Qumulo LogoQumulo Logo

블로그

From Detection to Containment in Seconds: Why Qumulo NeuralProtect combined with Cisco Hypershield and Splunk Changes the Ransomware Game

Ransomware has evolved. AI-generated phishing, credential theft, and faster lateral movement mean attacks now reach unstructured production data in minutes, not days. Yet most enterprise protection strategies remain fundamentally reactive: they detect an attack after files are already being encrypted, then lean on backups to claw the business back. By the time ransomware reaches production storage, the damage has already begun.

Qumulo NeuralProtect™ takes a different approach. It builds real-time ransomware and malware protection directly into the storage layer, inspecting every file at the point of write and stopping attacks before data is encrypted or corrupted. Paired with Cisco Hypershield and Splunk, it closes the loop from detection to network-level containment in seconds a capability no other file platform offers today.

The problem with how file storage detects ransomware today

Most file storage and data protection solutions fall into one of three camps, and all three share the same weakness: they respond after production data is at risk.

  • Entropy and metadata watchers. Many storage platforms infer ransomware by watching for statistical side effects, rising data entropy, unusual file extensions, and abnormal IOPS. Because they never look inside the files, they typically need a learning period, struggle with zero-day variants, and can be evaded by attackers who deliberately keep entropy low. Detection often comes only after enough files have changed to trip a threshold, meaning encryption is already underway.

  • Backup-centric recovery. Immutable snapshots and air-gapped copies are essential, but they are a safety net, not a defense. They accept the loss and optimize the restore — along with the downtime, the RPO gap, and the forensic effort that come with it.

  • External behavioral tools. Third-party software that monitors user access patterns from outside the array can lock accounts once suspicious behavior emerges. However, it adds separate infrastructure to buy and manage, and it still reacts to behavior after malicious writes have started landing on storage.

In every case, there is a gap sometimes minutes, sometimes hours between the first malicious write and the response. That gap is where the business impact lives.

NeuralProtect: deep file inspection at the point of write

NeuralProtect eliminates that gap by inspecting actual file content inline, in real time, at 64KB granularity, as data is written to the Qumulo platform. Instead of guessing from statistical side effects, a mixture-of-models detection engine examines what is really in the data:

  • A deterministic model that recognizes known ransomware families with 100% accuracy.

  • A statistical model that catches zero-day ransomware with 95%+ accuracy.

  • A temporal model designed for sophisticated attacks built specifically to evade entropy-based detection.

  • An integrated Bitdefender engine for malware detection.

Because detection is content-based rather than threshold-based, false positives fall below 0.01%, and there is no learning mode, no separate appliance to deploy alongside every cluster, and no add-on software stack to operate. Protection is native to the primary storage platform itself.

From detection to isolation and recovery — automatically, in seconds

Detection alone is not protection. What makes the offering unique is what happens in the seconds after a threat is identified. As the workflow above shows, NeuralProtect drives an automated, full-stack response:

  • Inspect. File content is inspected inline in real time at 64KB granularity as it is written.

  • Detect. The AI/ML engine identifies ransomware behavior and malicious encryption instantly.

  • Contain. Qumulo removes the writer's ability to write to the storage system and notifies Cisco Hypershield, triggering automatic containment.

  • Isolate. A new policy is pushed to Cisco Smart Switches, cutting the attacker off from everything — not just the storage, but the network itself.

  • Alert. Full threat details flow to Splunk for alerting, email notification, and automated incident response.

At the same time, NeuralProtect creates defensive snapshots so recovery starts from known-clean data. The result is containment measured in seconds across both storage and network—while competing approaches are still accumulating enough anomalous events to raise an alarm, let alone act on one.

Proven at scale

This is not theoretical. Across billions of inspections in 2025, NeuralProtect stopped more than 48,000 ransomware threats and intercepted over 4,000 malware threats with zero ransoms paid by protected customers.

The bottom line

Every other file solution asks some version of “how fast can you recover?” NeuralProtect asks a better question: why lose the data at all? By moving protection to the point of write, where the real risk lives, and wiring detection directly into automated network isolation and SIEM response, Qumulo turns ransomware defense from reactive recovery into proactive prevention. Detect faster. Shrink the RPO gap. Contain automatically. Recover clean.

One platform. Full-stack protection. Zero trust. Zero delay.

Learn more about NeuralProtect here.