What actually shipped
Cohesity and HCLTech announced on September 2, 2026 that HCLTech's VaultNXT cyber resilience service now includes a managed clean room capability built directly on Cohesity's platform. The idea is straightforward but has been conspicuously missing from most enterprise recovery playbooks: instead of restoring production data directly back into a compromised environment and hoping for the best, the clean room gives security and data teams an isolated space to investigate what actually happened, validate that recovered data is not still carrying malware, and only then bring systems back online with confidence.
VaultNXT already combined cyber vaulting, forensic investigation, and validated recovery services as separate capabilities within HCLTech's broader resilience offering. The clean room addition wires those pieces together into a single governed workflow rather than a set of tools a security team has to stitch together manually while an incident is actively unfolding, which is precisely the moment when manual coordination between disconnected systems tends to fail under pressure and cost precious response time.
Why restoring the backup stopped being enough
For years, cyber recovery performance was measured almost entirely by recovery time objective, essentially how fast a team could get the last good backup back online after an attack. That single metric ignores a much harder and more consequential question, which is whether the last good backup is actually clean, and whether the organization can later prove to a regulator or an insurer exactly what happened, when it happened, and how the response was handled. Ransomware groups that sit dormant inside a network for weeks before triggering a payload have made naive fast-restore approaches genuinely dangerous, since a rushed restore can reintroduce the same malware right alongside the recovered data.
Kit Beall, Cohesity's chief revenue officer, put the shift plainly: cyber recovery strategies need to go beyond restoring data to include investigation, validation, and trusted recovery as core parts of the process. That statement is a reasonable summary of where enterprise security and data leaders have been quietly pushing their vendors for the last two years, and it is now finally showing up as a purchasable, productized feature rather than an expensive, ad hoc incident response services engagement negotiated after the fact.
The compliance driver behind the feature
The clean room capability is explicitly positioned to help organizations meet DORA and NIS2, the EU regulations that require financial institutions and critical infrastructure operators to demonstrate real operational resilience under audit, rather than simply asserting that resilience exists on paper. Both regulations expect documented, repeatable incident response processes with clear, traceable audit trails, which is a considerably higher bar than merely having backups that technically work when tested in isolation.
Rampal Singh, HCLTech's senior vice president, framed the joint offering as combining HCLTech's global delivery scale and cyber resilience expertise with Cohesity's AI-powered data security to help customers reduce downtime, stay compliant, and remain operational through an incident. For multinational enterprises juggling overlapping regulatory regimes across different jurisdictions, having a vendor-managed process that maps directly to a specifically named regulation is a considerably easier internal sell than a generic best-practices pitch built around vague resilience promises.
What this means for data and security teams
Clean rooms have existed as a cybersecurity concept for years already, typically requiring substantial in-house forensic expertise or an expensive standing incident response retainer to stand up credibly on short notice during a real crisis. Productizing this capability as a managed feature inside an existing backup and recovery relationship meaningfully lowers the barrier to entry for mid-market and PE-backed portfolio companies, which cannot justify a full-time forensics team internally yet still face the same regulatory expectations as much larger public peers.
It also reinforces a line that has been blurring steadily all year: data protection vendors are increasingly selling governance and compliance outcomes directly, layered on top of the storage and recovery speed that used to be their entire pitch. For CIOs currently evaluating backup vendors, the relevant question is shifting from simply how fast can you restore my data toward the sharper follow-up of can you show a regulator exactly how that restore was independently validated.
The bigger trend this fits into
This announcement lands alongside a steady drumbeat of ransomware groups deliberately targeting backup infrastructure first, on the well-established theory that a company left without a trustworthy recovery path will pay a ransom faster and with less internal resistance. Recent incidents involving encrypted or deleted backup repositories have pushed cyber insurers to ask pointed questions about recovery validation before renewing coverage, adding a financial incentive on top of the operational one, and pushing boards to ask their own security leaders whether a similar validation gap exists in their own environment today. A managed clean room is a direct architectural response to that specific tactic: it assumes the primary environment is already compromised from the outset and builds the entire recovery process around proving trust step by step, rather than assuming trust and discovering the mistake later.
Expect competitors across data protection, from Rubrik to Veeam to Commvault, to move toward similar managed forensic-recovery packaging over the next few quarters, since the underlying regulatory pressure driving this demand, active DORA enforcement and ongoing NIS2 transposition across EU member states, shows no sign of easing and has become an increasingly frequent board-level topic rather than a purely technical infrastructure conversation left to IT alone. Procurement teams evaluating backup and recovery vendors over the next budget cycle should treat clean room capability, or a credible roadmap toward one, as a standard line item in any request for proposal, not an optional add-on reserved for the largest regulated enterprises.



