On-demand

Ransomware Readiness in the Age of AI

A threat actor bypassed EDR, sat quietly in a mid-sized company's AWS environment for more than 30 days, and slowly encrypted data on its way to storage — poisoning every backup along the way. Elastio and the AWS Security Incident Response team walk through what happened, why the customer's tooling never saw it, and what readiness has to look like now that AI has compressed the attack timeline from weeks to hours.

Webinar details
Date
August 25, 2026
Duration
39 minutes
Format
On-demand webinar
Speakers
Chris Sauer from Elastio and Dean Lawrence from AWS
Focus
Real-world incident response, AI-accelerated attacks, and proving your recovery path is clean
Watch On-DemandWatch on BrightTALK

Cybersecurity fundamentals matter more than ever as attacks get faster

The session opens with a real engagement. A successful mid-sized billing provider running on AWS — a capable IT team with best-of-breed tooling — was breached at the firewall and then bypassed EDR entirely. The attacker dwelled for over 30 days, mapped the environment, and placed a decryption key in memory on a key server. From that point on, every read was silently decrypted for users and every write was silently encrypted on the way back to storage. For roughly 11 days, the company's own backup jobs were faithfully capturing poisoned data. Because the encryption was slow, striped, and fileless, entropy detectors, signature scanners, and malware detection never fired.

When the attacker pulled the key, the business went offline overnight. AWS Security Incident Response engaged alongside Elastio and AWS partner JetSweep, used data-layer telemetry to pinpoint exactly when the encryption began, and identified the last known clean copy. The company recovered — but it lost six days of downtime and roughly ten days of data. It was survivable rather than an extinction-level event, and the difference came down to how quickly the team could answer one question: which copy can we actually trust?

Dean Lawrence then covers what AI has changed and what it has not. Attacker objectives are the same; the speed is not. The Hugging Face incident, where an autonomous agent ran an intrusion end to end, marks a shift from the exploit itself to the reasoning — the decision loop now runs faster than any human operator. The cyber kill chain that threat models were built around is executing in hours instead of weeks, which leaves defenders less time to detect, decide, contain, and recover. The uncomfortable takeaway is that speed doesn't reward clever tooling. It rewards hygiene: protect identity first, scope permissions, reduce blast radius, and rehearse the response chain end to end, because AI reaches a door that's slightly ajar much faster than anyone used to.

The session closes on the gap that decides outcomes. Perimeter, network, identity, and endpoint tools tell you where a threat is moving, but not what has happened to your data. Restoring is not the same as recovering: if the copy you restore is corrupt, you are back at zero. Elastio inspects at the data layer, detects encryption behavior at its earliest stage — including the slow and zero-day activity other tools miss — and feeds that telemetry into AWS Security Hub, where AWS Security Incident Response can act on it. In the case discussed, that signal would have surfaced the attack while it was still unfolding.

What you will learn

01How AI is compressing the cyber kill chain from weeks to hours, and what that means for detection, containment, and recovery.
02Why hygiene beats tooling: protecting identity, scoping permissions, reducing blast radius, and testing recovery plans before an incident hits.
03The process gaps that quietly burn hours mid-incident — unclear environment ownership, no out-of-band communications, and responders who cannot be granted or revoke access.
04Lessons from the Hugging Face incident, including why AI defenders hit guardrail blocks mid-response and why you should test your AI tooling in advance.
05The difference between restoring data and actually recovering, and why corrupt backups leave you back at zero.
06How Elastio inspects at the data layer to detect encryption early, identify the last known clean recovery point, and feed telemetry into AWS Security Incident Response.
07How to turn on AWS Security Incident Response today, and how proactive security can surface an attack before the customer even knows it is happening.

Who should attend

Security leaders, incident response and SOC teams, cloud architects, and infrastructure and resilience owners responsible for detecting ransomware and proving that recovery data on AWS is clean.

Speakers

CS
Chris Sauer
SVP of Global Alliances
Elastio
DL
Dean Lawrence
Partner GTM Lead, Security Search and Observability
AWS
On-demand session
See how a fileless, slow-encryption attack poisoned every backup — and what readiness looks like now.
Watch On-Demand

More from Elastio