory and configuration, along with the data systems agents act on, starting with Amazon Bedrock, with Microsoft
and Google platforms on the roadmap. - Cohesity’s research makes a strong case for measuring recovery by whether the business keeps running, not just whether systems come back up.
- Agent rollback is a logical first step, and the next frontier is handling actions that have already left the platform.
- Rubrik, Commvault, Druva, and Veeam are pursuing similar goals, with platform breadth and clean-recovery validation likely to set offerings apart.
The News: At its Catalyst 2026 event, Cohesity introduced Agent Resilience, a Cohesity Data Cloud capability for discovering, protecting, and recovering the infrastructure behind enterprise AI agents. At launch, it protects agent memory and configuration, along with the databases, file systems, and other services agents interact with, using the snapshot, immutable backup, and clean-room recovery architecture that Cohesity already applies to other workloads.
A per-agent topology view maps what each agent touches, and teams can restore an agent to a known-good point after memory corruption, misconfiguration, or malicious activity. Agent Resilience supports Amazon Bedrock AgentCore and Amazon Bedrock Agents, is available now to select customers, and is targeted for general availability at the end of 2026, with Microsoft and Google agent platforms on the roadmap.
Cohesity also outlined a vision for Autonomous Cyber Resilience, which will use human-approved agentic workflows to automate its five-step cyber resilience framework, and updated Gaia Catalog, first announced in March, which exposes curated backup data to analytics platforms starting with Databricks. Its fifth annual Global Cyber Resilience Report (3,200 respondents across 12 countries) found that 78% of organizations focus recovery on restoring systems rather than keeping the business running, and 56% are not well prepared to detect or contain unintended actions by AI agents.
Cohesity Extends Cyber Resilience to the AI Agents Themselves
Analyst Take: Backup vendors have spent the past year arguing that AI agents belong inside the recovery plan, and with Agent Resilience, Cohesity makes one of the more concrete versions of that argument: protect the agent’s own state, not just the data it touches, and bring it back to a known-good point when something goes wrong. The timing aligns with demand, as 57% of respondents to Futurum’s 1H2026 Cybersecurity Decision-Makers Survey (N=929) reported being highly concerned about the security implications of agentic AI operating within their environments.
Cohesity paired the launch with research that frames resilience as a business outcome, which we find useful. Its report found 78% of organizations build recovery around restoring systems rather than keeping the business running, and only 22% have tested a defined “minimum viable company.” In our own survey, 65% of decision-makers said they are very or extremely confident in their ability to respond to and recover from a significant incident.
Different surveys ask different questions, but read together, they suggest confidence may be running ahead of rehearsal. If agents become part of how the business runs, they become part of what must be returned after an incident.
Protecting the Agent, Not Just What It Touches
Credit where it is due. Cohesity protects the agent’s own state (memory and configuration at launch), not only the data it acts on, which makes a poisoned agent something to restore rather than rebuild by hand. Pairing that with the recovery of the databases and file systems, the agent change is the right shape for the problem.
What Can Rollback Undo?
We would offer a less comfortable read here. Rolling an agent back restores the agent and, where Cohesity protects them, the databases and file systems it changed. It does not restore anything beyond that boundary: an email that went out, an API call to a partner, a payment that cleared, or data that left the environment. For agents with write access to external systems, those actions tend to matter most.
To its credit, Cohesity does not present rollback scope as a solved problem, and neither should anyone else. We would add a second question: how does a team pick the “known-good” point when it does not yet know when the agent began to go wrong? The answer likely depends on signals from identity and agent-governance layers that sit outside the backup platform.
Everyone Now Protects Agents. What Separates Them?
The field is crowded. Rubrik (Agent Rewind, plus a same-day MCP launch), Commvault (AI Protect), Druva (AI Resilience), and Veeam (Agent Commander) all now claim some version of agent protection, and most of it, like Cohesity’s, is early, narrow in platform scope, or both.
To us, differentiation will come down to the breadth of agent platforms covered, the ability to validate that a recovery point is clean before restoring to it, and the data context that tells a team what an agent can reach. Cohesity has credible assets in the last two, from clean-room recovery to its data security posture work, though this is still a nascent area.
Security operations is the other test. Backup-side detection is a high-fidelity signal for an overloaded SOC, and Cohesity already feeds detection data into CrowdStrike’s Falcon platform. Integration is the requirement buyers raise most consistently in our decision-maker research, so two-way SOC integration (high-confidence signals out, API and playbook hooks in) is where Cohesity can turn a strong position into a stronger one.
A Constructive Path
The most important step is to get beyond Bedrock quickly, since enterprises running agents across Microsoft, Google, Salesforce, and others will not standardize on one platform for any backup vendor’s convenience. Pairing rollback with identity and agent-governance signals would help teams identify the right recovery point and determine which actions require compensating steps outside the agent.
There is also a demand-side opening. In our survey, 44% of respondents said they are intentionally delaying internal copilot or agent deployments until better security guardrails are in place, and a credible way to undo an agent’s mistakes is one of those guardrails. Positioned that way, agent resilience becomes a reason to deploy rather than only a cost of deploying.
And we would lead with the business-continuity story from Cohesity’s own research rather than with category claims. A CISO can take the 78% finding upstairs, which is more than most agent announcements this quarter can say. Cohesity should also claim its place in the security stack without hedging: recovery is part of the cyber program, not an adjunct to it.
For more information, read the full announcement from Cohesity.
What to Watch
- Which agent platform follows Bedrock, and how fast? Microsoft and Google are on the roadmap, and the pace of those additions will show how portable the architecture is.
- Will rollback grow into compensating actions? Restoring agent state is the first step, and reversing what an agent did in other systems will likely require identity and agent-governance partners.
- Who owns agent resilience? The backup team, the CISO, and the AI platform owner each have a claim, and the answer will shape how Cohesity and its rivals sell it.
- Does agent recovery become a checkbox? With Rubrik, Commvault, Druva, Veeam, and Cohesity all claiming it, clean-room validation of agent state may be what separates offerings.
- What will Autonomous Cyber Resilience run without a human? Cohesity plans to add more automation as the vision moves toward commercial availability, so the first actions it trusts to run unattended will say a lot about its confidence.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Read the full Futurum Group Disclosure.
Other Insights from Futurum:
Cohesity DSPM Bet Blurs the Line Between Visibility and Recovery
The Hard(er) Challenge in Agent Governance Is Authorization
RSAC 2026: The AI Tragedy of the Commons and the Future of Agentic Security
A Loud Floor and a Quiet Gap: Security Summer Camp 2026
So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident
Author Information
Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.
Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.
Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

