Skip to content
The ATC
Ctrl K
Ctrl K
Log in
What we do
Our capabilities
AI & DataAutomationCloudConsulting & EngineeringData CenterDigitalImplementation ServicesIT Spend OptimizationLab HostingMobilityNetworkingSecurityStrategic ResourcingSupply Chain & Integration
Industries
EnergyFinancial ServicesGlobal Service ProviderHealthcareLife SciencesManufacturingMedia & GamingPublic SectorRetailSports & EntertainmentUtilities
Learn from us
Hands on
AI Proving GroundCyber RangeLabs & Learning
Insights
ArticlesBlogCase StudiesPodcastsResearchWWT Presents
Come together
CommunitiesEvents
Who we are
Our organization
About UsOur LeadershipSponsorshipsLocationsSustainabilityNewsroom
Join the team
All CareersCareers in AmericaAsia Pacific CareersEMEA CareersInternship Program
Our partners
Strategic partners
CiscoDell TechnologiesHewlett Packard EnterpriseNetAppF5IntelNVIDIAMicrosoftPalo Alto NetworksAWSGoogle CloudVMware
What we do
Our capabilities
AI & DataAutomationCloudConsulting & EngineeringData CenterDigitalImplementation ServicesIT Spend OptimizationLab HostingMobilityNetworkingSecurityStrategic ResourcingSupply Chain & Integration
Industries
EnergyFinancial ServicesGlobal Service ProviderHealthcareLife SciencesManufacturingMedia & GamingPublic SectorRetailSports & EntertainmentUtilities
Learn from us
Hands on
AI Proving GroundCyber RangeLabs & Learning
Insights
ArticlesBlogCase StudiesPodcastsResearchWWT Presents
Come together
CommunitiesEvents
Who we are
Our organization
About UsOur LeadershipSponsorshipsLocationsSustainabilityNewsroom
Join the team
All CareersCareers in AmericaAsia Pacific CareersEMEA CareersInternship Program
Our partners
Strategic partners
CiscoDell TechnologiesHewlett Packard EnterpriseNetAppF5IntelNVIDIAMicrosoftPalo Alto NetworksAWSGoogle CloudVMware
The ATC
Overview
Explore

Select a tab

Cyber Resilience Built Into Every Layer of Storage

NetApp Security is an integrated portfolio of ransomware detection, data isolation, access control, and recovery capabilities built directly into ONTAP — the data management platform powering the world's most demanding enterprise storage environments. Unlike perimeter security tools that sit outside your data, NetApp's security operates at the storage layer where attacks actually land. 

From AI-powered threat detection that runs in real time inside every ONTAP volume, to logically air-gapped vaults that no attacker — or administrator — can delete, to a centralized console that continuously scores your resilience posture and guides recovery to a verified clean state: NetApp Security provides defense-in-depth coverage across on-premises, hybrid cloud, and edge environments under a single, unified policy. 

And NetApp is willing to sign its name to the outcome. The NetApp Ransomware Recovery Guarantee commits NetApp to recovering your protected Snapshot copies following a ransomware incident, with financial compensation if it cannot — a commitment very few storage vendors are prepared to make.

The Threat Landscape Has Changed. Your Storage Security Must Too.

Ransomware now targets unstructured data — the files, shares, and object stores where 70% of enterprise data lives and where traditional endpoint and network security tools have blind spots. Modern ransomware is designed to evade signature-based detection, move laterally across shares, and time attacks to maximize encryption before any alert fires. 

Storage-Native Detection 

Threat detection inside ONTAP — no agents, no proxies. Attacks caught where data lives, not at the network edge. 

Real-Time Response 

Automatic snapshot creation and user blocking happen in seconds — before ransomware can encrypt meaningful data volumes. 

Immutable by Design 

SnapLock Compliance data cannot be deleted by anyone — not admins, not attackers, not even NetApp Support — during the retention period. 

AI-Powered Intelligence 

Machine learning learns your workload patterns and catches zero-day ransomware that signature-based tools miss entirely. NetApp declares 99% accuracy in threat detection for file workloads, with under 1% false positives — independently validated by SE Labs, which awarded ARP/AI its AAA rating.

Fast, Clean Recovery 

Guided recovery workflows surface the last verified clean snapshot and restore in minutes — slashing RTO from hours to moments. 

Hybrid Cloud Coverage 

Same security posture across on-premises ONTAP, Amazon FSx, Azure NetApp Files, and Google Cloud — one policy, everywhere. 

Backed by a Guarantee

NetApp commits in writing to the recovery of your protected Snapshot copies after a ransomware incident — with compensation if recovery fails. Confidence you can put in front of a board.

 

Six Layers of Protection. One Unified Platform.

Each NetApp security capability addresses a distinct attack vector. Together they form an interlocking defense-in-depth architecture that covers detection, containment, isolation, and recovery. 

ARP is NetApp's AI-powered ransomware detection engine built directly into ONTAP. It analyzes NFS and SMB workload access patterns in real time, learning normal behavior and triggering instant alerts and snapshot creation when anomalies emerge — no ransomware signatures required.

NetApp declares 99% accuracy in threat detection for file workloads. With ARP/AI — generally available from ONTAP 9.16.1 — the detection model identifies evolving ransomware variants in NAS environments at 99% accuracy with fewer than 1% false positives. That figure has been validated independently: SE Labs awarded ARP/AI its AAA rating after testing against live malware. The model is trained on more than a million files and a broad corpus of known attacks, which is why it recognizes something it has never seen before without waiting for a signature update.

The false positive number deserves as much attention as the detection number. A control that blocks legitimate users is a control that gets switched off within a quarter. Precision above 99% is what allows ARP to run in enforcement mode on production volumes rather than sitting in an alert-only mode nobody reads.

Beginning with ONTAP 9.18.1, ARP is enabled by default on all new volumes for AFF A/C series, ASA, and ASA r2 systems — providing immediate protection the moment a volume is created.

Key Capabilities

  • 99% threat detection accuracy on file workloads with under 1% false positives via ARP/AI (ONTAP 9.16.1+) — SE Labs AAA rated against live malware
  • Detects unusual file extensions, encrypted data surges, and abnormal volume activity patterns
  • Automatically creates locked snapshots on detection — 6 snapshots per 4-hour window by default
  • Default-enabled in ONTAP 9.18.1+ on AFF A/C series, ASA, and ASA r2 systems
  • Integrates with NetApp Console for centralized alerting and posture management
  • Operates entirely within ONTAP — no agents, no performance overhead, no external dependencies
  • Works alongside Cybervault and Immutable Snapshots to contain and isolate attacks

Coverage

  • NFS Volumes
  • SMB shares
  • Zero-Day Ransomware
  • AFF/ASA/ASA r2

Cybervault is NetApp's logically air-gapped, immutable data repository — a hardened vault built on ONTAP Snapshot copies and SnapLock Compliance that is completely immune to threats affecting the primary network, including ransomware, malware, and insider attacks. 

In March 2026, NetApp deepened the Cybervault with Elastio's Provable Recovery Control (Deep File Inspection) and Commvault integration — ensuring that vault recovery points are not just immutable, but verified clean before restoration. 

Key Capabilities

  • Logical air gap via SnapLock Compliance — no deletions by anyone during the retention period
  • Immune to insider threats: not even ONTAP admins or NetApp Support can modify vault data
  • Automated vault replication via SnapMirror — continuously synchronized without production impact
  • Replaces complex, expensive physical tape air-gap solutions with a software-defined vault
  • Deepened with Elastio Deep File Inspection and Commvault integration (March 2026)
  • Supports multi-cloud vault destinations including Amazon FSx for NetApp ONTAP
  • SnapLock Compliance volumes are the configuration the Ransomware Recovery Guarantee is written against

Coverage

  • Ransomware isolation
  • Insider threat
  • Compliance
  • Disaster recovery

NetApp's User Behavior Analytics, delivered through Cloud Insights Storage Workload Security, applies AI and machine learning to build baselines of normal user access patterns — then detects and responds automatically when behavior deviates in ways consistent with ransomware or data exfiltration. 

UBA is the critical complement to ARP: where ARP detects file-level patterns, UBA detects human-driven attacks — compromised accounts, insider threats, and lateral movement across shares that evade automated file-pattern detection. 

Key Capabilities

  • AI/ML baseline modeling of individual user and service account access patterns across file systems
  • Detects behavioral anomalies: mass file reads, unusual access hours, lateral movement across shares
  • Automated response: blocks malicious users, triggers snapshot creation, sends real-time alerts
  • 13-month immutable audit trail — forensic-quality records that cannot be altered post-incident
  • Catches human-driven attacks that evade automated file-pattern detection (complements ARP)
  • Full forensic analysis, searchable audit history, and regulatory compliance reporting built in

Coverage

  • Insider threats
  • Compromised accounts
  • Data exfiltration
  • Audit/compliance

FPolicy is ONTAP's file-access notification and enforcement framework. Every file access event over NFS or SMB can be monitored, filtered, and acted upon in real time. In native mode it blocks ransomware file extensions directly in ONTAP; in external mode it integrates with AI/ML-powered UBA platforms for advanced behavioral detection. 

FPolicy has two modes: Native mode blocks known ransomware file extensions without any external server; External mode passes events to third-party UBA and AI/ML platforms for advanced analysis, enabling zero-day ransomware blocking without signature updates. 

Key Capabilities

  • Native mode: blocks known ransomware file extensions before encryption can proceed
  • External mode: integrates with third-party UBA and AI/ML security platforms for advanced detection
  • Fires notifications on every file open, create, rename, delete — complete file activity telemetry
  • Enables zero-day ransomware blocking without requiring signature updates
  • Automatically initiates snapshot copies and blocks compromised user accounts on policy trigger
  • Supported across on-premises ONTAP and Amazon FSx for NetApp ONTAP

Coverage

  • Fire-level blocking
  • Extension filtering
  • Zero-Day
  • NFS/SMB

NetApp Immutable Snapshots powered by SnapLock provide write-once, read-many (WORM) protection for Snapshot copies — creating an undeletable, unalterable recovery anchor that survives any ransomware attack. Available in Enterprise and Compliance modes to match operational and regulatory requirements. 

Immutable Snapshots are the last line of defense for data recovery. No matter what an attacker does to primary data, a SnapLock-protected snapshot ensures you always have a clean recovery point — enabling RTO targets that would be impossible with traditional backup-only recovery. 

Key Capabilities

  • SnapLock Compliance: cannot be deleted or modified by anyone until the retention period expires
  • SnapLock Enterprise: privileged delete available via audited procedure for operational flexibility
  • Logical air gap — replaces expensive physical tape and disk air-gap solutions
  • ARP automatically creates locked snapshots within seconds of detecting a ransomware anomaly
  • Enables point-in-time recovery to a clean, pre-attack state in minutes — meeting aggressive RTO/RPO SLAs
  • Meets SEC, FINRA, CFTC, HIPAA, and other regulatory data retention requirements
  • Snapshot copies held in SnapLock Compliance volumes are the recovery objects covered by the NetApp Ransomware Recovery Guarantee

Coverage

  • WORM compliance
  • Ransomware recovery
  • Regulatory retention
  • Air gap

The NetApp Console Ransomware Resilience Service is the centralized command center for your entire ONTAP security posture. It surfaces ARP alerts, assesses workload risk, guides recovery to verified clean snapshots, and continuously monitors your ransomware resilience score across all ONTAP environments — on-premises and cloud. 

Following the March 2026 Elastio and Commvault partnerships, the Console now verifies recovery points as provably clean via Deep File Inspection before presenting them for restoration — eliminating the risk of recovering from a snapshot that already contained dormant ransomware. 

Key Capabilities

  • Real-time ransomware posture dashboard across all ONTAP workloads and environments
  • Guided recovery workflow — surfaces the last verified clean snapshot and steps through restoration
  • Continuously verifies recovery points as clean via Elastio Deep File Inspection (March 2026)
  • Commvault integration for cross-platform backup verification and recovery orchestration
  • Behavioral detection via ARP integration with centralized alerting and triage workflows
  • Available via 30-day free trial, PAYGO (AWS/Azure/GCP marketplace), or BYOL license
  • The resilience score and verified-clean recovery points are the operational evidence behind the guarantee — and the artifacts an auditor or cyber insurer will ask to see

Coverage

  • Posture management
  • Guided recovery
  • Multi-Cloud
  • ONTAP on-prem

How the Six Layers Work Together

NetApp's six security capabilities are not independent products — they are interlocking layers of a cohesive defense-in-depth architecture designed to detect, contain, isolate, and recover at every stage of a ransomware attack lifecycle. 

DETECT 

ARP (AI Detection)  |  User Behavior Analytics  |  FPolicy Monitoring 

CONTAIN 

FPolicy Block  |  UBA User Block  |  ARP Automatic Snapshot 

ISOLATE 

Cybervault (Air Gap)  |  SnapLock Compliance  |  Immutable Snapshots 

ASSESS 

NetApp Console  |  Posture Dashboard  |  Elastio Deep File Inspection 

RECOVER 

Guided Recovery Workflow  |  Verified Clean Snapshot  |  Commvault Orchestration 

Backed by a Guarantee, Not Just a Best Practice

Every storage vendor will tell you their snapshots are safe. Very few are willing to sign something. The NetApp Ransomware Recovery Guarantee commits NetApp to the recovery of Snapshot copies stored in a SnapLock Compliance volume following a ransomware incident — and if those copies cannot be recovered, NetApp provides compensation.

The payout is the least interesting part. What matters is what a guarantee implies: a vendor willing to accept financial liability for recovery is a vendor that has engineered recovery to be deterministic rather than hopeful. The guarantee is the commercial expression of the architecture described above — immutable Snapshot copies no administrator can delete, a logically air-gapped vault outside the production blast radius, and a Console that proves a recovery point is clean before anyone restores from it.

What the Guarantee Covers

  • Applies to new FAS, AFF A-Series, AFF C-Series, ASA A-Series, and ASA C-Series arrays running ONTAP One, configured with validated SnapLock Compliance volumes — the installed base is not automatically covered
  • Covers recovery of qualifying Snapshot copies from SnapLock Compliance volumes, beginning with the most recent copy replicated before the incident
  • Requires a NetApp Professional Services engagement, license compliance, and AutoSupport enabled on eligible arrays throughout the guarantee term
  • Claims are submitted in writing within seven days of the unsuccessful close of a ransomware incident
  • The guarantee covers recovery of the Snapshot copy itself. It does not warrant that data was uncorrupted before it was vaulted — which is precisely why detection speed and Deep File Inspection verification matter as much as immutability
  • Business outcome: convert "we believe we can recover" into a written commitment you can take to a board, an auditor, or a cyber insurance underwriter. Insurers increasingly price on demonstrable recovery capability, and a vendor-backed guarantee paired with verified-clean recovery points is the evidence that conversation runs on.

Eligibility, guarantee term, and compensation limits are defined in NetApp's published guarantee documentation. Confirm current terms with your NetApp account team before quoting them to a customer.

NetApp Security and Zero Trust Architecture

NetApp's security model aligns to NIST Zero Trust Architecture — assuming breach at every layer and enforcing least-privilege access, continuous verification, and immutable audit trails at the data layer where attacks ultimately land. 

  • Verify Explicitly — FPolicy and UBA enforce continuous authentication and authorization at every file-access event, trusting no user and validating every request against behavioral baselines. 
  • Least Privilege Access — RBAC, multi-tenancy, and Storage Workload Security ensure users only access exactly what they need, blocking lateral movement at the data layer. 
  • Assume Breach — ARP, Cybervault, and Immutable Snapshots operate on the premise that a breach has occurred, containing the blast radius instantly and preserving clean recovery points. 
  • Immutable Audit — 13-month immutable audit logs via Storage Workload Security provide forensic-grade evidence chains that cannot be tampered with post-incident. 
  • Consistent Policy — One ONTAP security policy spans on-premises, Amazon FSx, Azure NetApp Files, and Google Cloud — eliminating security gaps across the hybrid estate. 

Connect with our WWT experts

Lauren WolfeGlobal Partner Mgr
Dale DarbyTechnical Solutions Arch III
John LochausenTechnical Solutions Arch III
Brian BartellMgr, Practice

NetApp Security

Confidently safeguard your data with AI-powered, built-in security that provides real-time threat detection, protection, and recovery. An intelligent data infrastructure enhances your security posture to protect any workload stored anywhere.

1 Follower
WWT
  • About
  • Careers
  • Locations
  • Help Center
  • Sustainability
  • Blog
  • News
  • Press Kit
  • Contact Us
© 2026 World Wide Technology. All Rights Reserved
  • Privacy Policy
  • Acceptable Use Policy
  • Information Security
  • Supplier Management
  • Quality
  • Accessibility
  • Cookies