Home/Backup & Cyber Resilience

Backup answers “can I get it back.” Cyber recovery answers “can I get it back after someone deliberately destroyed the backups too.”

Most organisations own the first and assume they bought the second. Four routes below; each answers a different failure — and each is its own guide.

Acronis documents that its immutable storage is in governance mode by default — an administrator can disable it. Rubrik documents that its Retention Lock needs two authorised officers and Rubrik Support to remove. Both say “immutable”. One word, two purchases.

Backup & Recovery

Something was lost, corrupted or deleted. You need it back.

15 productsOpen the guide →
Often confused with Disaster Recovery. The difference: one restores data, the other restores operations. Disaster Recovery

SaaS Backup

Your data is in someone else's cloud, and they are not backing it up for you.

11 productsOpen the guide →
Often confused with Backup & Recovery. The difference: the vendor keeps the platform running; keeping your data is your job. Backup & Recovery

Disaster Recovery

The site is down. You need to run somewhere else, fast.

9 productsOpen the guide →
Often confused with Cyber Recovery. The difference: DR assumes the backup is trustworthy; cyber recovery assumes it isn't. Cyber Recovery

Cyber Recovery

An attacker got in and went for the backups first.

15 productsOpen the guide →
Often confused with Backup & Recovery. The difference: immutability is a property, not a product — and most buyers don't know which they have. Backup & Recovery
Second entry axis

Something just happened?

Events send people here more often than job descriptions. If one of these is your week, it already names your route.

A file share was deleted three weeks ago

Backup & Recovery

A leaver's mailbox is gone and legal wants it

SaaS Backup

The data centre flooded, or the cluster won't boot

Disaster Recovery

Ransomware — and the backup console is empty

Cyber Recovery

Your hypervisor is changing (VMware → AHV / Proxmox)

Backup & Recovery

The insurer asked how your backups are immutable

Cyber Recovery

The overlaps

Why people pick the wrong door

Nobody confuses the definitions. They confuse the pairs. Four overlaps, and the one question that settles each:

Backup & RecoveryvsDisaster Recovery

Do you need the data back, or the business back?

Buy backup when you needed DR and the restore takes two days over a 1 Gbps line while the business waits. Buy DR when you needed backup and you own a second site that faithfully replicated last week's deletion — with no copy from before it.

SaaS BackupvsBackup & Recovery

Who is responsible for this data — the platform, or you?

Assume the server backup covers Microsoft 365 and discover, at the point of loss, that Microsoft's shared-responsibility model made the data yours and the retention policy kept nothing. Buy SaaS backup for the data centre and you have bought the wrong engine entirely.

Cyber RecoveryvsDisaster Recovery

Is the copy you will restore from trustworthy?

Buy DR as the ransomware plan and the replica carries the encryption to the second site within its RPO — seconds, if you paid for the good tier. Buy cyber recovery when you needed DR and you have a locked copy and no fast place to run it.

Cyber RecoveryvsBackup & Recovery

Can an admin credential delete your backup?

Own a backup product that supports immutability, leave it in governance mode or on a bucket without object lock, and the attacker with the backup admin's password deletes the copies before encrypting. Buy a vault without a backup engine and you have a very safe empty bucket.

Compare any two terms

vs
ImmutableCyber Recovery

Cannot be modified or deleted inside retention — enforced by storage, a custodian, the platform, or a flag an admin can clear.

The Cyber Recovery boundary section →
Air-gappedCyber Recovery

Where the attacker's credentials and network cannot reach — logical (separate tenant) or physical (tape).

The Cyber Recovery boundary section →

The difference

Immutable says the copy cannot be modified or deleted inside its retention — enforced by storage, a custodian, the platform, or a flag an admin can clear. Air-gapped says the copy sits where the attacker's credentials and network cannot reach — logically (separate tenant) or physically (tape). A copy can be either, both, or — with a firewall rule and shared admin credentials — neither while claiming both.

The vocabulary — one line each

Sixteen terms, one line each. The depth lives in each route’s guide.

These are not tiers of the same product. They answer different failure modes — a tool that handles accidental deletion perfectly may be useless against deliberate destruction. Each route’s guide resolves only the four its buyer confuses.

  • Backupan independent copy on different storage, kept for a retention period, restorable to a point in time
  • Replicationa continuously updated second copy of a running system, ready to take over — copies corruption too
  • Snapshota point-in-time image on the same storage as the source — fast rollback, gone with the storage
  • Archivedata moved (not copied) to cheaper indexed storage for retention — the only copy, not a recovery mechanism
  • Recycle bin30–93 days of a user's own deletions — ended by an admin purge, an expired window or a deleted account
  • Native retentiona governance control that keeps content from destruction until a date — not point-in-time recovery
  • True SaaS backupan independent, scheduled copy outside the tenant, restorable in place
  • Shared responsibilitythe platform vendor keeps the service up; the data — backup, recovery — is contractually yours
  • RPOhow much data you lose — seconds (continuous), minutes (periodic), hours (from backups)
  • RTOhow long until users are working again — minutes with runbooks and a warm target, days by hand
  • HAkeeps a system up through a component failure, in the same place — does not survive the site
  • DRmoves the estate to another place after the place itself fails, from replicas or backups stood up in order
  • Immutablecannot be modified or deleted inside retention — enforced by storage, a custodian, the platform, or a flag an admin can clear
  • Air-gappedwhere the attacker's credentials and network cannot reach — logical (separate tenant) or physical (tape)
  • WORMwrite once, read many — one way storage enforces immutability, not a synonym for it
  • Cyber recoverylock the copy, isolate it, scan it, restore into a clean room — assumes the copy and the network are compromised
Ground truths

What holds whichever route you take

The restore is the product

Every product on every route copies data successfully every night. What you are buying is the day you need it back — at volume, over your network, from a copy that was not deleted or encrypted first. Rehearse the restore you will need, not the backup you have scheduled; if it has never been rehearsed, the RPO, the RTO and the immutability are all unknown.

Storage is not in the licence

Per workload, per TB front-end, per TB back-end, per user, per device — none of those numbers includes the storage the copies sit on, the second site, the vault, or the egress on the day. It is frequently larger than the licence. Every guide states storage apart from the licence on every pricing block, on purpose.

India changes three answers

RBI, SEBI CSCRF and IRDAI expect documented RPO/RTO, drill evidence and data in India for regulated entities; DPDP lands around May 2027. Residency is documented for Druva (Pune-built, AWS Mumbai), Commvault Cloud’s India SaaS regions, Acronis (Mumbai), Barracuda Cloud-to-Cloud (India DC) and Veeam Data Cloud (Central India) — on every shortlist where it is documented, flagged where it is not, and your own design where you run the storage.

Immutability is a property, not a product

Every backup product on these pages can be made immutable; almost none is by default; and the word covers four materially different guarantees — storage-enforced, vendor-controlled, platform-enforced, or a flag an administrator can clear. The question to ask of any product on any route is who can delete a backup inside its retention, and what it takes. The cyber-recovery guide tabulates the answer per SKU.

The copy is the small number. The restore, the storage and who can delete the copy are the purchase.
TechBag
Where it's heading

The seams are moving

Backup vendors are absorbing cyber recovery and security posture — the lock, the scan, the clean room, the threat hunt — and Veeam, Rubrik and Cohesity now describe themselves as data security or data resilience rather than backup. Security vendors are absorbing backup from the other side (Acronis, Barracuda, NinjaOne: one agent for protection and the copy). Buying two of these today often means buying one thing twice — or buying the brand instead of the guarantee.

What you used to buyWhat you buy now
Backup & recovery
the copy of record
SaaS backup
M365 / Google / Salesforce
Disaster recovery
run elsewhere, fast
Cyber recovery
the copy survives the attacker
One direction
Backup absorbing cyber recovery and posture
the backup vendor sells the lock, the scan and the clean room
VeeamRubrikCohesityCommvaultDruva
One direction
Security vendors absorbing backup
one agent for protection and the copy
AcronisBarracudaNinjaOne
One direction
'Data security', not 'backup'
the category renaming itself around the attacker
RubrikCohesityVeeamCommvault

Buy for the seam that is moving, not last year’s org chart — and buy the guarantee, not the brand.

Check what you already own

A large share of buyers in this category already hold a mechanism for part of the thing they are about to purchase — and a larger share hold something that is called backup and is not.

  • Hypervisor-native snapshots roll back an hour; live on the same storage as the VM and die with it. Not a backup, not retention, not DR.
  • Storage-array replication a faithful second copy of the LUNs — including last week's deletion and tonight's encryption. A DR mechanism, not a backup, and only if the array is elsewhere.
  • Microsoft 365 retention policies a governance control, not a recovery control. They are not backup — Microsoft's own Service Agreement recommends third-party backup; Microsoft 365 Backup ($0.15 per GB / month) is.
  • Your cloud provider's backup service AWS Backup, Azure Backup — real backup for their own cloud, with vault lock / immutable vault. Nothing for the data centre or the other cloud.
  • Backup bundled into the RMM you run NinjaOne Backup, Acronis through your MSP — protects the devices the agent sits on, not the hypervisor, the database or the NAS.
  • Your backup product's immutability setting supported almost everywhere; enabled in far fewer places; in compliance mode in fewer still. Log in as the backup admin and try to delete yesterday's copy.

If the half you need is already on your invoice, we say so. It costs us a sale and saves you one.

Budget shape

What it costs, roughly

Four meters live in this category — and a fifth, storage, under all of them. Which one you are quoted tells you which route you are in; order of magnitude here, the tier- and term-matched USD + INR number is each guide’s job.

Backup & Recovery
Per workload · per TB · per socket
Veeam ~$250–450 per workload / yr; Commvault SaaS $58.50–90 per TB / mo; Cohesity ~$150–400 and NetBackup ~$400–900 per TB / yr; Rubrik ~$130 per back-end TB / mo; Barracuda Vx $599 per socket. Storage apart.
SaaS Backup
Per user per month
Commvault $1.70–4.50; Veeam $2.63–3.50; Barracuda $3.40 (unlimited, Entra ID); Druva ~$3; AvePoint ~$2–3.50; Rubrik ~$3.80 + storage; Microsoft 365 Backup $0.15 per GB.
Disaster Recovery
The licence, then the target
Veeam Advanced / Premium ~$350–450 per workload; Druva DRaaS per VM / mo; Acronis in compute points — and a warm second site or cloud target at roughly $70 per VM / mo indicative, which is the real bill.
Cyber Recovery
Per TB in the vault
Veeam Vault $14 / $24 per TB / mo (the only published list); FortKnox ~$150–300 per TB / yr reported; Rubrik ~$130 per back-end TB / mo; the clean room and the responders metered apart.
Appendix — every vendor in the category, tagged by route
  • VeeamData Platform (VUL per workload; CDP, Recovery Orchestrator, Premium scanners + Coveware), Kasten, public cloud, Data Cloud for Microsoft 365 (Central India), Salesforce, Data Cloud Vault ($14/$24 per TB, India Central)BackupSaaSDRCyber
  • CommvaultCloud Backup & Recovery (SaaS list $58.50–90 per TB / mo; India), Clumio (AWS), SaaS backup (M365 from $1.70), AD & Entra ID, Disaster Recovery, Cloud Rewind, Air Gap Protect, Cleanroom Recovery, ThreatWiseBackupSaaSDRCyber
  • CohesityDataProtect (DataLock, anomaly detection, CyberScan; SiteContinuity DR), NetBackup + resiliency, FortKnox cyber vault, Veritas Alta Recovery Vault, M365 (per user or per TB), GaiaBackupSaaSDRCyber
  • RubrikSecurity Cloud Enterprise Edition (append-only, two-person Retention Lock, monitoring, threat hunting, isolated recovery, orchestrated application recovery; ~$130 per back-end TB / mo), Cloud Vault, Microsoft 365, Identity ResilienceBackupSaaSDRCyber
  • DruvaSaaS-only, Pune-built, AWS Mumbai: Hybrid Workloads, Cloud Workloads, Endpoints, SaaS Apps (M365 / Google / Salesforce), DRaaS into AWS, Cyber Resilience (Data Lock, Curated Recovery)BackupSaaSDRCyber
  • AcronisCyber Protect Cloud (backup + security, one agent, via MSPs, Mumbai DC; M365 / Google backup; Disaster Recovery; immutable storage — governance default, compliance optional), Cyber Protect on-premBackupSaaSDRCyber
  • BarracudaBackup appliances / Vx ($599 per socket), cloud replication ($799 per TB), LiveBoot; Cloud-to-Cloud Backup for M365 ($3.40 per user, Entra ID, India DC)BackupSaaSDRCyber
  • NinjaOneBackup as an RMM add-on — devices and servers, S3 Object Lock in the Ninja cloud (mode is a choice)BackupCyber
  • AvePointCloud Backup — the widest SaaS list (M365, Entra ID, Dynamics, Power Platform, Google Workspace, Salesforce, Azure), unlimited storageSaaS
  • MicrosoftMicrosoft 365 Backup — native, $0.15 per GB / month, inside the tenant; AWS Backup and Azure Backup with vault lock / immutable vault for their own cloudsSaaSCyber

Five vendors span three or four routes; every product on the guides is mapped by SKU, not by vendor. Zerto (HPE), Veritas NetBackup appliances, Keepit and Dell PowerProtect Cyber Recovery are named in the guides where relevant but have no TechBag intel pages yet, so they are not ranked. Seqrite sells no backup product and is not on this category.

Know your route and want it narrowed to a shortlist? That’s the next page’s job — or ours.

Talk to an advisor

Vendor-neutral · no gated content