RackTop Systems
Practitioner Guide

When every storage product claims Cyberstorage: seven tests that tell them apart

Gartner expects every storage product to include Cyberstorage capabilities by 2029. When the label is universal, a datasheet stops telling buyers anything. Seven live tests for a proof of concept still can.

RackTop SystemsSeptember 23, 20266 min read

Key takeaways

  • According to Gartner’s 2026 Strategic Roadmap for Storage, as reported by Blocks and Files in December 2025, about 20 percent of deployed enterprise storage includes active, defense-focused Cyberstorage capabilities, and Gartner forecasts 100 percent by 2029.
  • When every vendor can claim Cyberstorage, the question that separates products is what each one does, on its own, when a valid account starts encrypting or copying files.
  • A Cyberstorage proof of concept should answer three questions: can the product stop the attack, does recovery survive the attack, and can you prove afterward what the attacker touched.
  • Seven live tests answer those questions with measurable results: bulk read, every protocol, time to stop, novel behavior, administrator compromise, surgical recovery, and evidence.

When every storage vendor claims Cyberstorage, one question still separates them: what does the product do, on its own, when a valid account starts encrypting or copying your files? That question is about to matter more. According to Gartner’s 2026 Strategic Roadmap for Storage, as reported by Blocks and Files in December 2025, about 20 percent of deployed enterprise storage includes active, defense-focused Cyberstorage capabilities today, and Gartner forecasts 100 percent by 2029.

For the category, that is a success. For a buyer, it means the word on the datasheet stops telling you anything. The products behind it range from ones that stop an attack in progress to ones that help you clean up afterward, and the difference shows up on the worst day your organization will have: whether files were encrypted or merely targeted, whether data left the building, and whether you can tell regulators exactly whose records were exposed. The only reliable way to see that difference is to test it, on your own data, under conditions that look like a real intrusion. This guide gives you the tests.

Four kinds of product carry the same label

Most products sold as Cyberstorage fall into one of four approaches. Each is useful for something, and each has limits that come from where it sits. Recovery features work from copies of the data. Add-on monitors work from activity logs that the storage system exports to them. Malware scanners inspect files as they arrive. Only the fourth approach sits in the data path, meaning inside the storage system that handles every file request, where it can judge each request and refuse it.

ApproachWhat it can do on its ownWhat it misses
Snapshots and vaultsRestore data to a clean earlier copy after an attackCannot see or stop an attack in progress, and cannot see files being copied out
Add-on monitorsAlert on suspicious activity in the storage logs, sometimes trigger a snapshot or block a userOnly as good as the logs it receives; acts after the fact and can be cut off from the feed
Malware scanningFlag or quarantine known malicious filesBuilt to catch bad files arriving, not a legitimate account encrypting or copying good ones
Built into storageJudge every file operation as it happens and end a hostile session itselfMust be the storage platform, or sit directly in front of it

Can it stop the attack? Tests 1 to 4

Run every test from a valid account. Stolen passwords, hijacked logins, and compromised service accounts reach file storage already authorized, so a test that only proves a product can catch known malware on an unknown account measures the part of the problem other tools already cover. Score each vendor with the scorecard at the end of this guide.

Test 1, bulk read. From a normal user account, copy several thousand files from a share that account can reach but rarely uses. Nothing gets encrypted. A pass means the storage stops the session, the user or program’s connection to the storage, while the copy is still running. Many ransomware features watch only for files being changed, and data-theft extortion needs nothing but reads. Fail this test and your data leaves without an alarm.

Test 2, every protocol. Run an encryption script against a share over SMB, then repeat it over NFS, S3, and Web Drive. A pass means the same result on all four. Protection that covers one protocol leaves the rest of your data to whichever path an attacker tries next.

Test 3, time to stop. Repeat Test 2 with nobody watching the consoles. Measure the seconds from the first malicious change to the session ending, and count the files changed along the way. A product that waits for a person to act on an alert turns seconds of attack into hours of damage.

Test 4, behavior nobody has seen. Write a new encryption script for the test, with an unfamiliar file extension, no known malware signature, and no contact with any canary file, the decoy files some products plant as tripwires. Run it on a system installed that week. A pass means the product catches it by what it is doing, with no signature to match and no learning period to wait out.

Does recovery survive the attack? Tests 5 and 6

Test 5, administrator compromise. Log in with an administrator account and try to delete snapshots, shorten retention, turn off the protection, and erase the audit log. A pass means your recovery copies and records survive. Attackers go after backups and snapshots early, so a vault the storage administrator can empty is only as safe as that one password.

Test 6, surgical recovery. After Test 3, restore only the files the attack changed, and keep every legitimate edit other people made in the same window. A pass means exactly the damaged files come back, in minutes. The alternative, rolling a whole volume back to last night, trades an attack for a day of lost work.

Can you prove what happened? Test 7

Test 7, evidence. Ask the product to list every file the Test 1 session read, with times and the machine it came from. A pass is a complete answer from a record that nobody, including an administrator, could have altered. That list decides whether a real incident ends with notices to a precise set of people or to everyone whose data might have been on the system, which is slower, costlier, and harder to explain.

The scorecard, and how BrickStor SP scores

Copy the first two columns into your evaluation and fill them in for every vendor on your shortlist. The third column is what RackTop BrickStor SP does in each test. Active Defense, the detection and response engine behind those results, has run inside the storage data path since October 2020.

TestA pass looks likeWhat BrickStor SP does
1. Bulk readSession stopped while the copy is runningTreats anomalous bulk reads as an attack and ends the session in under a second
2. Every protocolSame result over SMB, NFS, S3, and Web DriveThe same inline protection on all four protocols
3. Time to stopAutomatic, in seconds, no person neededTerminates the hostile session automatically in under a second
4. Novel behaviorCaught on behavior alone, on day oneBehavioral analysis from the first operation; no signatures, canary files, or learning period
5. Admin compromiseRecovery copies and records cannot be erasedImmutaVault copies are designed to survive administrative compromise
6. Surgical recoveryOnly the damaged files restored, in minutesIntelligent Bulk Remediation restores exactly the affected files, with a 1-minute RPO and 3-minute RTO
7. EvidenceEvery file read, with time and source, from an unalterable recordImmutable audit of every operation, by identity, from the platform’s own record

Run the seven tests on BrickStor SP

NAS ransomware protection is often sold as a recovery promise: snapshots, retention, a fast restore. Recovery matters, and Tests 5 and 6 measure it. But a product that passes only those two has shown it can clean up. Real NAS ransomware protection stops the attack on live data, restores exactly what it touched, and proves what happened, and the seven tests check all three.

The fastest way to see the difference is to run the tests yourself. Put BrickStor SP in your own environment for 90 days, point it at a copy of your data, and a RackTop engineer will work through all seven tests with you. Run them against any vendor, including us.

Frequently asked questions

Gartner forecasts that it will. According to Gartner’s 2026 Strategic Roadmap for Storage, as reported by Blocks and Files, about 20 percent of deployed enterprise storage includes active, defense-focused Cyberstorage capabilities, rising to 100 percent by 2029. That makes the label less useful for choosing a product and makes behavioral testing more important.
Immutable snapshots are a recovery control and an important part of a Cyberstorage platform, but they do not qualify on their own. A snapshot cannot see an attack in progress, cannot stop it, and cannot see files being copied out, so it offers no defense against data theft. Cyberstorage adds detection and response on live data in front of the recovery layer.
Use a valid account and run live scenarios: a bulk read of files the account rarely touches, mass encryption over every protocol you use, a new encryption script with no known signature, and an attempt to delete snapshots and logs with an administrator account. Measure time to stop without a person acting, files affected, whether only the damaged files can be restored, and whether the product can list every file a session read.NAS ransomware hardening checklist
Built-in Cyberstorage evaluates every file operation inside the storage system as it happens and can end a hostile session itself. Bolt-on tools run outside the storage and read the activity logs it exports, so they depend on that feed, act after a delay, and usually need a separate action to stop an attack.Built-in vs. bolt-on Cyberstorage
Because extortion increasingly relies on stolen data rather than encryption. A session that copies files and never changes one will pass through any control that watches only for writes. A Cyberstorage platform should treat anomalous bulk reads on live data as an attack and stop the session while the copy is underway.

Run the seven tests on BrickStor SP

Ninety days in your own environment, on a copy of your own data, with a RackTop engineer working through every test alongside you.

How to Evaluate Cyberstorage: 7 NAS Ransomware Tests | RackTop