Video summary
The interview features Vijay Pitchumani, Director of Product Identity Resilience at Rubrik, discussing the critical shift in cybersecurity focus toward identity protection as a primary defense against cyber threats. Pitchumani explains that while Rubrik originally specialized in data backup and recovery, the company has strategically extended its capabilities into security to address the fact that identity is now the most critical attack vector for 90% of security leaders. With non-human identities, such as AI agents, outnumbering human identities by a ratio of 50 to 1, the volume of potential entry points has surged. These automated entities often possess highly privileged access to critical business applications, making their protection essential. The core challenge lies not just in managing access permissions but in understanding and auditing the specific actions taken by these agents, ensuring that any malicious or inadvertent behavior is traceable, auditable, and recoverable.
To address these challenges, Rubrik employs a resilience strategy based on the concept of an "assumed breach," where attackers utilize stolen credentials to log in rather than relying solely on malware. The platform ingests activity logs from identity providers, Identity Governance and Administration (IGA) systems, and SaaS applications to stitch together the full context of an attacker's movements. This comprehensive view allows organizations to distinguish between legitimate changes, such as standard joiner-mover-leaver events, and malicious alterations. Rubrik's unique capability, known as "roll forward," enables customers to not only recover to a clean point in time but also to automatically remove all malicious changes that occurred between the breach and the current moment. This process effectively eliminates attacker persistence while restoring the environment to a safe and current state without disrupting legitimate business operations.
The discussion highlights Rubrik's deep integration with CrowdStrike, specifically through the use of Shardul AI within the Falcon platform, which allows for immediate recovery actions directly triggered by threat detection signals. Pitchumani notes that this synergy is vital as security operations evolve into autonomous environments where AI must sift through exponentially increasing volumes of data and alerts to separate signal from noise. While there are valid concerns about trusting AI with enterprise access, the industry conversation has shifted from questioning resilience needs to urgently solving how to implement it quickly enough to maintain business continuity. The integration empowers security teams to react instantly to threats, ensuring that when an incident is detected, the recovery mechanisms can be activated immediately to restore systems and data without significant downtime or loss of context.
Looking toward the future, Pitchumani outlines Rubrik's vision to provide end-to-end cyber resilience across the entire enterprise architecture, encompassing data backup, cloud infrastructure, identity management, and AI security. He emphasizes that traditional cybersecurity strategies are no longer sufficient in an AI-first world and that organizations must rethink their offense and defense models to tackle emerging threats like ransomware and supply chain attacks. The rise of frontier AI models and recent high-profile incidents has accelerated the need for robust resilience solutions that can handle complex, evolving attack vectors. Ultimately, Rubrik aims to position itself as a unified platform that helps CISOs secure their entire ecosystem, enabling the safe and productive use of AI while ensuring that businesses can recover rapidly from any incident, thereby securing the industry's future trajectory.
Read the full video transcript
Everybody, welcome back to Falcon 2026.
You're watching The Cube's live
coverage. This is where we're deep now
into day two. We started last night with
The Cube after dark. My name is Dave
Vellante. I'm here with Krista Case.
Krista, good to see you. You've been in
the analyst program all day.
>> I have.
>> Getting some, you know, the analyst
notebook. So, we're going to pick your
brain on that a little bit later, but
we're pleased to welcome VJ Pichumani,
who's the director of product
identity resilience at Rubrik. VJ,
thanks for coming on.
>> Thank you. Thank you for having me.
>> Good to meet you, and first time on The
Cube, yeah?
>> Yeah, it is.
>> A pleasure. So,
tell us about this identity resilience.
>> Yeah.
>> What is that? Is that a Is that a new
thing for Rubrik?
>> No,
yeah. First of all, thank you for having
me.
Rubrik has been doing identity
resilience for the last couple of years.
And so, from an identity perspective,
again,
identity continues to be the critical
attack path, right? Like, we speak to a
lot of security leaders. 90% of them
think identity is the most critical
attack vector that they have, and it's
extremely important to secure. So, from
a resilience perspective, Rubrik helps
customers effectively respond to cyber
attacks and restore the identities and
the access at, like, AI speed. And so,
that's the biggest problem that we solve
today.
>> Well, we were talking off camera. I
mean, Rubrik started in
>> backup, and then kind of the whole data
protection thing. And then, you were the
first people's vision to to move into
the security space.
I I I hesitate to call it a pivot, but
it was kind of a pivot, but really an
extension of your line. It's a security.
Went hard after that. Obviously, had a
very successful IPO around that. Um
I Now, identity, you've now got There's
human identities, and there's non-human
identities.
What kind of challenges and does that
present, and how is Rubrik solving that?
>> Yeah, yeah. I mean, and then you extend
that to this AI agent, which is also a
form of non-human identity. So, what we
are seeing is definitely
an increase in the volume of identities
that is absolutely happening. So,
non-human identities outnumber human
identities 50 to 1.
And
>> ratio 50 to 1 now?
>> That's That's You You can
You can look
at every report. The number keeps
increasing. It never keeps decreasing.
>> I was going to say, VJ, I've heard even
higher figures.
>> It's not going down, though.
>> It's not going down.
>> And so, the volume of identities and
then these non-human identities and AI
agents, they have
keys to the kingdom. They have highly
privileged access to your critical line
of business applications. And so,
protecting these non-human identities
becomes even more critical in this age
of AI. And so, we are hearing a lot
about how, you know, social engineering
is on the rise and effectively how admin
credentials get fished and, you know, uh
bad actors do bad things with these
non-human identities. So, just the
severity of protecting these identities
becomes ever more increasing. Yeah.
>> Certainly, VJ, and I think thinking
about resilience, I think it's really
important here because when we think
about agent identities, it's about more
than just the access, right? We used to
be kind of concerned about, you know,
the permissions and the access, but now
we also need to be concerned about the
actions that the agent is taking. So,
when Rubrik thinks about resilience for
identity
>> Yes.
>> can you talk to understanding the
context behind the action that the
identity is taking and kind of making
sure that you have that traceable,
auditable, and recoverable in the event
that, you know, whether maliciously or
inadvertently something goes wrong?
>> No, you you made a good point. So, the
way Rubrik thinks about identity
resilience is we think about assumed
breach, right? Attackers, they no longer
break in through malware, they log in
using these credentials. And so when an
attacker logs in and starts doing bad
things, Rubrik is able to start from the
identity providers. We ingest all of the
activity logs and are able to understand
what the attacker does inside of the
identity provider and then how do they
spread across the architecture, right?
So you start with the identity provider,
you go into your IGA systems, you go
into your SaaS applications. And so with
identity resilience, we are able to
stitch together that entire context on
what where the attacker was born, what
did they do in these systems, and what
actions they've taken. And we are now
able to rewind or restore back all of
those actions, ultimately eliminating
persistence for our customers.
>> And VJ, how do you determine what was a
legitimate change versus an illegitimate
change because, you know,
>> you know, I'm not going to want to roll
back everything, right?
>> Absolutely. So that's a great question
and this is a huge question our
customers have. So if you think about a
cyber recovery scenario, we talk about
this in three stages. Step Step one is
you recover back to a clean point in
time, which could be X days back when
the attack actually started. But then
between that step one, step two is
between the current point in time and
the clean point in time, you have
thousands and thousands of changes that
might have happened inside of your
organization. You have joiner, mover,
leaver events. You have people that have
been added to different groups, people
having elevated privileges. And so the
context is stored in the systems of
record. You have your HR systems which
holds who are the legitimate identities.
You have your IGA systems or your
privileged access systems who knows who
can actually do what inside these
systems. And you have the source of
truth in the SaaS systems. And so Rubrik
effectively integrates with all of these
systems, brings together the context to
classify legitimate and malicious
changes. And once you do that, we go one
step further by helping you to remove
those malicious changes. We call it roll
forward, where you not only recover
clean, but you recover clean and current
to the current environment. And so, we
take care of the automation end-to-end
from a cyber scenario.
>> So, you have technology, you can take a
mess, I think of Apollo 13, that movie
when they threw all the stuff on the,
you know, the table, said, "We got to
make a
a system that can help these guys
breathe." You take that mess,
>> Correct.
>> you un-chop it,
>> Yeah.
>> and then roll it forward so that it's
>> Correct. Safe.
>> Yeah.
>> How novel is that?
>> It's It's industry leading. Like, uh we
we recently announced roll forward, uh
and like, you know, we talked about it
at our forward event. And so, we are
introducing roll forward capabilities to
uh the identity provider, so Active
Directory uh is coming up pretty soon,
and then we're going to extend that into
Entra and even Okta as well.
Uh and so, yeah, we're seeing a lot of
excitement around this capability, and
like, you know, we're excited to get
this in.
>> B.J., you were You were saying, um
when we were talking off camera,
we were talking about security and
operations is the new
branding.
>> Yeah.
>> Explain. What What does that mean?
>> part of the the So, when we talk about
this exact scenario of responding to a
threat, this comes in the incident
response and like, you know, your
security operations control. So,
ultimately with Rubrik, we're trying to
bring together the security incident
response teams who rely on data across
the identity team and the line of
business teams to quickly respond to an
incident that happens. So, our goal with
the identity resilience platform is to
bring together these teams and give them
a single pane of glass to quickly
understand what's happening, what's
malicious, and quickly eliminate the
attacker. So, like, when we talk about
security and operations, we are helping
customers to operate the entire
operations process during a
>> So very complimentary to CrowdStrike.
>> Very very complimentary.
>> Their Their Their tagline is stop the
breach.
>> 100%.
>> Your guys You're all about responding
and recovering from that breach.
>> and so we announced today our
integration with Shardul AI. And so
we've had a very deep integration with
CrowdStrike. We integrate with the
next-gen identity security platform.
Today we introduced our integration with
Shardul AI. So with this new integration
we can now trigger recovery and roll
forward events directly from the Shardul
AI inside of CrowdStrike. And so we are
extremely complimentary and our
customers love that power because once
you detect a signal inside of
CrowdStrike, you can then immediately
recover and restore it inside of
>> So VJ, you know, we're hearing a lot
about kind of these autonomous security
operations or at least these, you know,
AI facilitated
both here at CrowdStrike. I had the
pleasure of sitting down with Rubrik at
Black Hat a couple weeks ago. And this
is it's a big step forward.
>> Yeah.
>> Can you talk to when you work with
customers, where do you see them being
most comfortable with trusting the AI
the AI
>> Yeah.
>> to take some automated actions
especially when think about resilience
and recovery
>> Yeah.
>> versus where the human still needs to be
in the loop in providing that critical
expertise and judgment.
>> no, it's a good question. So in in all
of our customer conversations uh
I've seen customers framed it as they
don't have a choice. They have to grant
access to these systems with AI.
Are they comfortable? Definitely not
because like that's what's keeping them
up at night. It's just how do these AI
systems securely access the enterprise
data and how do they make sure things
don't go wrong, right? And so this is
where I think like this is becoming a
board level issue for CISOs across the
world. And this is where Rubrik and our
entire cyber resilience story is
definitely resonating and can help a lot
with customers.
>> Well, the Me Too movement
moment now occurs hugging faces
created sort of a different conversation
at the board level. I mean, I think it
was
previously it was like, "How how are we
doing?"
>> Yeah.
>> Well, we could we we're not all green,
but we don't want to be all green cuz we
know there's a problem
that was kind of the previous
conversation. Then all of a sudden it
became
"Where are we exposed?
You know, how dangerous is this? What do
we do about it?"
>> Yeah.
>> "How much do you need to fix it?" You
know, "And how fast can you fix it?"
>> can you fix it? How fast can you
recover? How can you recover without any
loss of business context or business
continuity? That becomes a really big
challenge in the AI world.
>> How have How has that affected your your
business? You guys just announced good
quarters as usual, but how have you seen
the interest in what you guys do? Has it
been the Me Too has been a distraction?
Has it been a tailwind?
>> Uh I mean, it it's definitely been a
tailwind, I would say, and in the sense
of the conversations have just
accelerated. Because like now the
conversations are going from it's not
like I don't need resilience anymore.
It's more like, "Okay, there's an
awareness that I need resilience now,
and now how do I go about doing it?"
Right? So, definitely this the rise of
AI, the frontier models, and then Me Too
moment has really accelerated this
conversation significantly, and we are
having so many conversations around
identity and AI offerings, and how do
you implement resilience across the
board? And that's where Rubrik really
shines is the unified platform for
resilience.
>> You mentioned your announcement of
Charlotte AI and the integration there.
I was here when when George announced
Charlotte. I think it was 2 years ago.
Yeah. Gave a cool demo. Um
and he interestingly Chris didn't
mention it in the keynote today unless
they mentioned it after I had to leave
cuz we were doing the Cube.
What are you seeing in terms of of I
mean, the promise of Charlotte was it
was going to transform the security
analysts in the secops, you know, role.
>> What have you seen in terms of
Charlotte? The data from Qualtrics shows
that it's we're seeing an an uptick
>> Mhm.
>> in and getting high marks. What what are
you seeing?
>> Yeah, I think from from
conversations with our customers with
Charlotte, it's it's more around the
because of the volume of data that's
going up and then the rise of signals is
going up, you need a way to sift through
the signals very effectively and AI
provides that way to efficiently
separate the signal from the noise like
what Q says
ultimately use you use AI to respond to
these signals effectively, right? And
that's where with this integration
really shines because with Charlotte,
you can now effectively react to these
volume of signals that are coming up and
then integrate with Rubrik AI to
ultimately trigger these response
incidents ultimately ensuring they get
up and running pretty quickly. And so
that's what we've been hearing a lot
from our customer conversations overall.
>> Yeah, I would agree. I can share in some
of the sessions that we had with the
analyst track today, you know,
CrowdStrike was expressing similar
sentiments that really the job
especially if you're kind of
>> Yeah.
>> tier one security analyst is really
changing when it comes to, you know,
researching and detecting threats for
example. We even heard from some
practitioners today and I know it's been
really rapid.
>> the volume the volume
these agents interacting with these
systems is just going up exponentially
and that exponentially increases the
risk as well and this is where a lot of
the context comes in, a lot of the
alerting comes in which is very
valuable.
Yeah.
>> VJ, I had maybe one one more question
for you which was, you know, when we
think about Rubrik kind of combining
this insight and kind of ability to
recover on the identity side with your
more traditional data backup and
recovery. Seems to me like a move to be
able to recover, you know,
more holistic systems and maybe even
lean into being able to kind of
understand and start to recover business
state. I know we've heard that from
CrowdStrike as well that they're trying
to create these knowledge graphs to have
a better sense of the enterprise and the
state of the business. So, I guess can
you talk to
what should we read into that as as
being the strategy for Rubrik as well?
>> So, our vision is to provide cyber
resilience for the enterprise. And so,
today we do the data uh backup and
recovery, but we also do cloud uh data
backup. So, the data around M365 or
Salesforce. We do cloud infrastructure.
And then identity is the next uh
vertical that Rubrik is in, and then we
do the AI
uh security as well. And so, if you
think about the end-to-end story, our
goal is to bring together resilience for
the entire
uh architecture uh and make it like a
CISO's priority to ensure this this is
the right solution in this AI-first
world. And that's what we're really
going after because like when you have
the data, you ultimately ensure you're
able to recover the data quickly and
restore the data as well.
>> So, we talked a little bit about your
journey starting a backup recovery. I
think you've effectively sort of helped
us understand how that translates into
identity.
What do you tell the organization, the
CISO, that
and how do you help them not merely just
detect
>> Yeah.
>> what's going on? What are the actions?
What's the action item that they should
take to not just merely detect, but to
to to make sure that they can recover
their identity infrastructure? What's
your your action item to CISOs?
>> Yeah. So, I think my primary
uh takeaway that I tell in a lot of my
customer conversations is
AI is probably the biggest
transformational technology in at least
definitely my lifetime that we are
seeing. That demands a rethink towards
security. Like we the traditional way of
cybersecurity is no longer like going to
be helpful in this AI-first world. And
so when you think about rethinking
security, your offense and defense
strategies evolve. And resilience needs
to be part of this conversation. And
that's what like we really like enforce
when we talk to all of the CISOs across
the world because you really have to
rethink cybersecurity and think about
how cybersecurity evolves to tackle the
threats posed by AI. So, yeah.
>> We're seeing that as well, VJ, in
conversations with CISOs. For example,
you know, I think AI is accelerating it,
but when we think back even the last
several years, we saw the rise of
ransomware, we saw the rise of these,
you know, um
third-party supply chain attacks that I
think really raised the awareness
>> Yeah.
>> that even these mature security programs
are are going to potentially fail at
some point in time.
>> Face incident that was mentioned in the
keynote today is like just another
example of how we really have to rethink
security best practices. Yeah, you know,
I I
Sorry, I I didn't mean to interrupt you.
So,
carry on. Did Were you done?
>> no. Go ahead.
>> I just kind of skipped I'm glad you
mentioned the ransomware because I kind
of skipped over that that history of
Rubrik. I mean, WannaCry was another
tailwind for you guys, right? I mean,
that was
when you you probably could have taken
the company and just liquidated and
bought a bunch of Bitcoin at the time,
[laughter] but you decided hey, why
don't we go solve tech problems? So.
>> No, totally.
>> Good job doing that.
>> Yeah. No, absolutely. Funny.
>> Well, VJ, thanks so much for coming on.
I'll give you the last word. Your
thoughts on on Falcon
future for Rubrik.
>> Talking about talking before the
interview, it's been so vibrant and like
I think it's so exciting to see where
security is headed. like I think we are
at like a pivotal moment right now for
the entire industry and like it's about
securing this together and like you know
we are great partners with CrowdStrike
and Falcon and like we'd love to make
sure us as an industry
enable the safe use of AI because AI can
be really powerful in like how we you
know think about productivity for the
next 10 years. So I'm really excited to
see where this industry is heading.
>> Well it's been awesome watching the
ascendancy of Rubrik. You guys you know
helped you created categories multiple
categories and we're excited to see what
the what the future is. Thanks for
coming on the Cube.
>> Thank you for having me.
>> Thanks man.
>> You're very welcome. All right Dave
Vellante for Chris the case and Rebecca
Knight. This is day two of the Cube's
coverage of Falcon 2026. We'll be right
back right after this short break.