Rubrik, Inc. - Experts & Thought Leaders

Latest Rubrik, Inc. news & announcements

Rubrik Code Guardian Boosts AI Cyber Resilience

As autonomous agents make the digital world more dangerous, Rubrik, the Security and AI Operations Company, unveils Rubrik Code Guardian, a custom Claude Mythos 5 harness that red-teams customers’ code based on an air-gapped copy of their repository. Bringing cyber resilience up to speed of AI “Rubrik is one of the partners we are working with to put Claude Mythos 5's cyber capabilities in defenders' hands, so they can find and validate attack paths before attackers do," said Michael Moore, Cybersecurity lead at Anthropic. “Rubrik will use the model to test code faster and at far greater scale, and to bring cyber resilience up to the speed of AI.” The new service uncovers and prioritizes the multi-step vulnerability chains an attacker would actually exploit, validates each for exploitability, and turns confirmed critical issues into tracked remediation. Frontier AI “Frontier models are advancing at a fast pace. In the wrong hands, these models can be used to discover, chain, and exploit vulnerabilities at machine speed,” said Arvind Nithrakashyap, Co-Founder and Chief Technology Officer at Rubrik. “To move just as fast, we are using frontier AI to scale vulnerability detection faster than our traditional code scanning tools. We took Anthropic’s powerful model and built a Rubrik software harness to test on our code. We are using that experience and success now to give customers access to the harness, with a secure, isolated environment, which means we can run analysis of their code away from live repository and production systems.” The next milestone in agentic cyber resilience Rubrik Code Guardian makes critical enterprise systems more resilient to even the most advanced frontier AI-powered attacks. The product embeds and harnesses Anthropic’s Claude Mythos 5 into a service that operates directly on air-gapped copies of source code, enabling frontier model level vulnerability analysis while minimizing risk and impact on production environments. Rubrik Code Guardian proactively secures the core intellectual property that powers modern businesses: Red-Team Customer Code, Safely: Runs Claude Mythos 5 through Rubrik’s custom security harness against a secure clone of the immutable, air-gapped copy never against the live repository or production environment. Attack Chains, Not Alerts: Reasons across files, services, authentication patterns, and cloud boundaries to surface previously undetectable vulnerabilities, even “chained vulnerabilities” that advanced AI attacks now exploit. Validated Findings, Prioritized by Business Criticality: Validates attack chains for real exploitability before surfacing them and prioritizes findings by exploitability, blast radius, and business criticality. Accelerated Remediation: Pushes confirmed critical issues into developer workflows through Jira or GitHub issues with file-level remediation guidance. Built-In Code Resilience: Maintains recovery workflows so organizations can restore a known-good codebase if a security event or bad build occurs. Rubrik Code Guardian is currently accepting select design partners for private preview.

Rubrik Agent Identity: Transforming AI Governance

Today at the Black Hat Conference, Rubrik, the Security and AI Operations Company, announced Rubrik Agent Identity, a powerful new AI-based solution to manage and control AI agents' access and permissions, addressing a key obstacle in enterprise agent deployment. AI agent deployments are rapidly evolving, with the potential to execute complex, automated workflows across SaaS applications, databases, and APIs at unprecedented speed and scale. Yet most organizations lack the capability to monitor and control agent access and actions at the necessary speed and scale. Rubrik Agent Identity is designed to reduce operational vulnerabilities that stem from agent identities by allowing customers to both monitor every agent and model context protocol (MCP) at runtime using AI, and to deliver just-in-time permissions per tool call.  Traditional security boundaries "Agents are no longer just synthesising information, they are acting on behalf of employees, and the access models we built for humans. Static credentials were never designed for autonomous actors," said Dev Rishi, General Manager of AI at Rubrik. "Agent Identity lets enterprises decide who can do what with agents and enforces it per tool call, at the moment of action, with scoped, short-lived access and no standing permissions. With Rubrik Agent Cloud, enterprises can govern agent activity, enforce identity-aware policies, and apply semantic policy evaluation before sensitive actions execute. By using audit logs to prove what happened, agent adoption can scale with confidence, avoiding potential blast radius." Modern AI creates an unmonitored "shadow workforce" that bypasses traditional security boundaries. Because these systems often rely on broad, static credentials, a single compromised agent can trigger destructive, system-wide actions with zero visibility. Single compromised agent According to recent data from Rubrik Zero Labs, 86% of global IT and security pioneers expect AI agents to outpace their organization's security guardrails within the next year, while only 23% report full visibility into the agents operating in their environments. Rubrik Agent Identity, delivered as an expansion of the Rubrik Agent Cloud platform, establishes a unified "Govern, Control, and Prove" model across the entire agent lifecycle. The new solution operates alongside Rubrik's established SAGE governance framework, and now provides four distinct Rubrik Agent Cloud pillars: Agent Observability: Monitor every agent and MCP at runtime. Agent Identity: Control access per tool call at speed and scale using fine-tuned AI. Agent Runtime Security: SAGE intent-driven governance to enforce policies, and detect agent errors in real time. Agent Rewind: Undo agentic mistakes. Agentic identity posture The architecture introduces key capabilities designed to help enterprises rapidly harden their agentic identity posture: Build an Agent Identity Inventory: Discover and catalog all active AI agents, MCP servers, skills, and plugins to immediately eliminate unmonitored shadow AI. Delegate Least-Privilege Access: Scope access to specific MCP servers and tools by user and group using On-Behalf-Of federation, extending existing enterprise identity structures rather than replacing them. Enforce with Just-In-Time Tokens: Eliminate standing permissions entirely by minting scoped, short-lived tokens per tool call, ensuring access is validated at runtime before execution. Potential operational impact To prevent malicious or erroneous actions before they occur, every MCP tool call must clear three distinct checkpoints before execution: Behavioral Analysis: SAGE semantically evaluates the requested tool call, its context, input parameters, and potential operational impact before execution. Access Policy Enforcement: Run-time security policies are verified at the infrastructure layer, enriched with SAGE context. Identity Verification: The agent session is authenticated, and the system mints a short-lived token specifically scoped to that single tool call. Existing enterprise identities If an unauthorized action is attempted, such as a write or modification without an explicit policy scope, the transaction is immediately blocked before execution. For unexpected agent behaviors, Agent Rewind instantly and precisely undoes an autonomous agent’s destructive action., addressing the widespread industry concern where 88% of leaders worry about meeting recovery time objectives as agentic threats scale. Rubrik Agent Identity integrates seamlessly with Okta and Microsoft Entra ID, extending existing enterprise identities to autonomous machine actors without requiring new directories. The MCP Gateway provides a unified security checkpoint for all API-based and MCP resources across the enterprise. Ultimately, Rubrik Agent Identity advances the company’s vision to deliver Agentic Cyber Resilience to the customers, helping them keep pace with machine-speed attacks powered by frontier AI models.

Rubrik's Identity Resilience For Cybersecurity

In a world of nonstop cyberattacks, Rubrik announced its newest upcoming solution, Identity Resilience, designed to secure the entire identity landscape alongside data. Identity Resilience aims to protect the most common entry points for attackers – human and non-human identities (NHIs) – to help organizations maintain operations with minimal downtime.  Rubrik’s solution Rubrik’s solution is designed to secure this weak infrastructure that powers virtually Identity Resilience aims to address a blindspot in enterprise security. A critical piece of infrastructure utilized by a vast majority of organizations, identity remains a consistent target for hackers. When compromised, these identity systems grant attackers access to critical data and credentials, and their disruption can prevent cyber recovery. Rubrik’s solution is designed to secure this vulnerable authentication infrastructure that powers virtually every major enterprise. Identity risks and data security "Identity systems are not only complex and hard to manage, but they have also become the primary gateway for attackers aiming to access an organization's valuable data," said Mike Tornincasa, Chief Business Officer at Rubrik. "Today, we signal our commitment to identity protection, to address our customers' needs by detecting threats that target identities and proactively reduce identity risks, just as we have successfully done with data security.” Why this matters: Identity is how hackers get inside Rubrik’s solution is designed to provide continuous visibility into identity changes Rubrik's identity business safeguards millions of identities globally. It’s easy to see why: A recent CISA report found that 90% of cyber attacks on critical infrastructure begin with an identity compromise, often leading to privilege escalations and lateral movement into valuable corporate data. These threats usually unfold gradually, making it essential to understand not just the “who” and “what” but also the “when” - how privilege or access patterns shift over time. By leveraging time-series data, Rubrik’s solution is designed to provide continuous visibility into identity changes, enabling earlier detection of suspicious activity. How Rubrik monitors and sustains data Similar to how Rubrik monitors and sustains data, the company’s anticipated capabilities are designed to identify, monitor, and safeguard critical, sensitive, and active identities, including non-human identities (NHIs) such as machines using service accounts and access tokens.  NHIs, which outnumber their human counterparts, are complex to manage and introduce vulnerabilities that are increasingly targeted by attackers who compromise and escalate privileges. Current identity security approaches fail to provide enterprises the capability to assess NHI risk, view data access, and track suspicious activity over time.  A holistic approach drives cyber resiliency Rubrik aims to combine these abilities to provide new abilities, and a holistic view of identity and data Too often, identity management, identity protection, and data security are siloed as different products run by different teams in an organization. In contrast, Rubrik uniquely aims to combine these capabilities to provide new capabilities, and a holistic view of identity and data.  Identity recovery & identity resilience: Accelerating recovery Rubrik offers extensive coverage for identities across hybrid environments. New capabilities aim to empower organizations to thwart attacks earlier and restore systems more quickly to ensure cyber resilience: Hybrid Protection for Active Directory (AD) and Entra ID: With automated and orchestrated recovery workflows, organizations can restore complex hybrid identity environments - like Active Directory forests and full Entra ID tenants - faster and with greater confidence than before. Active Directory recovery can involve up to 22 manual steps. Rubrik reduces that with an easy-to-use wizard, dramatically cutting complexity and time to recovery. As a result, these capabilities are among the fastest-growing in Rubrik's history, safeguarding millions of identities and the sensitive data they access.  Comprehensive Risk Analysis for Human and Non-Human Identities: With a unified view across identity providers showing human and non-human identities who have access to sensitive data, organizations can identify dormant or orphaned accounts, detect risky privilege escalations, and expose problematic combinations of access that traditional tools often miss. Beyond visibility, organizations can track the risk associated with identities and target remediation by revoking identity access, data access, or both. This approach enforces the least privilege, shrinks their attack surface, and proactively shuts down potential identity-based threats. Complete Identity and Data Context: Instead of working with limited context from identity providers, organizations can tie identity-based information with sensitive data (e.g., healthcare, financial) context, privilege, and activity. This critical context can reduce remediation work while strengthening risk posture before a cyber attack, thereby speeding up threat hunting and remediation during and after an attack. Get a briefing on Rubrik's Identity Recovery and Identity Resilience at the 2025 RSA Conference, April 28-May 1, 2025, in San Francisco.