Jake Bussell
July 14, 2026

What is Content Disarm and Reconstruction (CDR)?

Every organization needs to exchange files. Documents arrive through email, collaboration platforms, customer portals and third-party systems every day. The challenge isn't whether to accept files, it's how to do so without introducing hidden threats into your environment.

Traditional security tools try to answer one question:

Is this file malicious?

They inspect files for known malware signatures, suspicious behavior or indicators of compromise before deciding whether the file can be trusted.

Content Disarm and Reconstruction (CDR) approaches the problem differently.

Instead of trying to determine whether a file is safe, CDR cybersecurity technology assumes every externally sourced file is untrusted. Every file is rebuilt before it's allowed into the environment, and only a trusted version is delivered to the user.

Rather than detecting attacks, CDR removes the opportunity for file-based attacks to execute in the first place.

This guide explains how Content Disarm and Reconstruction works, how it differs from antivirus and sandboxing, where it fits within a modern security architecture and what to look for when evaluating a CDR solution.

The problem CDR was built to solve

Detection-based security depends on recognising malicious content or observing suspicious behaviour.

Modern malware is designed to evade detection. Zero-day exploits target newly discovered vulnerabilities before any signature exists. Payloads delay execution to avoid sandbox analysis. File structures are deliberately manipulated to bypass security controls.

Detection technologies become less effective when the attack itself is unknown. Zero-day exploits, by definition, have no existing signatures or behavioral history to identify them.

This is the challenge Content Disarm and Reconstruction was designed to address.

How Content Disarm and Reconstruction works

Glasswall processes every incoming file using a structured workflow that validates the file, rebuilds it where necessary and removes risky content according to policy. Each stage is performed independently before the rebuilt file is delivered to the user.

  1. Inspect
    The file is broken down into its constituent components and validated against its published file format specification. This verifies that the file is structurally sound and identifies any components that don't conform to the expected format.
  2. Rebuild
    Non-conforming file structures are rebuilt in line with the file specification, producing a structurally valid version of the original document.
  3. Clean
    Configurable security policies determine how potentially risky content is handled. Depending on policy, active content such as macros, embedded objects, scripts and other high-risk elements can be removed before the file is delivered.
  4. Deliver
    The rebuilt file undergoes final integrity checks before being delivered. Users receive a clean, visually identical file that preserves business usability, while detailed reporting provides full visibility into the actions taken during processing.

Why CDR succeeds where detection struggles

The difference becomes clear when attackers try to evade security controls.

Malware can be modified to avoid signatures. Payloads can delay execution to outlast sandbox analysis. Attack chains can also be designed to suppress the behaviors detection tools expect to see.

CDR does not depend on any of those signals. It validates the file structure, applies policy to potentially risky content and rebuilds the file before delivery. That means macros, scripts, embedded objects and other active content can be removed or controlled whether or not they have been identified as malicious.

This approach helps neutralize threats delivered through:

  • Microsoft Office documents  
  • PDF files  
  • Common image formats  
  • Compressed archives  
  • Embedded active content, including macros and scripts  
  • Malformed file structures designed to exploit vulnerabilities in document readers and other applications

CDR vs antivirus and sandboxing

Objective testing across 8.27 million malicious files highlights the difference in outcomes between detection-based security and Content Disarm and Reconstruction.

Sandboxing missed approximately 1 in 6 malicious files. Antivirus missed approximately 1 in 8. Glasswall CDR neutralized 100% of the tested malicious files.

The reason isn't that antivirus or sandboxing are ineffective technologies. They solve a different security problem.

  • Antivirus: Detect known malware using signatures, heuristics and threat intelligence.
  • Sandboxing: Execute files in an isolated environment and monitor for malicious behavior.
  • CDR: Validate file structure, remove unsafe content according to policy, and reconstruct a clean version of the file.

Rather than replacing antivirus or endpoint protection, CDR strengthens them by reducing the number of potentially dangerous files that ever reach downstream security controls.

Where CDR fits in your security stack

CDR works best at the point where files first enter the organization.

Typical deployment points include:


By reconstructing files before delivery, CDR reduces the attack surface presented to endpoint protection, Endpoint Detection and Response (EDR) and other detection technologies.

What to look for in a CDR solution

Not every CDR platform delivers the same level of protection. When evaluating vendors, consider the following.

  • File format coverage. Your CDR solution should support the file types your organization actually exchanges. Glasswall supports more than 75 business-critical file formats, including Microsoft Office documents, PDFs, image formats, compressed archives and many other commonly exchanged business files.
  • Reconstruction fidelity. The reconstructed file should remain fully usable while preserving its original format and appearance. Some CDR approaches rely on document sanitization through file flattening, converting everything to PDF, which may reduce risk but often breaks business workflows.
  • Processing performance. CDR must operate at enterprise scale. Glasswall's patented processing technology has demonstrated throughput of up to four million files per day, allowing organizations to deploy CDR at high-volume email gateways and web proxies without introducing unacceptable latency.
  • Deployment flexibility. Look for deployment options that match your environment, including cloud, on-premises, Kubernetes and highly secure or air-gapped environments.
  • Policy control. Different organizations have different risk tolerances. Granular policy controls allow administrators to determine how active content, embedded objects and other potentially unsafe elements are handled while maintaining business usability.

CDR and Zero Trust

Zero Trust is built on a simple principle: never trust, always verify.

That principle applies not only to users and devices, but increasingly to the data itself.

Files remain one of the most common delivery mechanisms for cyberattacks, making them a critical part of the Zero Trust data pillar.  

Content Disarm and Reconstruction extends Zero Trust to file handling by treating every incoming file as untrusted, regardless of its source.

Instead of relying on sender reputation or historical trust, every file is inspected, validated and reconstructed before entering the environment.

The result is a stronger Zero Trust architecture that reduces file-based risk without disrupting legitimate business workflows.

Frequently asked questions

What does CDR stand for in cybersecurity?

CDR stands for Content Disarm and Reconstruction. It is a cybersecurity technology that validates, reconstructs and safely delivers files by rebuilding them into trusted, known-good versions rather than attempting to detect malware. The process is sometimes referred to as file sanitization, though CDR specifically covers the full inspect-rebuild-clean-deliver workflow.

Is CDR better than antivirus?

They perform different roles. Antivirus detects known threats using signatures and behavioral analysis. CDR reconstructs files so malicious content cannot survive the rebuilding process. The strongest security architectures use both technologies together.

Is CDR better than sandboxing?

Sandboxing observes file behavior. CDR rebuilds files before behavior can occur. Because CDR doesn't rely on execution, it remains effective against many evasion techniques designed to bypass sandbox analysis.

What file types does Glasswall support?

Glasswall supports more than 75 business-critical file types, including Microsoft Office documents, PDFs, common image formats, compressed archives and many other enterprise file formats. Refer to the supported file types documentation for the complete list.

Prevention before detection

Detection will always have an important role in cybersecurity. But when it comes to files, there is another option: remove the risk before the file ever reaches a user.

That's the role of Content Disarm and Reconstruction.

By validating file structure against published specifications and rebuilding every file into a known-good version, CDR removes the structural conditions that file-based attacks depend upon, without relying on signatures, threat intelligence or behavioral analysis.

For organizations that regularly exchange files with external users, partners and suppliers, CDR provides an additional layer of assurance that detection technologies alone cannot deliver.

Glasswall Content Disarm and Reconstruction technology rebuilds files against manufacturer specifications, removing the structural conditions that allow any file-based threat to execute. Book a demo to see it in action.

See what Zero Trust file protection looks like. Live, in 25 minutes.

A tailored walkthrough of how Glasswall rebuilds files to a known-good state, removes hidden threats, and provides the intelligence you need to understand file risk.

What's in the demo

  • See malicious files rebuilt in real time
    Watch Glasswall remove hidden threats and return a safe, usable files.
  • Integrate security without disruption
    See how Glasswall fits into your existing workflows and infrastructure.
  • Gain complete visibility into file risk
    Uncover threats, anomalies and hidden file intelligence.

Beazley's security is paramount, and this integration has significantly reinforced our cybersecurity framework.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.