Can Your Storage Array Detect Ransomware? NetApp vs Pure

Can Your Storage Array Detect Ransomware? NetApp vs Pure

In March 2026, NetApp — the vendor with the loudest claim to storage-native ransomware detection — signed alliances with Commvault and Elastio, two companies whose entire business is inspecting data after it leaves the array. That is the storage industry quietly answering the question buyers keep asking me: if my array can detect ransomware, do I still need detection anywhere else? The answer, from the vendor best positioned to say no, is yes.

This brief lays out what NetApp’s ARP/AI actually catches, what Pure Storage’s SafeMode does instead, why the two approaches are not interchangeable, and how the Commvault and Elastio deals settle the detection-versus-immutability argument. If you are budgeting a ransomware line item for FY27, this is the framing to take into the meeting.

What changed

Three things moved this from a feature-checklist debate to a strategy question. First, NetApp’s Autonomous Ransomware Protection with AI (ARP/AI) became the first storage-native detection engine to earn SE Labs’ AAA rating, posting 99% detection accuracy with zero false positives on legitimate workloads in that test. Second, NetApp wrapped it in a Ransomware Recovery Guarantee — a warranty-style commitment, with configuration strings attached, that snapshot recovery will work. Third, and most telling: in March 2026 NetApp announced partnerships with Commvault and with Elastio, embedding Elastio’s deep file inspection of snapshots into its Ransomware Resilience Service and wiring ONTAP’s detection signals into Commvault’s recovery workflows.

The takeaway a VP can repeat: the vendor with the best array-level detection just paid for two more layers of it. That is not an admission of failure — it is an admission of scope.

Why it matters

Ransomware economics turn on two clocks: time to detect and time to recover clean. Endpoint and network tooling owns the first clock until the attacker reaches your data. Once encryption starts hitting primary storage, the array is the last observer with a real-time view — and the first place a fast response can shrink the blast radius from terabytes to gigabytes. A detection that fires minutes into an encryption run, paired with an automatic snapshot, is the difference between restoring a volume and rebuilding a data center.

But detection at the array is inherently a file-workload story. ARP/AI watches NAS activity — entropy shifts, extension churn, abnormal write patterns on NFS and SMB shares. Attackers who exfiltrate quietly, encrypt inside application-level containers, or simply go after your backups first never trip that wire. That is why the immutability camp, led by Pure, has argued for years that guaranteed-clean copies matter more than clever alarms. Both camps are half right, which is exactly what the March deals confirm.

NetApp’s bet: detect at the array

ARP/AI runs on-box in ONTAP, using a pre-trained model that needs no per-workload learning period — a genuine improvement over the original ARP, which required weeks of baselining before it could be trusted in enforcement mode. When it suspects an attack it takes an automatic snapshot and raises an alert, so your recovery point lands minutes into the incident rather than at last night’s backup. The SE Labs result — AAA, 99% detection, zero false positives in testing on ONTAP 9.15.1 — is the strongest independent validation any storage vendor has for on-box detection, and NetApp has been justifiably loud about it.

Where it is weaker: ARP/AI is a file-workload feature. SAN and block-heavy estates get far less benefit, and a lab result on curated samples is not a guarantee against a patient adversary who throttles encryption below detection thresholds. The Recovery Guarantee is real money but reads like an insurance policy — specific configurations, specific processes, or no payout. NetApp fits shops that are already ONTAP-centric with large unstructured estates, and it is the obvious pick when file-share ransomware is your top tabletop scenario. For the broader platform question, see our full Pure Storage vs. NetApp comparison.

Pure’s bet: snapshots nobody can delete

Pure Storage — mid-rebrand to Everpure as of mid-2026, though the product names have not moved — takes the opposite position: assume detection fails, and make the copies indestructible. SafeMode retention locks snapshots so that nobody, including a fully compromised storage admin account, can delete them before the timer expires — up to 30 days on FlashArray, up to 400 days on FlashBlade. Unlocking early requires contacting Pure support with pre-designated named contacts and a multi-step verification process. It ships in the box at no extra license cost, which procurement will notice.

The honest critique runs the other way: SafeMode is containment, not detection. It tells you nothing while the attack is happening. Pure1’s fleet analytics can flag anomalies — a sudden drop in data reduction ratio is a classic encryption tell — but that is telemetry-scale signal measured in hours, not an on-box engine measured in minutes, and Pure has no SE Labs-style third-party detection rating to point at. The 30-day FlashArray ceiling also matters: dwell times beyond a month are common, and a locked snapshot of already-encrypted data is a very safe copy of garbage. Pure fits block-heavy and mixed estates that want a guaranteed recovery floor with near-zero operational overhead — and teams honest enough to admit they will not tune an alerting pipeline.

Detection vs. immutability, side by side

The verdict up front: NetApp wins on detection, Pure wins on simplicity of containment, and neither closes the case alone.

NetApp ARP/AIPure SafeMode
Core mechanismOn-box AI detection of encryption behavior on file workloadsRetention-locked snapshots deletion-proofed against admin compromise
Third-party validationSE Labs AAA, 99% detection, 0 false positives (ONTAP 9.15.1 test)None for detection; immutability is architectural, not tested behavior
Blast-radius effectShrinks it — auto-snapshot minutes into an attackCaps it — guarantees a floor to recover from
Coverage gapBlock/SAN workloads, slow-and-low encryptionNo real-time signal; 30-day FlashArray lock vs. longer dwell times
Operational liftLow-moderate — alerts need an owner and a runbookNear zero — set the policy, size the snapshot capacity
Best fitONTAP shops, large NAS/unstructured estatesBlock-heavy or mixed estates wanting a guaranteed recovery floor

One cost note both sides underplay: aggressive snapshot policies consume real capacity, and SafeMode’s lock means a mis-sized policy cannot be walked back quickly. Budget 15–20% headroom before you turn either program on. List pricing varies; neither feature carries a separate license, but the capacity to feed them is not free.

Does array detection replace backup scanning?

No — and the March 2026 announcements are the proof. NetApp’s Elastio deal embeds Elastio’s Provable Recovery Control into the NetApp Ransomware Resilience Service, adding deep file inspection of snapshots — actually opening and validating the data, not just watching write patterns — starting with Amazon FSx for NetApp ONTAP. Elastio’s pitch has always been that a snapshot is not a recovery point until something has proven it clean, and NetApp just endorsed that pitch by productizing it. Elastio remains a young company betting on a single capability, which is a vendor-viability question worth asking in diligence, but the capability itself is the missing piece between “we have snapshots” and “we can restore with confidence.”

The Commvault alliance answers the other half: recovery orchestration. Commvault brings backup-layer anomaly detection, threat scanning, and — critically — the workflow to rebuild at scale, now consuming ONTAP’s detection signals directly. Commvault’s strength is breadth across heterogeneous estates; its weakness is that breadth comes with a heavier operational footprint than either array feature. The pattern to internalize: array detection shrinks the blast radius, immutable copies cap it, and backup-layer inspection proves your way out. Three layers, three different failure modes. Our immutable backup storage comparison covers the second layer across vendors in detail.

What to do about it

  • If you run ONTAP with meaningful NAS estates, turn ARP/AI on now — it is the rare security feature with independent test results and near-zero workload cost. Assign an alert owner before you enable it, not after.
  • If you run Pure, enable SafeMode this quarter, but size retention against your realistic dwell-time assumption — 14 days is a floor, not a default, and FlashBlade’s 400-day ceiling is where long-retention use cases belong.
  • Whichever array you own, do not cut backup-layer scanning from the budget. Array detection is a tripwire; it is not verification. Rule of thumb: if you cannot prove a recovery point is clean, you do not have one.
  • If your board is asking about worst-case recovery, evaluate an isolated recovery environment as the fourth layer — our cyber recovery vault comparison breaks down who does that well.

Frequently asked questions

Can a storage array detect ransomware?

Yes, for file workloads. NetApp’s ARP/AI detects encryption behavior on NFS and SMB shares in real time and takes automatic snapshots when it fires. Block workloads and slow, throttled encryption remain hard for any array-level engine to see, which is why array detection is a layer, not a strategy.

Is NetApp ARP/AI better than Pure Storage SafeMode?

They solve different problems. ARP/AI is real-time detection with strong third-party validation; SafeMode is deletion-proof containment with almost no operational overhead. A NAS-heavy ONTAP shop gets more from ARP/AI; a block-heavy estate gets more from SafeMode. Mature programs want both capabilities, from whichever vendors they run.

Do I still need backup ransomware scanning if my array has detection?

Yes. Array detection watches write behavior; backup-layer tools like Commvault and Elastio inspect the data itself and prove recovery points are clean. NetApp’s own 2026 partnerships with both companies signal that even the best array-level detection is one layer in a defense-in-depth design.

How accurate is storage-level ransomware detection?

The best independent number as of mid-2026 is SE Labs’ test of NetApp ARP/AI: 99% detection accuracy with zero false positives, earning a AAA rating. Treat lab numbers as an upper bound — real estates include workloads and attacker behaviors no test set covers.

Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.