Smarter, Strategic Thinking
Technology is moving faster than most organisations can adapt.
The question is can your strategy keep up?
Smarter, Strategic Thinking is a podcast for IT leaders, decision-makers, and executives responsible for data, infrastructure, and long-term risk.
Each episode brings practical insight from industry leaders and innovators covering the realities behind ransomware resilience, storage strategy, infrastructure modernisation, and the decisions shaping the future of enterprise IT.
Hosted by Fortuna Data, trusted partners of IBM, Lenovo, Seagate, HYCU, QNAP, Qualstar and many more, this podcast cuts through vendor noise to focus on what actually matters: performance, cost, risk, and scalability.
If you’re responsible for where your data and your business goes next, this is where the right conversations start.
Smarter, Strategic Thinking
IBM FlashSystem: 20PB Density & 60-Second Ransomware Detection
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of Smarter Strategic Thinking, host Ray Quattromini talks to Alex MacIndoe, UK Flash Systems sales lead at IBM, about the newly refreshed FlashSystem range the 5600, 7600 and 9600 launched in February 2026.
Want to know more: https://www.data-storage.uk/ibm-flashsystem/?utm_source=Podcast_Flashsystem&utm_medium=Youtube_Video&utm_campaign=Flashsystem
The conversation covers how IBM is achieving industry-leading storage density: 20PB in just 18U of rack space at a 1:1 data reduction ratio, compared with over 100U from IBM's nearest competitors. Alex explains how IBM's in-house manufacturing of FlashCore Modules protects lead times, and how a custom CPU built into every module enables hardware-accelerated compression, deduplication and ransomware detection without loading the controllers.
Alex also demos FlashSystem AI, a natural-language assistant that lets storage admins provision LUNs, tune performance and manage compliance documentation through chat rather than command line — with every action logged and a dual-approval safeguard against destructive commands from rogue operators.
On the security side, Alex details IBM's inline ransomware detection: the system monitors every I/O for entropy-level anomalies and is contractually guaranteed to detect a ransomware event within 60 seconds, with Sentinel verifying clean snapshots before any restore.
The episode closes on Flash Grid, IBM's single-pane-of-glass tool for managing multiple FlashSystems — including older and newer models — across sites.
Keywords: IBM FlashSystem 9600, storage density, ransomware detection, FlashSystem AI, Flash Grid, enterprise storage, flash storage, cyber resilience, IBM storage.
Yeah, I'm an Arsenal fan.
SPEAKER_01Oh you're even happier. Are you looking forward to the weekend?
SPEAKER_02Yeah, you wait till Saturday.
SPEAKER_01Well I'm a Liverpool fan, so you know there's always all there's you know we were never gonna win against AC Milan and I was in Eston Bull on the twenty fifth of may two thousand five and it was like it was bedlam.
SPEAKER_02Storage and the cloud is affordable and the cloud is good and everything else. But ten years ago, a petabyte of storage was in ten rack. This is the crazy, isn't it?
SPEAKER_00Your storage is under attack. Your team has seconds to respond. IBM Flash System guarantees ransomware detection in under 60 seconds, backed by a legal contract. And it fits 20 petabytes into just 18U, while competitors need over 100. If you're responsible for enterprise infrastructure, this is the conversation you need to hear.
SPEAKER_02Let's dive in. Hi, I'm Ray Quatramini from Fortuna Data. Welcome to Smarter Strategic Thinking. Today we have Alex Mekindo talking about IBM flash storage. Alex, pleasure to meet you. Thank you for coming in. Tell us a bit about your background and your role in IBM.
SPEAKER_01Been around the storage market for about 20 years. Started off doing the basics, right? So installing tape drives, cleaning tape drives, fixing tape drives, and then you move up to disks and arrays. Started off on the technical side, so really getting my hands dirty. And then I slowly went on from the technical side onto more of a pre-sale side, more of a consultancy side, and then went through the backup side as well with Veritas and the semantic side. And then eventually I ended up at IBM about seven years ago, and I transitioned from the technical side all the way onto the sales side now. So my current role at IBM is to kind of look after the flash systems from a sales point of view in the UK. You know, every day I am just travelling to different business partners or different customers to talk about our new flash systems, which we'd released a new batch in February this year.
SPEAKER_02Tell our audience what IBM's flash systems are and where you start from a footprint and where you go in terms of capacities?
SPEAKER_01Sure, we've kind of condensed our flash systems this year. So we only really have three models. They're called the 5600, the 7600, and the 9600. With each model, they go up in size and in slot count and the you know the amount of memory and cash that you can have with them.
SPEAKER_02From a capacity point of view, where do they start and where does it end?
SPEAKER_01We have about five or six different sizes of flash core modules. So they start off at you know single digits, and you don't have to fill the box up with all of the drives straight away. So you can you know you can have four or five drives depending on what your use case is, and then you can go all the way up to a 9600, which has got you know 32 slots, and you can fill them all up. And the largest flash core module we've got is currently 105 terabytes, and with data reduction, you know, with five to you can get five to one on certain data. There's a hell of a lot of uh data in in one flash core module. Yes, and of course, you can then start to daisy chain these arrays to get to you know petabytes of the stuff. Yeah, yeah, yeah. In in a tiny footprint. In in a very, very small footprint, yeah. And you know, the the 9600 is is to you.
SPEAKER_02In terms of storage density, it's five times more dense than anyone else on the planet.
SPEAKER_01Yeah, so we've we've recently done some research because of the new models that came out in February. So you know, we look at we look at our competitors, obviously, and I didn't know how big this margin was. So if I take 20 petabytes and I do it a one-to-one ratio, so I'm not using any data reduction here at all, we are 18 U. Our nearest competitor is over 100 U. Five times more physical space. You have to worry about tiles and everything and weight load in data centers, but then it's also cooling and power with with less storage, less power and cooling on a day like today, is also very important.
SPEAKER_02It is sunny, by the way, for our viewers out there. It's due to get to 30 degrees today. But so IBM storage has gone for a big transformation over the last few years. From your perspective, what's the most exciting shift you've seen of how customers think about storage?
SPEAKER_01Come a long way. So I I I I'm I'm 20 years in, which is some people will say that's a lot of number, and some people will say it's not a lot, especially with the IBM tenure. A lot of people are 10, 20, 30 years in. But you know, I've seen it go from physical media from from floppy drives um from five and a quarter inch to you know three and a half, and all the way up to to you know what we see now is 105 terabytes in in your hand. Um by the end of the year, we're gonna have you know 200 terabytes in your hand. And with five to one compression, that's a petabyte in your hand.
SPEAKER_02And that and that's a that's an FCM there.
SPEAKER_01This is an FCM here, yeah. So the you know, the the biggest change I've seen is you know the consolidation of the size. This is before you we start talking about you know AI and everything else. Is you know, are going into customers who have bought storage five years ago, and it could be from us, it could be from our competitors, and they have racks of the stuff, you know. They've got four or five or six racks, and they go, Well, you're gonna replace it with four U or eight U or something like that. And that's the biggest change I've seen recently is just the consolidation of the size and how much data you can get in such a small form factor these days. You know, obviously we've now got storage for AI and we've got storage for cyber resilience, which is even even you know, yeah, it's it's becoming more and more feature-rich. It's not just block storage, you know. Five, ten years ago it was block storage, you may have got some data reduction, provision it, and you align it to a server, but now it's got so much more intelligence in there and it's really giving the value back to the customers.
SPEAKER_02You know, the 9500 was for you, the 9600 is to you, now storing 3.3 petabytes into you. How does the density stack up against the competitors? What's driving this real world decision?
SPEAKER_01We've done the research against Dell, Pure, HP, etc., and you know, we are 18U. I I can't remember the exact figures, but we are 18U for 20 petabytes. Pure are 121, Dell are 131 or something like that. They're all over 100. Not sure why they are over 100 when you know we look at these, and you know, this is this is our latest flash core module, and this is you know, I think this is a I'll have to read the back of there, but I think this is 40 terabytes. So it's not it's not the big ones and it's not the small ones, it's you know halfway between.
SPEAKER_02But even the the big one, 105, it's still the same footprint.
SPEAKER_01It's still the same. We don't change the footprint, we just we just add more memory cores on here. And you know, if I open it up, this is this is why we can store so much, it's it's double-sided. So I can open it up and it flips over like this, and you can see there's these there's more there's more memory chips on there. And you know, this is this is how we get the density on there.
SPEAKER_02And you make these?
SPEAKER_01We make these, these have got our our our logo on it with the market going at the moment, which is really key, because we make them, we don't buy them in. Can actually help with supply. Still got a 40-day lead time on our kits, which is which is pretty good compared to our competitors. I've heard lots of horror stories of you know, I don't know when the kit's turning up, let alone it's it's coming in a couple of months. But because we make these, we've you know, we've we've sourced supply for the actual memory chips until years ahead. We'll have to give it to our supply our supply chain manager, he's done a really good job. Regardless of the features and the functions, everything else, just reacting to the market at the moment and BMN to serve our customers, deliver to our customers is is quite key at the moment.
SPEAKER_02Your secret source, if I can call it that, is that shiny thing on the top?
SPEAKER_01Yeah, we've got a couple of things. So we've we've got these CPUs. So we've got a CPU on every single flash core module. I don't think anybody else does this. This is quite a unique selling point for us. Um, and what this enables us to do is we can turn on all these extra features. So we can turn on the hardware data reduction, the compression, we can turn on cyber resiliency checks, so we can actually scan for ransomware without having to overload the controller. In the normal world, you'd have to, you know, you turn on all of these features and all of the processing would go up to the controllers inside the chassis. Whereas we still have those controllers in the chassis, but we get a lot of extra help from every single flash core module because it has this CPU.
SPEAKER_02And that's your custom designed ASEC, isn't it?
SPEAKER_01Absolutely, yep, yep. So this is ours, and then we also have a unique IP on the actual memory chips as well. So the QLCs, so the the uh so each memory chip, um, they're called QLCs, so the quads, so that which means four bits per memory core, and then what we do is we mix the QLCs with the SLCs, which is the single bits. Um and because we can mix the QLCs with the SLCs, what we can do is we can actually get to the speed and the endurance of the TLCs, which are the the industry standard and the best of the best, which is trick TLCs is three, so it goes from single to to to three to to four. So that's how we kind of you know, we we mix the QLCs with the SLCs to make it behave like a TLC.
SPEAKER_02And I heard a really interesting stat, and uh your flash core modules, which you've had for eight, nine years now, you've never ever ever had a failure.
SPEAKER_01No, so from uh from an endurance point of view, um I'm gonna touch wood because it hasn't happened yet, but uh, we haven't had to replace one in the field. I think the last count that we had, we had over a million shipped, and we've never had to replace one for from an endurance point of view. They haven't worn out yet. So so that whoever's created the IP for the QLCs and the SLCs and everything else, they've done a really good job. And it's actually a lot of the IP is created in Hursley in the UK. So it's it's quite you know, it's quite close to us. Uh it's quite close to us right now. Um and it's great that to hear from so especially from a big American company like that with the UK is you know is is helping out on keeping these flashcore modules the the latest and greatest.
SPEAKER_02Yeah, that it's it's it's amazing. I'm constantly flabbergasted that any in what by the end of this year will have a petabyte in that footprint. It's mad.
SPEAKER_01I d I don't know if you've ever had a Google of how much data a petabyte is, but it's it's an astonishing amount of HD videos. I think it's like 770,000 uh HD videos in you know in the palm of your hand.
SPEAKER_02It's crazy. Flash Systems AI is described as an acting agent for co-administrators trained on tens of billions of data points. In plain terms for a customer who's never used AI-driven storage. What does this feel like using IBM's flash systems?
SPEAKER_01It's a really good question. This is a brand new feature out this year. So it was only introduced with the the 56, the 76, and the 96, and it's called flash systems.ai, as you said. And it's kind of it's like having a virtual storage admin sitting on your shoulder. If you've got tasks to do like creating learns, provisioning LUNs, if you've got alerts that are coming along, the flash system.ai will help you in a kind of a normal language kind of way. So instead of having to circumvent lots of different maybe screens and lots of different mouse clicks, you can actually chat to the flash system. Um, which is, you know, you've got to get your head around that bit, first of all. So you actually have a chat window on the right hand side and you you talk to it, and you'll say, in natural human language, you'll go create 50 terabyte lungs, and you give maybe give them a name. Um so you can say call them one, two, three, four, and assign them to server one two three four. Press enter. And um the flash system will go away and it will say, right, this is what I think you you you said. So it will actually kind of summarize what what you've said, and it will say, Here's the run book to do that. Do you approve? Um, and you know, you press approve, it goes away and does it. Um, so it's it's that's why we say it's like having a virtual storage admin on you know on your shoulder because it goes away and does those jobs for you without having you having to go through uh a week's course to work.
SPEAKER_02Or command line, or yeah. That's a bit of a game changer, that's a bit of a time saver as well.
SPEAKER_01When we launched this in in February, we had a lot of people in the room and there was lots of customers, lots of business partners, and I heard the words cool and exciting for the very first time when you're talking about storage, because they were watching flash system.ai working. And it also it that's that's the reactive way the flash system.ai works, it also works proactively as well. So if you have alerts, because I said earlier about alerts, if you have, I don't know, let's say a performance alert, so if a workload is hitting the I.O. limit, yeah, it may recommend some changes. If the let's say there's a cyber ins a cyber resiliency incident, it will recommend some changes. And it will say, Maybe you want to do this. And you go, oh, actually, yeah, I would like to move the workload from maybe an old flash system to a newer flash system because it's faster, it's better, it's more suited for that workload, and then it will you know give you the run book, say approve, yes, and then it'll go away and do it. This is crazy.
SPEAKER_02From from when I remember entering command lines and what's the what's the LUN of that and what's the worldwide name of this, and how do you map this? And it does it all for you.
SPEAKER_01Well, I'm pretty sure we've all made I I've definitely made some mistakes on on you know which lun to assign and or which one to do this and stuff like that. So hopefully it could take some of that away. Also, maybe speed things up as well. So hopefully it will our kind of our idea was they can do things a lot quicker. Yeah. So they can get more of their jobs out of the way, so they could maybe then go and be more innovative. So it's all about trying to free up some s free up some time for the storage admin to maybe look at what's coming out next. So, what storage do I may need for containers? Because the world is the application world is shifting to containers. Maybe they want to learn or set up what storage they need for containers or what storage they need for AI or something like that. So it's all about trying to free up some time for the storage admin to go and do something you know that's giving back for the company.
SPEAKER_02Flash system.ai, can you explain its decision and generate compliance documentation for a Fortuna customer in a regulated industry? How does that audit trial work in practice?
SPEAKER_01Obviously, everything is everything you type and everything it says is is safe, right? It all goes into the log files. So if anyone wanted to go and have a look at that, you know, for a regulatory purpose, why did you make that decision or why did you do that? All audited, right? So you can then you can have a look at it, you can search for it at a later date because a regulatory board might need to have a look at that.
SPEAKER_02You talk about flash system AI. If I was a a rogue operator and I wanted to delete some LUNs or storage, what what prevents me from doing that?
SPEAKER_01So the good thing is flash system.ai has not been taught, because it is a a a language model at the end of the day, it hasn't been taught how to do anything destructive. So if you did type in delete lun one, it would actually come back and say, I do not understand the command. So it hasn't been taught anything destructive. But on top of that, so what you'd have to do is you'd have to go out of flash system.ai and go on to the the normal GUI that you'd use normally, um, and then you'd have to delete it through there. But what we can do is we can turn on something called that so a second approver has to approve anything destructive. So we can add on layers of of defence against a rogue insider or you know someone who wanted to do something destructive to make sure two people have to approve anything that's destructive.
SPEAKER_02Flash System AI automates provisioning, tuning, diagnostics, and remediation. Can it assist with initial configuration as well, or is it more an ongoing operational tool that is already set up?
SPEAKER_01It's a bit of both, right? So it obviously it can't do anything physical, so it can't physically put the put the rack in for you. But as soon as it's up and running, you know, you can then start to ask Flash Instai to start provisioning. So if you need to create obviously quite a few LUNs, you need to provision the LUNs, you can write it all down inside the flash.ai to create the runbook to run those commands. So it is a bit of both, it can help you set up because a lot of the setup in a storage device is creating the LUNs and provisioning the LUNs, and then also setting up the policies for H A and DR. So, you know, if you need any replication, if you need any mirroring, you can do that all of that in the code.
SPEAKER_02Could I ask AI what are the performance metrics for certain systems or and that's where the proactive side of the flash system comes in.
SPEAKER_01So if it's monitoring a workload and you do have to tell it what the kind of the limits are. So if you've got a workload that you know needs this certain limit, it will then monitor that that limit, and if it breaks the limit, that's when it will proactively say it's running too, you know, this flash system is running too slow. For this workload, you might want to move it to something faster.
SPEAKER_02Yeah. If I'm an administrator and I want to show my boss that my systems are running pretty good, or not, as the case may be, what could I could I then get a nice little graph printed and say, here, boss, this is what it is. We need some more storage or something's going amiss, or absolutely yeah.
SPEAKER_01So you can see that you can see the spikes of the I.O. and you can you can save those as a report and you can print them out, and it will show you where your line of the policy is and it will show you where the spikes are. So it'll, you know, if that if there are any spikes, you don't have to have spikes, but it will show you where the spikes are and what time they are, so you could maybe even troubleshoot it to a point where well why the system comes on. Exactly. What's what's spike in the I.O. Because before you spend some money, you might want to try and fix the fix the spikes. But if obviously, if it is, you know, if it's overloaded, if there's too many users, or if the workload just needs more power, then obviously you can gain as much information from you can from the flash system to then then go to the boss and ask for some more money.
SPEAKER_02If a customer's workload changes significantly, say they move into AI training or spin up a new database, how quickly does Flash System recognise that it it it retunes the system without admin intervention?
SPEAKER_01Pretty instantly. So because we monitor every single I/O, and if it goes over your threshold, it will alert you straight away. So you know if you set a certain policy threshold and you hit it, you know, it it will it will monitor it will alert you straight away.
SPEAKER_02And is it is it also self-tuning?
SPEAKER_01Kind of, yeah. What I said before was it will make recommendations. So it will if you've got because what we can do is if you've got many flash systems, what we have is something called a flash system grid. And they all be they can all be managed from kind of a single pane of glass. So if you've got some some of the newer models with the new flash flash core modules and some of the older ones with the older flash core modules, it can make recommendations and say this workload should maybe go on to some one of the new flash systems because it's faster, it's got more capacity, and then what it'll do is it will create a runbook of moving that workload over to the new the new flash system. A human has to approve it, and then it will move the workload and it will be absolutely seamless to the end user. So there'll be no downtime needed. The user shouldn't know in the background that the workload has moved from one storage box to another storage box. Nice new flash system, which is uh the the the top speed.
SPEAKER_02You mentioned flash grid. Do you want to explain a little bit more about what flash grid is and how it would work in a customer's environment?
SPEAKER_01Absolutely. So as soon as you have multiple flash systems, you know, before you have multiple GUIs. So you'd have flash system one, GUI, flash system two GUI, and you'd have to manage them separately. But now we have something Flash System Grid. So as long as your flash system supports the latest code, which could be an older model or the newer models, then we create Flash System Grid. And then that gives you one pane of glass to manage all of the flash systems and all of the policies, which could be a HA policy, it could be a DR policy, it could be just the management policies and stuff like that. But you can all manage it from one pane of glass rather than the multiple GUIs. It also works across site. Absolutely, yep. So if you've got a secondary site or HA site or a DR site, then you set it all up from the flash system grid.
SPEAKER_02And it would then load balance and whatever it needs to do across.
SPEAKER_01Yeah, whatever your policies, you know, if you if you've got synchronous or asynchronous replication, you know, you set it all up from the flash system grid.
SPEAKER_02HFCM5 checks drive stats every two seconds against ransomware patterns detecting in under one minute. How does it detect false positives and what's the response for automating it or stopping it? What actually says ransomware, what's the next thing?
SPEAKER_01It's a really good question. So it's our it's our it's what we call inline threat detection, and it happens via the CPU here, that's why we can turn on these nice features. And what we do is we actually monitor every single I.O. into the drive. And we use we use the the CPU for that. Um and because we monitor every single I/O, we get to learn a lot of the characteristics of the I/O pattern. Um and when the I.O. pattern maybe changes, um, and we know what an I.O. pattern looks like from a ransomware point of view, um, it's actually what what we it's a mathematical term called the entropy level, which is the how we how you measure randomness. Um so if the entropy level changes above our policy, what we do is we we we flag a ransomware um an event, and it goes into the flash system log and it alerts the the user or the storage admin that there is a ransomware level threat. We don't actually do anything apart from that, so we just alert. We don't block anything or change anything, we don't turn anything off because you know we want the human to make the decision. So you know they can make the decision whether to you know pull the plug on the internet or turn the box off or or you know do something with the workload. Or you know, they can have a look at our safeguarded copy snapshots and then restore from an old uh from a from a snapshot. Because what we've had in the past, if if um for example, if someone forgets to tell the um the system that they turn on an encryption, an encryption, obviously, if you turn on IBM encryption, it looks like ransomware. So that's why a human will always make the last decision. Right.
SPEAKER_02And how how many snapshots can the flash systems actually hold?
SPEAKER_01It's all depending on how much space you've got. Um, because I think you'll run out of space before you run out of the fit the logical limit of snapshots because it's into the hundreds or the thousands. But it's you know it uses up a little bit of space every time you do a snapshot because it it recognises what's changed since the last snapshot. Going back to the the ransomware we you know we will detect it in 60 seconds. That's a that's actually a guarantee. We actually guarantee that with a with a legal contract with the customer, and then you then you go back to the snapshot. Just be aware that you know you need to make sure so when you go back to that snapshot, you know, it's it's clean and everything else. So we've we've got tools out there as well called Sentinel that will make sure that that snapshot is clean before you make the decision to go back to that.
SPEAKER_02And you can roll back, correct me if I'm wrong here, to a minute.
SPEAKER_01Yep, we guarantee that one as well. So there's a our guarantee is to detect and restore from a ransomware level event in 60 seconds. If you can work that quickly, you can restore it in 60 seconds. But um, you know, you do do you do need to do due diligence to make sure that you're restoring back to the right snapshot. Yes. And that's why we've got tools like Sentinel to make sure that it's clean. You're not restoring ransomware and you're restoring to a clean version of that snapshot.
SPEAKER_02The FCM5 does have hardware accelerated analytics on every IO. What's the latency overhead of that? And how does IBM ensure that it doesn't impact production workload?
SPEAKER_01Well again, I'm gonna I'm gonna point to the CPU again. So this is this is what makes us not have the massive overheads that maybe some of our competitors have. So you can turn on all of the features that we've talked about compression, and the inline threat detection, the hardware deduplication, and the CPU will take most of the work. Obviously, it's not gonna be zero overhead, but it will be very, very minimal overhead because this CPU will take all of that processing and power off the controllers and keep it all on that CPU.
SPEAKER_02Well, Alex, yeah, that's really good, and hopefully everyone now will be knowing more about IBM flash systems. Thank you for your time. Give us a thumbs up, give us a like, and uh enjoy your day.