Why Cybersecurity Awareness Month means something different this year
Every October, Cybersecurity Awareness Month asks organizations to pause and check their defenses. This year, it feels more urgent than ever. Why? The adversary is now automated. Agentic AI now writes malware, probes for misconfigurations, and adapts mid-attack without having to wait for a human operator to give the next command.
You’ve no doubt seen the stories of rogue AI models that have exploited sandbox escapes to breach multiple organizations, delete local files and databases, and wipe an entire company’s infrastructure. We saw what happened this past July when OpenAI models being evaluated for cyber capability exploited a zero-day and ran roughly 17,600 actions inside Hugging Face’s network before it was contained. Given these facts, it’s not surprising that 53% of security leaders named AI-powered attacks as their primary challenge this year.
While these AI-powered attacks have been grabbing all the headlines, a second exposure is accumulating on a longer timeline. Nation-state actors and well-resourced criminal groups are exfiltrating encrypted data today, on the assumption that quantum computing will break current encryption within the decade. This means data stolen this month could be readable in plaintext five years from now.
If reading this has got you worried, you aren’t the only one. At Everpure, we’ve been hard at work turning your data layer into an active defender.
The active defender promise and what it means for you
An active defender architecture does more than simply build walls. It assumes the perimeter will be breached, embeds security and anomaly detection at the data layer, and recovers automatically when something gets through. It’s this premise that the Everpure architecture is built on, and this October, we’re extending it across three pillars of cyber resilience: built-in security, connected detection, and dynamic response and recovery.
Figure 1: Everpure delivers cyber resilience designed for this new age of AI-powered threats, focused on both preventing an attack and recovering swiftly from one.
1. Built-in security
Post-quantum cryptography for data in flight and at rest closes the harvest-now-decrypt-later exposure on hardware you already have installed. AES-256, the industry standard for encrypting data at rest, is already built to withstand quantum attacks, but public-key exchange does not. In-flight data is where the exposure sits. Commercial National Security Algorithm Suite (CNSA) 2.0 phases out non-compliant equipment by December 31, 2030. Because Everpure encryption is software-defined, moving onto new algorithms happens through library and protocol updates, and our Evergreen® subscription covers hardware upgrades that firmware alone cannot do.
Key Management Interoperability Protocol (KMIP) support for Portworx® keeps encryption keys in your own external key manager, so rotation, revocation, and access stay with you rather than the storage vendor. Each tenant gets its own key, which enhances secure multi-tenancy, especially for service providers and sovereign cloud platforms. Rotation happens server-side with no data re-encryption.
Figure 2: This diagram shows how KMIP support for Portworx centralizes key management, ensuring secure multi-tenancy.
PCI-DSS assessment in Pure1® brings fleet-level security scores, compliance checks, and appliance-level findings into one view. Appliance insights, open anomalies, and fleet-wide common vulnerabilities and exposures (CVEs) and their severity surface through the security assessment APIs, so teams work the real risk first. Results are repeatable, which is what audit preparation actually requires. Everpure Fusion™ fleet policy sits alongside this, moving the unit of configuration from the individual array to the fleet.
2. Connected detection
Enhanced anomaly detection in Pure1 delivers fleet-wide anomaly detection and correlation, widening both what the platform watches and how deeply you can drill down. It monitors data reduction ratio, capacity, latency, IOPS, bandwidth, volume changes, and snapshot counts across fleet and appliance views. More importantly, it now watches identity behavior: failed and unusual logins, unseen IP addresses, unusual time zones, brute-force behavior, and password spraying. Appliance-level insight names the affected volumes and their recent snapshots, so triage and the choice of a recovery point happen in the same place.
Fleet visibility for Veeam lets you register the Everpure Fusion fleet once and manage protection across all FlashArray™ systems from Veeam. Pure1 anomaly detection flows through the Incident API, with Everpure Fusion adding storage and workload context so affected restore points can be flagged for investigation.
Everpure Fusion-enabled anomaly workflows for Commvault turn a Pure1 storage anomaly into a workload-aware context. Everpure Fusion identifies the affected storage resources and correlates them with IntelliSnap-protected clients and VMs, raising events in Commvault Cloud where Threat Scan and other investigation and recovery workflows can take over.
Figure 3: The combination of Everpure and Commvault enables accurate anomaly detection, investigation, and recovery workflows across your data.
Rubrik for volumes brings FlashArray volumes and protection groups into Rubrik Security Cloud as first-class protected objects under the same SLA policies, RBAC, and reporting as other workloads. Rubrik uses Purity Changed Block Tracking to move only changed data, without a hypervisor in the path, while SafeMode™ Snapshots provide fast local recovery and Rubrik provides off-array protection for longer-term recovery. The result is one policy-driven protection model across the storage and backup layers.
3. Dynamic response and recovery
The Unified Data Protection Catalog in Pure1 brings snapshots, SafeMode settings, replication, recovery points, and protection metadata into one fleet-wide view with RPO and expiration. Each object connects to its own lineage, with downloadable evidence of how data was recovered. Protection gaps, policy drift, immutability issues, and RPO exposure surface as findings, so recovery readiness is something you check rather than assume.
Portworx DR with Red Hat Advanced Cluster Management moves Kubernetes disaster recovery out of a multi-step CLI workflow and into the OpenShift ACM console. The MultiCluster Operator handles kubeconfig exchange, cluster pairing, and backup location configuration, and runs preflight checks before a pair exists. Failover and failback are expressed declaratively as Kubernetes resources, from the console or through GitOps. Asynchronous DR is qualified on OpenShift 4.18 and later, at an RPO of 15 minutes and an RTO under 60 seconds.
Figure 4: Portworx DR with Red Hat Advanced Cluster Management configures and monitors DR for Portworx clusters from the OpenShift ACM console instead of a multi-step CLI pairing workflow.
ActiveDR™ for Everpure Resilience Service (now GA) adds snapshot-and-copy cycles for a replica link that streams changes to the recovery site as they happen, so the available recovery point stays close to current instead of waiting on the last completed cycle. Test failover, production failover, and failback to the original site are all built in. At scale, that’s RPO down to near-zero and RTO under 30 minutes for hundreds of VMs—among the fastest SLAs in the industry for cyber recovery.
The bottom line
The question for every security owner this October is not whether your prevention stack is merely good—it’s what happens in the hour after it fails. Would your storage signal reach the console where your responders actually work? Does anything in your architecture know which volumes come back first? Those are the gaps worth closing now, and Everpure is here to help you do it.











