All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Cohesity sells backup, malware scanning of backups, and cyber recovery to large enterprises and governments. Its CFO told TechCrunch that the two businesses it merged in December 2024 shared under 5 percent of their customers. The small overlap is what the cross-sell plan depends on. It said it would train one sales force to sell both product lines rather than running two. RBC Capital Markets research puts the combined company at 19 percent of a fragmented market, built from its own 5 percent plus the 14 percent it acquired. The distinctive part of its record is federal. It holds a US government cloud authorization at the FedRAMP Moderate level and a place on the US Department of Defense approved products list. An independent review reports more than 300 federal organizations using it.
| Description | Cohesity sells enterprise data protection and cyber resilience software. Its Data Cloud platform protects workloads across cloud, on-premises, and SaaS environments, speeds recovery, and surfaces insights from the data it holds. | [f1] |
|---|---|---|
| Founded | 2013 | [f2] |
| HQ | Santa Clara, California, United States | [f3] |
| Latest funding | Series H led by Haveli Investments, funding the combination with the Veritas enterprise data protection business | [f4] |
| Product | What it does |
|---|---|
| Cohesity Data Cloud | Data protection platform covering cloud, on-premises, and SaaS workloads, sold as backup as a service, self-managed software, or through a service provider. |
| NetBackup | Enterprise backup software with storage-agnostic immutability, hash-based malware and indicator-of-compromise search, and orchestrated recovery. |
| NetBackup Appliances | Turnkey on-premises backup appliances running NetBackup software, deployable as an isolated recovery environment. |
| Cohesity Threat Protection | Scans backup snapshots for malware using Google Threat Intelligence and Sophos feeds, with custom YARA rules for threat hunting. |
| Cohesity DSPM | Data security posture management, powered by Cyera, that finds and classifies sensitive data across structured and unstructured sources. |
| NetBackup IT Analytics | Reporting and predictive analysis on backup and storage estates across hybrid and multicloud environments, on-premises or as SaaS. |
| Cohesity DataProtect | Hyperscale backup and recovery for enterprise workloads, positioned against ransomware within the Cohesity Data Cloud. |
| Cohesity Identity Resilience | Identity security, protection, and recovery for Active Directory, Entra ID, or a hybrid of the two. |
| Cohesity FortKnox | Cyber vaulting that keeps protected data in an immutable, air-gapped environment for recovery after an attack. |
| Cohesity Gaia | AI-powered conversational search over the enterprise data Cohesity protects. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Cohesity Threat Protection scans backup snapshots for malware and supports threat hunting, Cohesity DSPM classifies sensitive data, and the Cohesity Data Cloud restores data, applications, and identity directories after an attack. These lines are mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | The buyer is the enterprise or agency that has to get operations back after ransomware, and the pain is stated the same way outside the vendor: Forrester records customers switching away from ill-fitting backup tools, and an independent federal reviewer writes that legacy backup tools fall short when ransomware targets critical systems. [s12, s13, s17] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Product pages document the mechanisms, and an independent reviewer exercised the backup and restore path: FedTech backed up VMware vSphere and Amazon Web Services environments and reported consistency across environments as a strength. Common Criteria EAL2+ certification and a NIST-validated FIPS 140-2 cryptographic module add third-party evaluation of the platform itself. [s13, s2, s5, s3] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is credible and documented, with Forrester recording customers opportunistically switching from ill-fitting backup solutions to modern data resilience-oriented solutions. Buyer-side demand inside the last year rests on a single independent signal, an October 2025 review reporting that agencies face growing pressure to modernize their data protection strategies. [s12, s13] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | The operating team has verifiable prior builds at scale. Sanjay Poonen was COO at VMware, Eric Brown led Informatica's IPO as CFO, and founder Mohit Aron co-founded Nutanix as CTO before starting Cohesity in 2013. [s6, s9] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 5/5 | Traction is corroborated outside the company: RBC Capital Markets research puts Cohesity at 19 percent of a fragmented market, and a FedTech review reports more than 300 federal organizations using the product, naming the US Department of Agriculture. Cohesity's own pages add a Leader placement in the 2026 Gartner Magic Quadrant and a Peer Insights Customers' Choice recognition. [s11, s13, s17, s18] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The single margin figure in the record is the company's own pro forma 28 percent for the year to July 2024, and CNBC reported that the profitable side of that combination was Veritas while Cohesity's own business was unprofitable. The transaction also added a JP Morgan term loan alongside the Series H. [s7, s11] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Buyers and analysts place Cohesity without vendor coaching. Cohesity records a Leader placement in the 2026 Gartner Magic Quadrant for backup and data protection platforms, its seventh consecutive year, and Forrester writes about it inside a named data resilience market alongside Veeam, Commvault, Dell, Druva, IBM, OpenText, and Rubrik. [s17, s18, s12] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 4/5 | A platform vendor bundling backup would still meet Cohesity's federal credential set: FedRAMP Moderate authorization, a DoD Information Network approved-products listing, GovRAMP authorization, and authorizations to operate on classified federal networks, with an independent review reporting more than 300 federal organizations using the product. The cited record carries no measure of how quickly a rival could match them. [s2, s13] |
Enterprises and agencies buy Cohesity to get back to work after a ransomware attack. Forrester's Brent Ellis records customers opportunistically switching from ill-fitting backup tools to data resilience products as they adopt cloud architectures and generative AI. FedTech's John Breeden II makes the same point for government: agencies face growing pressure to modernize their data protection strategies, and legacy backup tools fall short when ransomware targets critical systems.
The category is large and it has moved. Cohesity's own announcement cites IDC sizing the data replication and protection software market at $12.3 billion in projected 2024 vendor sales. Gartner has retitled the report several times since 2014, from enterprise backup software and integrated appliances to backup and data protection platforms.
The stakeholders these pages name span more than one function. Cohesity's Data Security Alliance pitches integration into the security operations centre, and its threat protection line takes custom YARA rules for hunting over backup snapshots. Its Nasdaq customer story is told by a lead systems administrator, and names the Office of the General Counsel as the source of a data-residency requirement. [s12, s13, s7, s18, s4, s5, s16]
The Cohesity Data Cloud protects workloads across cloud, on-premises, and SaaS environments. It is sold as a service, as self-managed software, or through a partner who runs it. NetBackup, the NetBackup appliances, and NetBackup IT Analytics sit in the same portfolio after the Veritas transaction, and the NetBackup page cross-sells Cohesity FortKnox for immutable cloud storage.
The security functions cover both the backup copies and the wider data estate. Threat Protection scans snapshots using Google Threat Intelligence and Sophos feeds, and takes custom YARA rules. NetBackup adds hash-based blast-radius malware and indicator-of-compromise search. DSPM finds and classifies sensitive data across structured and unstructured sources, and Cohesity brands it as powered by Cyera.
An independent reviewer exercised the product rather than reading about it. FedTech's John Breeden II backed up VMware vSphere and Amazon Web Services environments and reported consistency across environments as a strength. He also reported that agencies can expand backup capacity without disruptive forklift upgrades. [s1, s3, s5, s15, s13, s19, s7]
Cohesity competes inside a crowded top group. Forrester names Veeam, Commvault, Dell, Druva, IBM, OpenText, and Rubrik as formidable competition in the same market. Cohesity publishes comparison pages against Rubrik and Commvault. It records a Leader placement in the 2026 Gartner Magic Quadrant for backup and data protection platforms, its seventh consecutive year.
Scale is the argument the company makes. RBC Capital Markets research, reported by CNBC, puts Cohesity at 19 percent of a fragmented market, built from its own 5 percent plus the 14 percent it acquired. Blocks and Files reported Commvault at $839.2 million and Rubrik at $627.9 million of fiscal 2024 revenue, both smaller than the combined Cohesity.
The Veritas transaction defined the current portfolio. Cohesity took NetBackup, the NetBackup appliances, and the Veritas Alta data protection offerings. Backup Exec, InfoScale, and the data compliance business went to Arctera, a separate company that Carlyle still owns. [s12, s24, s17, s11, s8, s7, s10]
The customer figures come from the company. TechTarget reports more than 12,000 customers and a presence in 85 of the Fortune 100, attributing both to the vendor. Blocks and Files relays the vendor's claim that Veritas supplied more than 10,000 of that base.
RBC Capital Markets research puts the combined company at 19 percent share, which measures where Cohesity sits rather than how it is performing. A FedTech review reports more than 300 federal organizations using the product and names the US Department of Agriculture. Cohesity's own pages record a Leader placement in the 2026 Gartner Magic Quadrant, its seventh consecutive year, and a Peer Insights Customers' Choice recognition.
The growth plan is a cross-sell. Cohesity's CFO told TechCrunch that the two merged businesses shared under 5 percent of their customers. The company said in December 2024 that it would train one sales force to sell both product lines rather than running two. [s10, s8, s11, s17, s18, s13, s9]
The chief executive and the finance chief come from large enterprise software rather than from backup. Sanjay Poonen was COO at VMware, where the company says he helped double revenue from about $6 billion to $12 billion. Eric Brown, now CFO and COO, led Informatica's IPO as CFO, raising $1 billion in proceeds at a $10 billion enterprise value.
Mohit Aron founded Cohesity in 2013 and co-founded Nutanix as its CTO in 2009. His title on the leadership page is now Founder Emeritus, so the founding engineering pedigree is no longer part of the operating team.
The board carries security weight. Kevin Mandia, the founder of Mandiant, is an independent board member. The leadership page lists a senior vice president whose title covers cloud, security, and NetBackup engineering, so one leader's stated remit covers the acquired product line as well as the original one. [s6, s9]
Cohesity records its certifications on a public trust centre: FedRAMP Moderate authorization, GovRAMP authorization, Common Criteria EAL2+, a FIPS 140-2 Level 1 validated cryptographic module, SOC 2 Type II for the Helios SaaS platform, and ISO/IEC 27001:2022 for the cloud services. Cohesity says the SOC 2 Type II audit of that platform runs annually.
The federal position goes past cloud authorization. The Defense Information Systems Agency has certified the platform for the DoD Information Network Approved Products List. Cohesity says it maintains authorizations to operate inside classified Department of Defense, Department of Energy, and US intelligence community networks.
The product security programme is documented rather than asserted. The trust centre describes STRIDE threat modelling in design, regular third-party penetration testing, and REDLab, where Cohesity says it validates products against live malware and modern attack techniques in an air-gapped environment. [s2, s13]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Rubrik | competes with | Forrester names it among the vendors that still represent formidable competition, and Cohesity publishes a comparison page against it. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Commvault | competes with | Forrester names it as competition in the same market, and Cohesity publishes a comparison page against it. | |
| Veeam | competes with | Forrester names it among the vendors that still represent formidable competition in data resilience. | |
| Dell | competes with | Forrester names it among the vendors that still represent formidable competition in data resilience. | |
| Druva | competes with | Forrester names it among the vendors that still represent formidable competition in data resilience. | |
| Arctera | adjacent | Holds the Veritas product lines that were left out of the combination, namely InfoScale, Backup Exec, and the data compliance business. |
Add analyzed competitors to compare them side by side with Cohesity.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
Cohesity's strongest barrier is its federal position. It holds FedRAMP Moderate authorization, a place on the US Department of Defense approved products list, and Common Criteria certification. An independent review reports more than 300 federal organizations using the product. Several parts of the product come from other vendors. The malware feeds are Google Threat Intelligence and Sophos, and the classification engine carries Cyera's branding. Forrester describes data resilience tools as sticky. The reviewed record does not size what leaving Cohesity would cost a customer. No cross-customer data asset appears in that record. Outside that federal position, the differentiators the record documents are reproducible by a funded rival.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Cohesity sells software rather than judgment. The same platform ships as a service, as self-managed software, or through a partner who runs it, and the packaging list names an expert-led incident response service alongside the software capabilities. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Forrester records that data resilience tools are sticky and that moving is slowed by the need to keep recovery capability for existing backups and by the production systems the tool connects to. The cited record does not size that migration, so what it documents is friction rather than an evidenced exit cost. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 3/3 | Cohesity holds its own federal authorizations: FedRAMP Moderate, a DoD Information Network Approved Products List certification from the Defense Information Systems Agency, GovRAMP authorization, Common Criteria EAL2+, and authorizations to operate inside classified Department of Defense, Department of Energy, and US intelligence community networks. An independent review reports more than 300 federal organizations using the product. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | The documented mechanisms are systems work rather than dashboards: instant mass restore of virtual machines from unlimited fully hydrated snapshots, an immutable multi-protocol backup target reachable over NFS, SMB, or S3 with unified permissions, and hash-based blast-radius malware and indicator-of-compromise search across a backup estate. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The buyers are regulated enterprises and governments. TechTarget reports a presence in 85 of the Fortune 100 that it attributes to the vendor, an independent review reports more than 300 federal organizations, and Cohesity says it maintains authorizations to operate inside classified Department of Defense, Department of Energy, and US intelligence community networks. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The Cohesity Data Cloud is a control layer over the customer's data estate rather than a point tool, protecting workloads across cloud, on-premises, and SaaS from one interface. The applications and identities it protects run without it, which places it at the platform level. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The reviewed record names no non-public cross-customer dataset. The malware feeds come from Google Threat Intelligence and Sophos, the classification engine carries Cyera's branding, and what accumulates is each customer's own backup estate. |
Large enterprises are the buyers the independent record names. TechTarget reports a presence in 85 of the Fortune 100 that it attributes to the vendor. Federal government is a declared segment of its own, and the organizations Cohesity lists working with there are federal civilian agencies, law enforcement agencies, Department of Defense and intelligence agencies, and the systems integrators and ISVs that serve government agencies.
A midsize line exists under its own brand. Cohesity Essentials offers ransomware resilience across on-premises, multicloud, and SaaS environments for organizations with lean IT teams, with as-a-service, self-managed, and appliance deployment options.
In the Nasdaq customer story, compliance shaped the purchase. That story turns on data-residency compliance that the Office of the General Counsel asked for.
The AI story is about operating the platform rather than defending AI itself. Cohesity Copilot handles conversational reporting, anomaly detection, and operational actions. RecoveryAgent orchestrates recovery groups and blueprints. Both are available today.
Cohesity Maestro extends that through the Model Context Protocol. Announced in June 2026, it is built on the open MCP standard so that Anthropic Claude, OpenAI ChatGPT, and Google Gemini deployments reach the platform without custom connectors. The MCP interface and the additional agents are expected later in the year, so this is announced capability rather than shipped capability.
Detection runs over the backup copies. Threat Protection scans snapshots on schedule or on trigger, using Google Threat Intelligence and Sophos feeds, and accepts custom YARA rules for hunting. DSPM classifies sensitive data across structured and unstructured sources, and Cohesity brands it as powered by Cyera.
The go-to-market plan after the merger is a cross-sell run through one organization. Cohesity's CFO told TechCrunch that the two businesses shared under 5 percent of their customers. In December 2024 the company said it would train one sales force to sell both product lines and group reps by vertical rather than running two teams.
Partners are a stated route to market rather than an exception. The same platform can be bought Cohesity-managed, self-managed, or partner-managed, so a service provider can run it on the customer's behalf.
Cohesity records a Leader placement in the 2026 Gartner Magic Quadrant for backup and data protection platforms, its seventh consecutive year, and a Peer Insights Customers' Choice recognition. Gartner positioned it on completeness of vision and ability to execute.
Cohesity packages the platform in two editions. Core is described as covering essential data protection and ransomware remediation. Enterprise, the edition the vendor recommends, is described as covering protection against sophisticated cyber threats plus rapid response and recovery in critical situations.
The packaging page also names capabilities sold as add-ons rather than folded into an edition, so what a buyer pays depends on which functions it wants. Threat hunting and monitoring and a Cyber Event Response Team incident-response service both appear among the capabilities on offer.
No price appears on the reviewed purchase pages. The packaging page lists what each edition includes without a figure, and the Essentials page describes predictable pricing for midsize buyers without publishing a number, so a buyer has to contact sales to learn cost.
Cohesity offers three ways to run the same platform. It can be consumed as a service, run as self-managed software in public clouds and on-premises on certified platforms, or handed to a service provider to operate.
The backup appliances are integrated with NetBackup software. They ship as a turnkey deployment and can be configured as an isolated recovery environment.
The NetBackup estate gets a stated migration posture. Cohesity's NetBackup page frames the options as keeping, extending, or transforming an existing environment, and cross-sells Cohesity FortKnox as immutable cloud storage into that estate.
Cohesity records FedRAMP Moderate authorization, GovRAMP authorization, Common Criteria EAL2+ certification, a FIPS 140-2 Level 1 validated cryptographic module, SOC 2 Type II for the Helios SaaS platform, and ISO/IEC 27001:2022 for the cloud services.
Federal reach goes past cloud authorization. The Defense Information Systems Agency has certified the platform for the DoD Information Network Approved Products List, and Cohesity says it maintains authorizations to operate inside classified Department of Defense, Department of Energy, and US intelligence community networks.
The product security programme is described in operational terms. The trust centre records STRIDE threat modelling in design, regular third-party penetration testing, and REDLab, where Cohesity says it validates products against live malware and modern attack techniques in an air-gapped environment. An independent review reports more than 300 federal organizations using the product.
The ecosystem is built around the security stack a customer already owns. The Data Security Alliance publishes integrations that include CrowdStrike threat intelligence feeds, Zscaler Data Protection, the Wiz cloud-native application protection platform, CyberScan powered by Tenable, and Semperis for identity threat response. Its stated purpose is to put anomaly detection and data protection into detection, response, and recovery workflows.
The platform also hosts third-party code under vendor control. Cohesity digitally signs every app intended for the Cohesity Marketplace, and the platform will not execute an unsigned or improperly signed app.
Cohesity Maestro is the openness argument. It is built on the open MCP standard so that Anthropic Claude, OpenAI ChatGPT, and Google Gemini deployments reach the platform without custom connectors. The interface is expected later in the year the announcement was made.
The chief executive and the finance chief come from large enterprise software rather than from backup. Sanjay Poonen was COO at VMware, where the company says he helped double revenue from about $6 billion to $12 billion. Eric Brown, now CFO and COO, led Informatica's IPO as CFO and raised $1 billion in proceeds at a $10 billion enterprise value.
Founding technical credibility sits at one remove. Mohit Aron founded Cohesity in 2013 and co-founded Nutanix as its CTO in 2009. His current title is Founder Emeritus.
One executive's title covers the merged portfolio. The leadership page lists a senior vice president for cloud, security, and NetBackup engineering, so one leader's stated remit covers the acquired product line as well as the original one. Kevin Mandia, the founder of Mandiant, is an independent board member.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Cohesity Data Cloud platform overview | official | 2026-08-18 |
| f2 | TechCrunch: Cohesity completes its merger with Veritas | press | 2026-08-18 |
| f3 | Cohesity Maestro press release dateline | official | 2026-08-18 |
| f4 | TechTarget: Cohesity completes acquisition of Veritas | press | 2026-08-18 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.