Key Takeaways
- Three CTERA inventors, Aron Brand, Doron Sher and Simon Taib, were awarded U.S. Patent No. 12,639,433 that covers CTERA’s server-side behavioral malware detection, which identifies ransomware by how it handles files instead of by known signatures.
- In an independent evaluation by Synergy7’s Cybersecurity Lab, CTERA Ransom Protect detected all eight of the most destructive ransomware families tested, with a median time to block of 24.5 seconds.
- Gartner’s February 2026 Market Guide for Cyberstorage lists CTERA as a Representative Vendor among Platform-Native Cyberstorage Solutions, and Gartner projects that by 2029, 100% of storage products will include cyberstorage capabilities.
Why Wait for Encryption? CTERA Patents Ransomware Detection
I’m genuinely happy to see the patent behind CTERA Ransom Protect officially granted. It’s a special moment when an idea that started as a customer problem statement becomes a product actually used by customers and, eventually, protected intellectual property. Patents take years to work through the system, so by the time one lands, the technology behind it has usually already been proven in the real world. This one certainly has.
As we saw the scourge of ransomware affect more and more organizations, we asked ourselves, “Why should storage wait passively for ransomware to encrypt data and then rely entirely on recovery?” For most of the industry’s history, that’s exactly what storage did. It sat there, dutifully writing whatever bytes it was told to write, trusting that whatever was upstream, whether the endpoint, the network, or the Security Operations Center (SOC), would catch the bad actor before the damage was done. That trust has been misplaced for a while now.
CTERA Ransom Protect, part of our CTERA Cyber Protection product, takes a different approach. It uses machine learning models to analyze file-operation behavior, identify the fingerprint of an attack, and act before significant damage is done. Not after. Before.
What Is Cyberstorage?
Cyberstorage is a set of security capabilities built into enterprise storage itself. It detects attacks such as ransomware and data theft at the storage layer and proactively responds, instead of waiting for backup and recovery to clean up afterward. The idea underneath all this is simple. Storage stopped being a passive container the moment attackers realized that encrypting a company’s files was the fastest way to bring that company to its knees. Once that happened, storage had a choice: stay passive and hope somebody else stops the attack, or start actively defending the data it holds.
Gartner’s Market Guide for Cyberstorage, published in February 2026, treats cyberstorage as an emerging category and lists CTERA as a Representative Vendor among Platform-Native Cyberstorage Solutions. Gartner also projects that by 2029, 100% of storage products will include cyberstorage capabilities focused on active defense beyond recovery, up from 20% in early 2025.
How Long Does It Take to Turn a Product Idea Into a Patented Innovation?
I think the following milestones tell the story better than I can.
- 2022 — Customer frustration sparks an idea. Customers voiced frustration with ransomware and the disruption of recovering after an attack. That frustration brought us back to a simple question: Why should storage wait for files to be encrypted before doing anything about it?
- 2023 — Ransom Protect Product launch. CTERA released Ransom Protect, the market’s first solution bringing AI-based ransomware detection, mitigation, and recovery directly into storage.
- 2024 — Honeypot protection added. We added decoy-file capabilities to detect unauthorized access, data theft, and double-extortion activity in real time.
- 2025 — Independent validation. Synergy7’s Cybersecurity Lab, powered by Dell Technologies, tested the product and reported a 100% detection rate across eight major ransomware families with a median blocking time of 24.5 seconds.
- 2026 — Patent granted. S. Patent No. 12,639,433 was granted for CTERA’s server-side behavioral malware-detection technology.
- 2026 — Gartner recognition. Gartner listed CTERA among Platform-Native Cyberstorage Solutions in its Market Guide for Cyberstorage.
- 2029 — The direction of the market. Gartner predicts that by 2029, 100% of storage products will include cyberstorage capabilities focused on active defense beyond recovery, up from 20% in early 2024.
To me, this timeline demonstrates that a good patent isn’t recognition of a theoretical concept. Our technology was conceived in 2022, in the field since 2023, expanded based on emerging threats, and has been independently tested against real ransomware families. It also reflects a wider change in how we think about enterprise storage. Endpoint and network defenses remain essential, but they can be bypassed. The storage layer sees what is actually happening to the data and should be able to detect and stop malicious activity itself, rather than waiting for someone else’s alarm to go off first.
How CTERA Ransom Protect Identifies Ransomware
Behavioral detection at the storage layer
This is the idea behind cyberstorage: moving storage beyond passive protection and post-attack recovery toward active detection, containment, trusted recovery, and data-layer defense. It’s a mouthful of a term, but the concept underneath it is simple. Storage stopped being a passive container the moment attackers realized that encrypting a company’s files was the fastest way to bring that company to its knees. Once that happened, storage had a choice: stay passive and hope somebody else stops the attack, or start actively defending the data it holds.
As mentioned, Gartner’s prediction that cyberstorage capabilities will become universal by 2029 is quite striking (they rarely predict numbers as definitive as 100%), but to me, this is not surprising. As attackers increasingly target production data, backups, and storage infrastructure directly, active defense at the storage layer will become a basic requirement, not a differentiator. When the majority of storage products offer some form of active defense, the ones that don’t will be the exception that security teams have to compensate for manually.
That’s really the shift we anticipated back when this started as an engineering conversation on how to protect our customers, long before “cyberstorage” was a category Gartner would write a Market Guide about.
The Detection Methods Behind the Patent
The patent covers the server-side behavioral detection engine at the core of CTERA Ransom Protect: advanced machine learning that identifies behavioral anomalies indicating fraudulent file activity and blocks the offending user within seconds, without relying on signature updates that are always a step behind whatever the attacker just changed. That’s what makes it effective against zero-day ransomware variants that have never been seen before: the detection isn’t looking for a known signature, it’s looking for the way ransomware actually behaves when it touches files.
Alongside that behavioral engine sits the honeypot layer we introduced in 2024: decoy files planted to lure attackers. These give us an early, unmistakable signal the moment someone starts poking at data they have no business accessing, including the slower, quieter data-exfiltration attempts that precede a double-extortion demand. Ransomware groups increasingly pair encryption with the threat of leaking stolen data, and a detection strategy that only watches for encryption misses half the attack. The honeypots close that gap. For a closer look, read how CTERA Ransom Protect prevents data exfiltration.
Not a Solo Effort
I’m especially proud to share this achievement with my co-inventors, Doron Sher and Simon Taib, and with the broader CTERA team that transformed the original machine-learning concept into a real product. Patents list inventors, but they never quite capture the engineers who hardened the code, the customers who ran it in production and told us what broke, and the researchers at Synergy7 who put it through its paces against real ransomware families instead of taking our word for it.
Where CTERA Ransom Protect Fits Today
CTERA Ransom Protect is now part of the CTERA Cyber Protection service, combining behavioral AI, honeypot detection, rapid containment, immutable protection, forensic visibility, and recovery into a single, deeply integrated security layer for the CTERA Intelligent Data Platform. It’s built to move organizations from a reactive security posture to proactive resilience. It detects anomalous behavior and data exfiltration attempts. It also arms teams with actionable alerts and forensic detail to contain a threat quickly. And it backs it all with FIPS 140-3 certified cryptography and DoD STIG-compliant architecture, for organizations that need to meet the highest compliance bar.
None of that changes the original question we started with. Why should storage wait? It shouldn’t. And increasingly, it won’t have to.
Frequently Asked Questions
- What is cyberstorage?
Cyberstorage is a set of security capabilities built into enterprise storage. It proactively detects attacks such as ransomware and data theft at the storage layer and responds there, rather than relying only on backup and recovery after the damage is done. Gartner treats it as an emerging category in its February 2026 Market Guide for Cyberstorage.
- How does CTERA Ransom Protect detect ransomware?
It watches file operations on the server and uses machine learning to score the behavior. When the aggregate risk score passes a threshold, it starts incident handling, which can include quarantining or blocking the offending user. Because it looks at behavior instead of known signatures, it does not wait on signature updates and stays ahead of ransomware attacks.
- What does U.S. Patent No. 12,639,433 cover?
It is the patent titled “Behavioral detection of malware that performs file operations at a server computer.” It covers a server-side method that turns file-operation events into feature vectors, scores them with a trained machine learning classifier, and starts incident handling when the aggregate risk score passes a threshold.
- How fast does CTERA Ransom Protect stop ransomware?
In the Synergy7 evaluation announced in December 2025, the median time to block an attack was 24.5 seconds across eight of the most destructive ransomware families, and all eight were detected before encryption completed. With mitigation enabled, a median of 2.28% of files were affected.
- Can CTERA Ransom Protect detect data theft and double extortion?
CTERA added honeypot protection in 2024. Decoy files give an early signal when someone touches data they should not, including the slower exfiltration attempts that often come before a double-extortion demand.
- Does cyberstorage replace endpoint and network security?
No. Endpoint and network defenses remain essential. They can be bypassed, though, and the storage layer sees what is actually happening to the data, so it should be able to detect and stop malicious activity itself.
- CTO
Aron Brand, CTO of CTERA Networks, has more than 22 years of experience in designing and implementing distributed software systems. Prior to joining the founding team of CTERA, Aron acted as Chief Architect of SofaWare Technologies, a Check Point company, where he led the design of security software and appliances for the service provider and enterprise markets. Previously, Aron developed software at IDF’s Elite Technology Unit 8200. He holds a BSc degree in computer science and business administration from Tel-Aviv University.