Skip to content
TrackPodcasts
technologyMar 31, 202620:00

The Backup Layer Is a Security Layer | A Brand Spotlight at RSAC Conference 2026 with Anthony Cusimano, Chief Evangelist & Director of Solutions Marketing at Object First

About this episode

At RSAC Conference 2026, Anthony Cusimano, Chief Evangelist and Director of Solutions Marketing at Object First, joins Sean Martin on the show floor to break down what separates truly immutable storage from the checkbox version. The answer comes down to zero access: no command line interface, no root access, no administrative back doors at any layer -- for customers or for Object First itself.

Object First appliances are purpose-built for Veeam and ship with S3 protocol storage in automatic compliance mode, versioning, and object lock. Once data is written and a retention period is set, nothing -- no admin, no attacker, not even the vendor -- can touch it. Cusimano describes the architecture as a storage utility, not an administration platform: Veeam handles all backup policy and configuration; Object First handles one thing only, ensuring the data cannot be erased.

The statistics behind the design are sobering. According to Cusimano, 96 percent of ransomware attacks specifically target backup data -- a figure validated across four independent industry surveys. Organizations that rely on encryption alone, without immutable storage, are leaving a critical gap that attackers have learned to exploit. Many do not discover that gap until recovery is already underway.

Cusimano also makes the case for recovery testing as a security priority in its own right. He recommends full tabletop exercises that assume worst-case conditions: every admin credential compromised, active directory gone. Teams that run through this process discover gaps in their architecture that no amount of vendor documentation will surface. His practical tip -- collect coworkers' cell phone numbers before an incident -- reflects just how complete the communications blackout can be when directory services fail.

Two capabilities from Object First round out the conversation. Fleet Manager, launching May 6th, gives managed service providers and large enterprises a single SaaS dashboard to manage all Object First instances with unified telemetry and honeypot visibility -- with no backup data leaving the appliance. And the honeypot feature, included on every device at no cost, simulates a Veeam backup and replication server as a decoy. When agentic AI-driven attacks probe the environment, they interact with the honeypot exactly as they would a real target, triggering alerts that can surface threats days or weeks before a full attack develops.

This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight

GUEST

Anthony Cusimano, Chief Evangelist & Director of Solutions Marketing, Object First
LinkedIn: https://www.linkedin.com/in/anthonycusimano89/

RESOURCES

Object First website: https://objectfirst.com
ITSPmagazine RSAC Conference 2026 coverage: https://www.itspmagazine.com/rsac-2026-conference-san-francisco-usa-cybersecurity-event-infosec-conference-coverage

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight

KEYWORDS

Anthony Cusimano, Object First, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, ransomware, immutable storage, backup security, Veeam, data protection, RSAC Conference 2026, cyber resilience, absolute immutability, ransomware recovery, Fleet Manager, honeypot detection, managed service providers, zero trust storage

Get every episode summarized

Each time The ITSPmagazine Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

210 searchable segments. Every word is indexed and playable.

The Backup Layer Is a Security Layer | A Brand Spotlight at RSAC Conference 2026 with Anthony Cusimano, Chief Evangelist & Director of Solutions Marketing at Object First

The ITSPmagazine Podcast

0:00
20:00

Full transcript

The ITSPmagazine PodcastThe Backup Layer Is a Security Layer | A Brand Spotlight at RSAC Conference 2026 with Anthony Cusimano, Chief Evangelist & Director of Solutions Marketing at Object First. Machine-transcribed; use the interactive transcript above to jump the player to any line.

here we are here we are Anthony it's exciting right yeah and I got a new hat you did hey looks good on you I like the hat I like the white hat I like the purple I'm a fan of purple it's a good combo I like to fan I like the purple and the orange the orange contrast is good too yeah you guys got it going on so here we are at RSA C conference 2026 Anthony Kusumano how are you I'm doing great Sean how are you good good to see you and the short flow the floor show floor there we go if I can spit that out is buzzing might hear a little bit in the background good conversations this week so far oh my gosh yeah it's non-stop yeah you know last night they did the big opening the flood gates opened I've never seen so many people and a little corner of a show floor my life but it was just I'm surprised I have a voice there you go yeah that's that's good that's a good

sign yeah get to have some good conversations elevator pitch for object first just so we kind of level set folks what they're going to hear about today as we as we chat right so if you haven't heard of object first before you might have heard of Veeam data protection the largest data protection vendor on the planet so Veeam is excellent at what they do but when it came to Veeam customers and storage they were using they needed a little bit more and that's exactly where we come in object first is simply resilient storage for Veeam I would even go so far as to say the best storage for Veeam and what we deliver is absolute immutability absolute immutability yes and we had a nice chat about this before the show we did so I'm going to encourage everybody to listen to that conversation but refer to what that actually means right well unfortunately immutability and just immutable storage in general hasn't become a little bit of a buzzword marketing term you can go look on the website and control after immutability you'll find it there but oftentimes

it's not actually immutable if an admin can come in and disable it that's not immutability that's just a check box right if you can come in at a different layer and say the operating system the ESX host Veeamware layer you can delete that machine it's not really immutable so we had to create a new term to describe something that is absolutely immutable meaning once the data is written nobody no matter the amount of privilege admin hacker AI powered ransomware or even the vendor themselves can delete destroy or update that data once it is written so in the world of security when we start to make bold claims right right right you have to be able to back it up you absolutely how do you do that so for us it's twofold right you know object first our physical appliance we only do physical appliances by the way it is a purpose built solution we only support Veeam in fact Veeam did acquire

us earlier this year so that makes it really easy we're consuming one ingestion engine from Veeam we know exactly how they're going to send us the data over their smart object storage API we receive that data we put it in our immutable object storage and that's that but that's not enough right like we have to consider all of the layers like I mentioned before right so we do what's called a zero access approach zero access for any destructive actions to be taken against the storage layer the operating system the firmware the BIOS or any any typical way that someone could get into a platform command line interface root access or we offer none of that okay both for our customers those are all hard and also for ourselves right out the gate exactly that wasn't enough we do run on a hardened Linux operating system that we've customized our storage layer is object storage we're using s3 communications protocol but in addition it's automatically in compliance mode we use versioning and object lock so once that data is written it truly cannot be unwritten

for whatever the time period you set it to be very cool so there's the proof that there is the proof and then and then the other side of the proof is or when we often talk about securities like well it's so locked down right you can actually use it yeah so how does that scenario play on on the other side of the problem probably the most common conversation I have here with security minded folks right because I'm telling them hey you can't do anything with our product and they're like I don't like that and the the conversation is too full one it lends to incredible simplicity our box can be rack stacked and set up in less than 15 minutes because we really only let you do a couple of things you can turn on MFA you can create an s3 key you can create an s3 bucket you can turn on our honeypot feature which is a nice little detection trap right but it's just turning things on there's no turning things off there's no deletion and that does rub some people the wrong way yeah it's incredibly easy but what I tell them is this we are the storage utility right you're sending your data to our box and we're going to keep

it immutable we're not limiting your control from the beam side of things a beam admin still has the ability to turn on encryption set up there there's skill skill up macro repositories the way they want to you all of those settings that can be tweaked optimized managed from vene we let vene handle all of that our job is just to make sure once the data lands on us it cannot be deleted in any circumstance yep so yes you are sacrificing a little bit on the storage end but it's storage right right how much do you need to administer your storage anyway you need to be focused on your backup focused on other things right exactly if you're running a business so let's talk about the business yeah what are some of the sectors you work in well let's start that so what obviously regulated organizations probably have requirements to do so the things you offer so let's talk about that space for vene has such a large footprint when it comes to you know they are the largest data prediction that are on the planet and when I started an object first four years ago we only had a 64 terabyte box

in 128 terabyte box so kind of limited you know you could build a four node cluster of 128 and get just about a terabyte or a petabyte of data we have since expanded in both directions so we've got the mini which is a small tower form factor we've also got our 432 which is a 2U that has 432 terabytes of data and with vene scale and backup repository you can get beyond seven petabytes of storage using us so that means we fit in a lot of spaces right now I talk to a lot of folks in the education space right because educators they're limited IT budget they're limited IT staff they see us and like oh it's easy and it's secure simplicity yeah and you can prove it and we've actually seen this with some of our customers they've been hit by ransomware and like a school district was taken out they Sunday night show up they're like what's going on we have no access to our network we have no access to our virtual machines everything's down FBI shows up and they're like hey what's that thing with the orange bezel over there I guess our object first device that's

the only thing standing and they had to recover everything from our box because that was all that was left so I would say really we fit wherever ransomware dwells right pretty much everywhere yeah you know it's hard to hide from that it really is so the different types of organizations some that are mature take security seriously some who have good risk management program in place that actually do backups what's the range of organization that you find and they either come to realize they need secure backup and storage recovery or they already have something but they need something better and why do they need something better so maybe talk through so it's it's funny because it's either a conversation about education I'm usually telling them hey we've got a lot of data that says you know 64 percent don't have a meatable storage today like why don't need it I click the secure encryption I got encryption I'm good it's like that is not encryption is not

enough right so on the on the let's just say the sort of less informed side it's it's usually a conversation about education listen 96 percent of attacks and this is actually a statistic that has been validated by I think four different surveys now not just from us but from a lot of vendors 96 percent of ransomware attacks go after the backup data because they know if I can take out that backup data I've got you you're going to pay the ransom you cannot recover right so when there when they're trying to figure things out I usually try to say hey listen thinking about your storage what would happen if you lost it what's your recovery plan if you've even tested a recovery when and generally the conversation is known so then it's okay how do we get you in there how do we fit in what you're doing and that's a that's a pretty easy conversation to have we're pretty good at sizing scaling and figuring out how much a meatable storage a prospect needs it's not something that's very easy to figure out on your own sadly because you got to think about how long do I want to keep it if it's a full incremental incremental and another full like all that math has to be done

we do have a system that helps people figure out what's the right size for you now on the other side yeah I know everything about cyber security then it becomes a conversation really about let me tell you what we're doing to ensure this isn't just secure today this is secure for the future and a big thing we focus on is third-party penetration testing so once a year we take both our hardware as well as our source code and we give it to a really reputable third-party penetration tester and say go nuts they get a month with our box they get a month with our source code they give us a report back of any found vulnerabilities we will then go fix it give them back everything say all right try again and they give us a clean bill of health we actually take all of that information and post it publicly okay because it's not just a trust us trust them right like we are very much a zero trust organization and you should be questioning trust but verify all the claims of your vendor and we we make all of that public okay no secrets here yeah in terms of the recovery

because you said right have you tested that yeah the recovery process doesn't always work right the and whether or not you tested properly is another thing so it's talking about some of that and you you mentioned the school or there are other uses or use cases like that you can trust them sadly I think this is an area where they're just not enough attention and it's it's it's likely due to the fact that a lot of IT staff are completely overworked and they're just not enough time you know I come from the world of data protection I've been in it for over 15 years now and it doesn't matter where I am testing recovery is never the priority and really it should be because going through those operations making sure one you actually have backed up everything you need going to a tabletop exercise saying hey if we lost everything active directory our complete vSphere environment our source cutter repository how long does it take us to get back online because you could have the backup but if you had run through the operations it's it's almost like where's Waldo and that's

not a fun game to play when you are under the guide yeah try to recover what are some scenario or pieces that organizations often miss yeah so this is where I start giving advice basically saying if you can carve out the time and you should carve out the time run through a full tabletop exercise and assume the worst breach imaginable assume you yourself through the IT admin all your credentials are leaked to everything what does that mean for you like write everything down disable your access to all of that and run through a full recovery in a safe environment like if you can create a B test environment run through that is it power on does it connect like how does your what does your DNS look like afterwards and it's such an illuminating process for folks because they're going to find every single gap which will actually help them then go back into their architecture and say hey we need a lot more zero trust in here we need a lot more segmentation another tip I offer everybody is make sure you have added all of your coworkers on LinkedIn and have their cell phone numbers

because you are losing active directory every single time or enter ID or whatever it is you have that your communications protocol it's going to be gone so thinking about all of those steps ahead of time assuming the absolute worst that will get you to a better state of recovery the problem really comes down to you can I find the time to be this right and that's that's really a conversation I recommend everyone have with their their directors their managers push that upwards and say hey if we're down we're expecting two weeks of recovery time we could get it down to three days but we got a car about the time to prioritize getting there what does some of the most mature organizations look like because I know we talk about best practices and networking segment and network control access and you have MFA and all other best practices like that you recommend and other like really mature organizations that say we're going to run our core infrastructure in one environment and that's one backup and then our our front offices in a different place and but what are some things you see there you know who has this the hardest is managed service

providers and service providers in general right right because they have their own right they have their own cooking they're working on and then every single one of their clients and I'll give you a little bit of a sneak preview on May 6th we're actually launching a new utility called fleet manager okay and what that does is it allows you to hook up all of your object first instances both on-site off-site to a SAS cloud application that we've created uses enter ID so you simply log in as long as telemetry is enabled on your device it will create a visibility report for every single device you have so if you are a service provider manager's provider and you've got hundreds of clients it's probably a nightmare all ready just to manage everything you've got in there we're trying to make that a little bit easier okay on the backup storage side so you get a complete holistic view all of your data all of your health but none of the backup data goes there we we understand like some things need to stay secret so we're only sending up our telemetry health data you get that full report you get that full understanding if their if your customers

have honey pot mavered yeah and they're getting that that trap data someone's trying to do a brute force entry that's going to show up yeah so you get that single pane of that glass view for everything in your environment and that that is truly the hardest thing yeah the bigger you are the more you scale even if you're not a service provider you're still a large enterprise you've got multiple sites you probably got multiple IT teams that unification especially when you've got all kinds of different vendors everywhere just becomes a management nightmare yeah and when I want to talk up we yeah briefly touched on in the last chat yeah the honey pot I love that technology and it's so powerful you don't want to wait for no the need to recover right if you can alert this is where it kind of the security folks should love this capability absolutely if I can get an alert where maybe the endpoint detection and protection piece didn't pick it up and and it's clearly something going after my data that's that's powerful thing so describe how the honey pot so we just like everything else we made it really easy you go into our settings

you click enable honey pot and if you want to give it a custom IP address you can't and it's on and what it does is it actually simulates a beam backup and replication server in a segmented portion of our appliance so there's no risk of it leading into any of your backup data not that there was any risk of that anyway but we always want to make that clear this is completely segmented yeah right when it's on it looks it smells it acts like a VBR server so if a bad actor is probing the environment and that looks like the first thing I want to take out and we know ransomware likes to dwell it likes to hang out and take its time but it is probing it is trying to see what it can get into this is a great way to detect something days if not even weeks early yeah so not only do you get that detection we're telling our customers like look this is going to help you bridge the conversation between your backup admin and your security team like we're going to help you guys out and I think that's a good thing we want to see backup and storage become more

ingrained with security that's why we're at RSA yeah we see it as a very key part of your security strategy and honey botches a great way to start that conversation but also say we're helping out here right so the the bad actors are smart right and they have tools yes and technology yes they do I'll say the two letters we have I won't say them but the two letters we know I knew you're going to feed everything but I guess the point is they can detect some of these things but because you know that environment so well you can present it in a way that isn't it hard to detect that it's you know that's the goal right and I I think the the advantage here with the two letter word we're not going to say that's becoming so aggressive right these agentic attacks where it is little servers talking to other little servers and they're all multi-pronged approach just reaching their tentacles and everything they're not smart enough to know that a honey pot's not real right so you're going to be able to detect things even earlier than even would say a human was doing it

right it's not programmed to think that way yeah it just sees oh this is a VBR server yeah I don't know any different yep and the second that happens we're sending up alerts we're sending out emails hey you're getting probing activity here there's like brute force slogans happening here we should probably look at this the service inside your your infrastructure and just make sure it's okay everything's behaving the way you want it to be but I think it is a great ad and again it takes seconds to turn on it costs you nothing to do it and we've included it with all of our object first devices so every single of our customers just gets it in no cost even they even let the little tower in the long guy yes yes the little guy does it too our object first minis ah well Anthony it's always a great chat with you always great shot I'm going to give you the final word what what's the common thing customers say after they either take on your new technology or have to use it for recovery so they're a common theme there they're actually it's kind of

funny because the conversation getting to the the the sale is always about we are secure we're going to give you something that is absolutely immutable there's no way that a bad actor or even you can get in there and destroy your data so they they you know they believe us on that and they should they should trust us although zero trust but every single time I talked to a customer that set up on our boxes they're like holy cow I that took five minutes like I did not could not believe how easy it was to configure this thing and get it hooked into beam I was riding my backup data in ten minutes time and it just simplifies my operations and I don't have to worry about it it's powerful yeah it's powerful well it's great chatting with you always great chatting good luck at the show thank you thanks everybody for watching spain tune for more please connect to Anthony and the object first team if you're here at the show come get a authentic object first all right thanks everybody

More episodes

More from The ITSPmagazine Podcast

View all episodes →