PRODUCT SECURITY GOOGLE CLOUD Sep 30, 2026
What shipped. NetApp moved NetApp Console Cyber Resiliency to general availability for Google Cloud NetApp Volumes (GCNV). Per the vendor’s product-update page, GCNV customers “can now protect their workloads running on Google Cloud against ransomware attacks with a unique multi-layered approach.” The capability first appeared as a preview with GCNV earlier in 2026 (June 2026 preview note); this announcement is the GA step, not a new product line.
How it works. NetApp describes the workflow as Console Ransomware Resiliency powered by ONTAP’s Advanced AI-based ransomware protection (ARP/AI). It “leverages ONTAP’s built-in security features like immutable snapshots and access control while streamline[ing] the backup and recovery workflow to provide an extra layer of protection.” In practice that means detection and recovery are Console-driven while the enforcement primitives stay where they have always been — on the ONTAP side, in Snapshot copies and role-based access. This is the pattern to understand: Console is the control plane, ONTAP is the data plane.
Who it applies to. NetApp states customers “can use GCNV Flex Unified service level with ONTAP-mode” to achieve the protection. That qualification matters: the announcement covers the Flex Unified service level in ONTAP mode specifically. It does not extend to other NetApp cloud services by implication — there is no AWS/Azure/Cloud Volumes ONTAP GA claim in the source, so do not assume parity from this note alone. For the underlying platform differences, see Cloud Volumes ONTAP and the on-premises versus cloud guide.
The operational to-dos for GCNV admins. Three things are worth doing this week: (1) confirm your GCNV deployments are on the Flex Unified service level in ONTAP mode — anything else is out of scope for this GA; (2) check that immutable Snapshot policies and access controls are actually configured, because the Console workflow builds on them rather than replacing them — the ransomware protection reference and snapshot management guide cover the primitives; (3) validate that your backup/recovery runbooks now assume Console as the orchestrator. NetApp points to its Console Ransomware Resiliency documentation for the detail.
What the announcement does not say. NetApp’s note does not carry a version number, a list of known issues, or an upgrade path — it is a feature-availability notice, so treat it as a capability you can now adopt rather than a release you must schedule. That distinction matters when it lands in a change window: enabling Console Cyber Resiliency for GCNV is a configuration decision, while the storage-side controls it relies on (immutable Snapshots, ARP/AI, access control) are the components you already patch and test.
Read the original (NetApp product updates) · Hybrid cloud hub · Cloud Volumes ONTAP reference · On-prem vs cloud