Ransomware operators target backups first. If your backup can be deleted by an admin credential, it is not a recovery plan.

Cyber recovery is four questions the backup product never asked: can anyone with admin rights delete or shorten the copy; is the copy somewhere the attacker’s credentials cannot reach; will you know the data was encrypted before you restore it; and do you have somewhere clean to restore into. Vendors describe materially different answers with the same word.

Acronis documents that its immutable storage is in governance mode by default — an administrator can disable it, with a 14-day grace — and that compliance mode cannot be disabled by anyone, including Acronis support. Rubrik documents that Retention Lock can be removed only by Rubrik Support with two authorised customer officers. Both say “immutable”.

Already decided — before the word immutable

Your backup productdecides which vaults and locks you can use
Your regulator and insurerdecide whether a clean room and evidence are required
Who holds admin on the backup serveris the attacker's first target

Still yours to weigh

Implementationobject lock · vendor-controlled · append-only · software flag
Who can lift itnobody · two people · an admin
Clean roomsomewhere to restore into
If you’ve never bought one

What cyber recovery actually is — and why backup was not it

A modern ransomware operator spends days inside the estate before encrypting anything. In those days they find the backup server, its console and its credentials — and delete, shorten or encrypt the backups first, so that the ransom is the only way back. Cyber recovery is the set of controls that survive that: a copy nobody with admin rights can remove inside its retention; an isolation the attacker’s credentials cannot cross; detection that the data in the backups was already encrypted or infected; and somewhere clean to restore into, because the production network is still theirs.

Two things are true at once. Every backup product on the backup guide can be made immutable — and almost none is, by default. And “immutable” covers four materially different guarantees — hardware WORM or object lock in compliance mode (the storage refuses), vendor-controlled (a custodian you cannot reach refuses), software-enforced on the platform (the product refuses, with quorum), and a software flag an administrator can clear (governance mode). The DR guide assumes the copy is trustworthy; this page assumes it is not. Prevention — the endpoint and the backup server’s own EDR — is the endpoint-protection guide.

The most common mis-purchase

“Immutable” that a domain administrator can override — because the product supported compliance mode and the default was governance, or the bucket was created without object lock, or the hardened repository’s console was reachable with the same credentials as everything else. Support is not a default. Ask who can delete a backup, and what it takes.

Often confused withBackup & Recovery — the copy; this page is whether the copy survives the attacker·Disaster Recovery — assumes the copy is trustworthy; replication copies the encryption·Endpoint Protection — where the encryption is seen first, and what protects the backup server itself

The four routes of backup and cyber resilience — and which one is yours

Boundary — the terms this buyer confuses

Immutable vs air-gapped vs WORM · cyber recovery vs DR

Three words vendors use interchangeably, and one pair of disciplines buyers merge. None of these is a tier. They answer different failure modes, and a tool that handles one perfectly may be useless against another.

Immutable

The copy cannot be modified or deleted inside its retention. The question is who enforces that: the storage (object lock in compliance mode, hardware WORM — the strongest), a custodian you cannot reach (vendor-operated vaults), the backup platform itself (append-only filesystems, DataLock with quorum), or a software flag (governance mode — an administrator can clear it). Same word, four guarantees.

Air-gapped

The copy sits where the attacker's credentials and network cannot reach. Logical: a separate tenant, separate credentials, no path from production (every vault here). Physical: offline — tape, a rotated drive, a powered-down system (Veeam and the base backup products document tape). A firewall rule between two systems that share an admin is marketing.

WORM

Write once, read many: the storage medium or service refuses overwrites and deletes for a period, at the hardware or object layer — tape WORM, object lock, appliance WORM modes. WORM is one implementation of immutability, not a synonym; software immutability without WORM underneath is as strong as the software's admin model.

Cyber recovery vs DR

Disaster recovery assumes the backup or replica is trustworthy and optimises for speed — and replicates the encryption within its RPO. Cyber recovery assumes the copy, the network and the credentials may all be compromised: lock the copy, isolate it, scan it, restore into a clean room. Different rehearsals, different products, often the same vendor.

These are not tiers of the same product. Immutable says the copy cannot change; air-gapped says it cannot be reached; WORM says how the storage enforces it; DR says how fast you come back if all three were unnecessary. An estate with perfect DR and governance-mode immutability handles a flooded data centre perfectly and is useless against a patient attacker with the backup admin’s password.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Seven variables decide this purchase. The instrument tests the ones documentation establishes (who can lift the lock, custodian, detection, scanning, clean room, delivery form, India); air gap type, retention-lock duration and recovery time from the immutable copy are prose because the honest answers are a configuration and a rehearsal.

01

Immutability implementation

Hardware WORM or object lock in compliance mode (the storage refuses); vendor-controlled (a custodian you cannot reach); software-enforced on the platform (append-only filesystem, DataLock with quorum); or a software flag an administrator can clear (governance mode). Vendors describe all four identically. The depth section tabulates which is which, from documentation.

02

Air gap: logical, physical, or marketing

Separate credentials and tenant (logical — every vault here); offline or tape (physical — documented at Veeam and the base backup products); a firewall rule between systems sharing an admin (marketing).

03

Anomaly and encryption detection in the backup itself

Does this SKU notice that last night's backup is 40% encrypted, or that a decoy was touched — or is detection another product? Separated from storage in the instrument, on purpose.

04

Clean-room recovery capability

An isolated environment to restore into while production is still the attacker's — documented at Commvault (Cleanroom Recovery), Rubrik (isolated recovery environments) and Veeam (Recovery Orchestrator clean room).

05

Who can delete a backup, and what it takes

Nobody inside retention; two officers and the vendor; quorum and MFA; an administrator by design; not established. The single most important line on this page.

06

Retention-lock duration

Configurable everywhere; who can shorten it is the question above.

07

Recovery time from the immutable copy versus a normal one

A vault in another tenant restores across a network — slower by design. Measured in the rehearsal or unknown.

The narrowing instrument · the reasoning is the product

Narrow 15 products to your shortlist

Set what is true for you. Products that fail a constraint fade with the reason on them; products whose behaviour is not established from documentation are marked unknown and stay. Every chip is reversible — and nothing here is eliminated on marketing copy.

Where you recover to

What it detects

Who can lift the lock

How it is delivered

India

Estate size

Air-gap type, retention-lock duration and restore time from the vault are in the notes below, not chips — the first is a configuration, the second is the lock question asked differently, the third is a rehearsal figure.

Still in15/ 15
Veeam logo

per workload (VUL) / year reported for Premium; immutability is the hardened Linux repository (immutable attribute, single-use credentials) or object lock in the mode you choose; tape for an offline copy; Coveware incident-response retainer separate

Veeam estates that want the ransomware layer on the licence they run: inline malware detection, Recon Scanner for the backup infrastructure, YARA scanning before restore, clean-room orchestration and Coveware's responders on retainer.

The catch: Immutability is your build — a hardened repository an attacker with root and console access can still reach, or object lock whose mode (compliance vs governance) you chose; nothing is immutable by default; Premium-tier pricing on quote.

Your repositorySecure restore (YARA)Coveware retainer
Intel page →
Veeam logo
$14 · $24₹1,162

per TB / month list (Foundation locally redundant · Advanced zone-redundant, unlimited restore); always-on immutability in Veeam-managed Azure storage; India Central region

Veeam estates that want the off-site immutable copy to exist without building one — a fixed per-TB price, no egress surprises on the Advanced tier, and nothing to harden.

The catch: Storage only — detection, scanning and the restore engine are the Veeam licence; Veeam's own product only; the Foundation tier meters restores.

Always immutableIndia CentralFlat per TB
Intel page →
Commvault logo

per TB / month on quote, or included with Commvault Cloud SaaS plans; Commvault-managed immutable storage on Azure, AWS or OCI, isolated from your tenant; India via Commvault's SaaS regions

Commvault estates that want the isolated immutable copy managed for them — no storage account, no credentials, no bucket policy to get wrong.

The catch: Storage only and Commvault only; detection (Threat Scan, ThreatWise) and the clean room are separate SKUs; per-TB quote.

Vendor-managedIsolated tenantCommvault only
Intel page →
Commvault logo

per protected workload on quote; an on-demand isolated Azure environment, built clean, for recovery testing, forensics and production failover — from Air Gap Protect copies

Regulated and insured estates that must prove recovery works: a clean room stood up on demand, tested on a schedule, with evidence — without keeping a second data centre idle.

The catch: Commvault copies only; the cleanroom's Azure region for Indian buyers is not documented; compute for tests and for a real recovery is metered apart.

On-demand clean roomScheduled testsAzure
Intel page →
Commvault logo

per sensor / environment on quote; deception decoys that look like production and backup assets, firing before encryption starts

Estates that want early warning inside the network — attackers touching a decoy backup server or share before they reach the real ones.

The catch: Detection, not storage and not recovery — it holds nothing immutable; Commvault-sold, though decoys are vendor-neutral; quote-only.

DeceptionEarly warningNot storage
Intel page →
Cohesity logo

per TB / year reported (licence); DataLock WORM on the SpanFS filesystem with quorum / MFA for privileged change; ML anomaly detection and CyberScan on the backups

Cohesity estates that want the appliance's own storage to be the immutable copy, with detection and scanning built into the platform and FortKnox as the off-site vault.

The catch: Software-enforced on the platform you operate — strong (quorum, MFA, WORM on the filesystem) but not a separate custodian; an India region for the BaaS form is not documented.

DataLock WORMAnomaly + CyberScanQuorum
Intel page →
Cohesity logo
~$150–300+₹12,450

per TB / year reported; SaaS cyber vault on AWS S3 Object Lock or Azure immutable storage (irrevocable DataLock), Cohesity-operated, virtual air gap with a transfer window; recovery to the source cluster or an alternate location

Cohesity estates that want a second, vendor-operated immutable copy outside their tenant with a documented clean-recovery path to an alternate cluster or cloud.

The catch: Cohesity only; storage and recovery path, not detection (that is DataProtect); India region not documented; quote-priced per TB.

Object Lock, irrevocableVendor-operatedAlternate-site recovery
Intel page →
Cohesity logo

per TB / month on quote; Veritas-managed immutable cloud storage for NetBackup, isolated from the NetBackup domain

NetBackup estates that want the immutable off-site copy operated for them rather than built on their own object storage.

The catch: NetBackup only; storage, not detection; India region not documented; quote-only.

For NetBackupVendor-managedQuote
Intel page →
Rubrik logo

per back-end TB / month reported on three-year terms; append-only filesystem by design, Retention Lock removable only by Rubrik Support with two authorised customer officers; anomaly detection, threat monitoring, quarantine of infected snapshots, isolated recovery environments

Enterprises that want backup and cyber recovery to be one posture — the storage cannot be written over, the lock needs two people and the vendor, the snapshots are scanned, and the recovery can be rehearsed in an isolated environment.

The catch: The most expensive meter on this page on three-year terms; the platform is the custodian (strong, but one vendor for data and lock); India region not documented.

Append-onlyTwo-person Retention LockIsolated recovery
Intel page →
Rubrik logo

per TB on quote; Rubrik-hosted immutable storage in Azure, isolated from your tenant, under the same Retention Lock rules

Rubrik estates that want the off-site immutable copy hosted by Rubrik with no storage account of their own to protect.

The catch: Rubrik only; storage, not detection; India region not documented; quote-only.

Rubrik-hostedAzureQuote
Intel page →
Rubrik logo
In Enterprise Edition

part of Rubrik Security Cloud Enterprise Edition; IOC / YARA hunts across the backup history to find the last clean snapshot and the point of entry

Rubrik estates that need to answer 'which snapshot is clean, and since when' before restoring — without mounting and scanning each one by hand.

The catch: Scanning, not storage — it finds the clean point; the immutability is Enterprise Edition's; Rubrik data only.

IOC / YARA huntsLast clean snapshotRubrik data
Intel page →
Druva logo

included in or added to Druva's Enterprise / Elite plans; Druva-operated AWS with Data Lock that cannot be disabled once set, UEBA and unusual-activity detection, Curated Recovery building a clean restore point, quarantine and rollback actions; AWS Mumbai region

Druva estates — SaaS-only, no storage of their own — that want the air gap, the lock, the detection and the clean restore point as a service in India.

The catch: Druva-protected data only; no isolated clean-room environment as a product (recovery is into your environment or DRaaS); plan-tier pricing rather than a list.

SaaS air gapCurated RecoveryMumbai region
Intel page →
Acronis logo

Acronis Cloud storage per GB plus the per-workload licence, through MSPs; immutable storage in governance mode by default (an admin can disable it, 14-day grace) or compliance mode (nobody, including Acronis support); Safe Recovery scans backups; Mumbai data centre

MSP-run estates that want backup, anti-malware and an immutable cloud copy under one agent and one partner, in India — with the lock mode chosen deliberately.

The catch: Governance mode is the default: until compliance mode is switched on, an administrator can lift the immutability; partner pricing; enterprise scale is not where it is documented.

Governance by defaultSafe Recovery scanMumbai DC
Intel page →
Barracuda logo

per TB / year list for replication to Barracuda Cloud; cloud copies written once and not modifiable through the appliance or API; local appliance copies are not the immutable ones

Barracuda appliance sites that want the off-site copy to be the one an attacker on the appliance cannot reach.

The catch: Who can delete a cloud copy inside retention, and through what process, is not established from documentation — marked unknown; local copies are mutable; no detection or scanning.

Cloud copies onlyLift: unknownFlat per TB
Intel page →
NinjaOne logo

per device / month on top of the RMM plus Ninja cloud storage; AWS S3 Object Lock in governance or compliance mode; cloud copy only — the local copy is not locked

NinjaOne RMM estates that want the endpoint and server backups' cloud copy locked at the storage layer, from the console they already run.

The catch: Devices and servers only (no hypervisor-level VMs); the lock mode is a choice — governance can be lifted by the tenant for a period; no detection or scanning; India region not documented.

Object Lock (mode is a choice)Cloud copy onlyRMM add-on
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

An isolated clean roomRules out Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud ThreatWise, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Rubrik Threat Hunting, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud — recovery is into your environment or an alternate site; no isolated recovery environment documented for this SKU. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud Cleanroom Recovery and Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery).

Detects anomalies itselfRules out Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Rubrik Threat Hunting, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud — storage or recovery only; detection comes from another product. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud ThreatWise, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Druva Cyber Resilience — Accelerated Ransomware Recovery and Acronis Cyber Protect Cloud — immutable storage + Advanced Security.

Clean restore pointRules out Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud ThreatWise, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud — no documented malware / IOC scan of the backup data. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud Cleanroom Recovery, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Rubrik Threat Hunting, Druva Cyber Resilience — Accelerated Ransomware Recovery and Acronis Cyber Protect Cloud — immutable storage + Advanced Security.

No single admin can lift itRules out Commvault Cloud ThreatWise and Rubrik Threat Hunting — a detection or scanning product, not a storage mechanism. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Rubrik Cloud Vault, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud. It flags Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware — Depends on the mode you chose, Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Depends on the mode you chose, Barracuda Backup — immutable cloud copies — Who can delete inside retention is not established from documentation and NinjaOne Backup — S3 Object Lock in the Ninja cloud — Depends on the mode you chose — marked on the cards, not removed.

A vendor-operated custodianRules out Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Cohesity DataProtect — DataLock, anomaly detection, CyberScan and Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) — immutability is enforced on storage you operate: your configuration, your credentials; Commvault Cloud ThreatWise and Rubrik Threat Hunting — a detection or scanning product, not a storage mechanism; NinjaOne Backup — S3 Object Lock in the Ninja cloud — object lock in the vendor's cloud but the mode and lifting are in your tenant's hands. That leaves Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security and Barracuda Backup — immutable cloud copies. It flags Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Acronis-operated storage; the mode (governance vs compliance) is set by your tenant — marked on the cards, not removed.

Vault as a serviceRules out Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud ThreatWise, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) and Rubrik Threat Hunting — enforced on a platform or repository you run. That leaves Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud.

Immutable copy in IndiaRules nothing out on published terms. It flags Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware — Your repository or bucket, Commvault Cloud Cleanroom Recovery — India region not documented for this service, Commvault Cloud ThreatWise — India region not documented for this service, Cohesity DataProtect — DataLock, anomaly detection, CyberScan — India region not documented for this service, Cohesity FortKnox — India region not documented for this service, Veritas Alta Recovery Vault (Cohesity) — India region not documented for this service, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) — India region not documented for this service, Rubrik Cloud Vault — India region not documented for this service, Rubrik Threat Hunting — India region not documented for this service, Barracuda Backup — immutable cloud copies — India region not documented for this service and NinjaOne Backup — S3 Object Lock in the Ninja cloud — India region not documented for this service — marked on the cards, not removed.

Petabyte-scale vaultsRules nothing out on published terms. It flags Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Unverified at petabyte scale, Barracuda Backup — immutable cloud copies — Unverified at petabyte scale and NinjaOne Backup — S3 Object Lock in the Ninja cloud — Unverified at petabyte scale — marked on the cards, not removed.

Air gap: logical, physical, or marketingEvery product here documents a logical air gap — separate credentials, separate tenant, no network path from production to the copy. A physical (offline) copy — tape, a rotated drive — is documented for Veeam Data Platform (and for Commvault's and NetBackup's base products, which are on the backup guide). A firewall rule between two systems that share an admin is not an air gap; a vendor-operated vault your tenant cannot reach with any credential is. Ask which one the word means in the proposal.

Retention-lock durationConfigurable everywhere (days to years); the question is who can shorten it. Nobody inside retention: Veeam Vault, Air Gap Protect, FortKnox, Alta Recovery Vault, Druva, Acronis in compliance mode. Two people and the vendor: Rubrik. Quorum and MFA: Cohesity DataLock. An administrator, by design: governance modes (Acronis default, NinjaOne's choice, object lock in governance on Veeam targets). Not established: Barracuda.

Recovery time from the immutable copyA vault in another tenant or cloud restores across a network — slower than the local copy, by design. FortKnox, Air Gap Protect, Veeam Vault, Alta and Rubrik Cloud Vault all document restore paths; what they do not document is your hours-per-TB over your line. Measure it in the rehearsal; TechBag's delivery figures per platform are [TechBag to confirm].

Detection is a different product from storageCommvault sells the vault (Air Gap Protect), the early warning (ThreatWise) and the clean room as three SKUs; Rubrik folds monitoring, hunting and isolated recovery into Enterprise Edition and sells the vault apart; Veeam puts detection in Premium and the vault in Data Cloud; Cohesity puts detection in DataProtect and the vault in FortKnox; Druva and Acronis bundle most of it into a plan. The instrument's chips separate them so a vault is never mistaken for a scanner.

Prevention belongs next doorThe backups are the last line; the endpoint is the first. Which EDR the estate runs decides how early the encryption is seen and whether the backup server itself is protected — the endpoint-protection guide. Veeam's Recon Scanner and Commvault's ThreatWise are the two products here that look at the estate before the encryption reaches the backups.

Narrow to your situation

Eight situations, eight shortlists — with the lock named

Each shortlist names who can lift the lock in that estate and where the clean restore would happen. Start from the row that names your backup product — the vault decision was made when that decision was.

Veeam estate — make the backups survive the attacker

Why: Premium adds the scanning, the secure restore and Coveware's responders on the licence already running; Veeam Vault gives the off-site copy that is immutable by default instead of by your build.

The trade-off: Until the vault or a compliance-mode object-lock target exists, a hardened repository is as strong as its console access — test it as the attacker would.

Commvault estate — vault, warning and a room to recover in

Why: Air Gap Protect is the managed immutable copy, ThreatWise fires before encryption reaches it, Cleanroom Recovery stands up an isolated environment to prove the restore — three SKUs that read as one programme.

The trade-off: Three quotes; the cleanroom's Azure region for Indian buyers is not documented — ask.

A vault as a service — no storage of ours to protect

Why: Five vendor-operated vaults, each for its own backup product: Veeam Vault (published $14 / $24 per TB per month, India Central), Air Gap Protect, FortKnox (S3 Object Lock, irrevocable), Rubrik Cloud Vault, Alta Recovery Vault for NetBackup.

The trade-off: Each vault is tied to its vendor's backup product — the vault decision is made when the backup decision is; only Veeam publishes the per-TB price.

The insurer or regulator wants a clean room and evidence

Why: Commvault's on-demand cleanroom with scheduled tests, Rubrik's isolated recovery environments with threat hunting, and Veeam's Recovery Orchestrator clean-room flow with YARA scanning — the three documented isolated-recovery paths here.

The trade-off: Clean-room compute is metered on the day and for every test; the evidence is only as good as the last scheduled rehearsal.

SaaS-only estate, India, nothing to build

Why: Druva's Data Lock cannot be disabled once set and its Curated Recovery builds the clean restore point from the AWS Mumbai region; Acronis offers immutable storage and Safe Recovery from its Mumbai data centre through an MSP.

The trade-off: Acronis is governance mode until compliance mode is switched on — make the switch part of the onboarding, in writing.

Rubrik posture — data, lock, hunt and recovery from one vendor

Why: Append-only storage, a Retention Lock that needs two officers and Rubrik Support, monitoring, threat hunting across snapshots, and isolated recovery — with Cloud Vault as the hosted copy.

The trade-off: One custodian for the data and the lock, on the page's most expensive meter and three-year terms.

SMB through an MSP or RMM — lock the cloud copy

Why: Acronis and NinjaOne lock the cloud copy with object lock in a mode you choose; Barracuda's cloud copies are written once and unreachable from the appliance.

The trade-off: Modes default to governance (Acronis) or are a choice (NinjaOne); Barracuda's deletion process inside retention is not documented — three flags, not three eliminations.

Cohesity estate — platform lock plus a separate vault

Why: DataLock on the appliance with quorum and MFA, anomaly detection and CyberScan on the platform; FortKnox as the vendor-operated, irrevocably locked second copy with an alternate-site recovery path.

The trade-off: Two Cohesity SKUs, two per-TB quotes; neither documents an India region for the service form.

The spine of the decision — from documentation, not brochures

Four implementations of one word, and who can undo each

Every product on this page says “immutable”. This is where each one’s technical documentation puts it. Products whose mechanism could not be established are listed as unknown, not placed by guess.

Implementation A

Storage-enforced: object lock (compliance) or hardware WORM

The storage layer refuses deletes and overwrites until the retain-until date — no credential in your tenant or the vendor's changes that. FortKnox (S3 Object Lock / Azure immutable, irrevocable). Acronis and NinjaOne use object lock too, but the mode is chosen by the tenant — compliance is this row; governance is row D.

Implementation B

Vendor-controlled: a custodian you cannot reach

The vendor operates the storage in its own tenant; you hold no credential that can delete inside retention. Veeam Vault (always-on), Air Gap Protect, Alta Recovery Vault, Rubrik Cloud Vault (under Retention Lock), Druva (Data Lock cannot be disabled). Barracuda's cloud copies are written once — who can delete inside retention is not documented.

Implementation C

Software-enforced on the platform you run

The backup platform's own storage refuses change by design — Rubrik's append-only filesystem with Retention Lock (two officers plus Rubrik Support to remove), Cohesity DataLock WORM on SpanFS with quorum and MFA. Strong; one custodian for the data and the lock; as reachable as the appliance.

Implementation D

Your build, or a flag an admin can clear

Veeam's hardened repository (Linux immutable attribute, single-use credentials — an attacker with root and console access can still reach it) or object lock on a target you configured, in the mode you chose. Governance mode anywhere (Acronis by default, NinjaOne as a choice, Veeam targets in governance) is a software flag an administrator can lift.

Who can delete a backup, and what it takes

The single most important line, per product — from documentation.

  • Nobody inside retention: Veeam Data Cloud Vault; Commvault Air Gap Protect and Cleanroom copies; Cohesity FortKnox (irrevocable DataLock); Veritas Alta Recovery Vault; Druva (Data Lock cannot be disabled once set); Acronis in compliance mode (not even Acronis support).
  • Two people and the vendor: Rubrik — Retention Lock removed only by Rubrik Support with two previously authorised customer officers (Enterprise Edition and Cloud Vault). Quorum and MFA: Cohesity DataLock on the platform.
  • Depends on the mode you chose: Veeam hardened repository / object-lock targets; Acronis by default (governance: an administrator can disable it, 14-day grace); NinjaOne (governance or compliance, your choice).
  • Not established: Barracuda cloud copies — written once and unreachable from the appliance or API; the deletion process inside retention is not documented. Not a storage product: ThreatWise, Rubrik Threat Hunting.

The ransomware-day test

Ask these before the word immutable, in this order.

  • Show me the documentation page that says who can delete inside retention. Not the datasheet. If it says “governance” or the answer is a role name, it is a flag.
  • With the backup administrator’s credentials, what can I reach? The repository console, the bucket policy, the vault tenant? The attacker will have them.
  • How will I know the copy is clean, and where will I restore it? Anomaly detection, a malware / IOC scan, and a clean room — three separate products at most vendors.
  • How long does a full restore from the vault take over my line? Rehearsed, or unknown.
What breaks as you grow

What changes at 10 TB, 100 TB and a petabyte

Cyber recovery scales by the size of the copy that must sit out of reach and by how long a restore from there takes. The bill follows the vault; the confidence follows the rehearsal.

10 TBTB in the immutable copy

The default is the constraint

  • Any vault here holds it; the risk is the default — governance mode, a bucket without object lock, a hardened repository on the same credentials as everything else.
  • Vendor-operated vaults (Veeam Vault at $14–24 per TB per month, Acronis, Druva) remove the configuration risk for a small estate at a visible price.
  • A restore from the vault is hours at this size; rehearse it once a year.

Put this in your PoC

Log in as the backup administrator and try to delete yesterday's copy. If you can, the attacker can.

100 TBTB in the immutable copy

The custodian and the scan are the constraint

  • The off-site immutable copy becomes a budget line of its own — object-storage rates times the retained TB — and the argument for a vendor-operated vault versus your own object lock is about who holds the keys, not the price.
  • Anomaly detection and a clean-restore-point scan stop being optional: restoring 100 TB of encrypted data is a week lost.
  • Restore time from the vault over your line is now a board number — measure it.

Put this in your PoC

Ask for the restore throughput from the vault for an estate your size, and for the documentation page on who can delete inside retention.

1 PBTB in the immutable copy

The clean room and the evidence are the constraint

  • Isolated recovery environments (Commvault Cleanroom, Rubrik, Veeam Orchestrator) and scheduled tests with evidence are what the insurer and the regulator read.
  • Two custodians — the platform's lock plus a vendor-operated vault — is the honest enterprise shape; Acronis, NinjaOne and Barracuda are flagged unverified here, not ruled out.
  • The rehearsal is a programme with an owner: last clean snapshot, restore order, clean room, evidence.

Put this in your PoC

Run a clean-room restore of the crown-jewel application from the vault and produce the evidence. Hours and findings are the slide.

Veeam, Commvault, Cohesity, Rubrik and Druva document petabyte estates; Acronis, NinjaOne and Barracuda are flagged unverified at that size. Where a specific vault or platform strains at your size: [TechBag to confirm].

The switching cost

Leaving a vault is a retention-tail project with no gap allowed

The copies in the vault are immutable by design — they will not move, and they will not be deleted early. Switching means the new immutable copy must exist before the old one stops being refreshed.

The locked tail

Copies in the old vault stay until their retention expires — you cannot shorten it (that was the point). Budget the old vault until the last lock lifts.

Exit costPay until the lock expires

No gap

The day the old product stops writing, the new product's immutable copy must already be current and tested. Overlap is not optional; it is the only honest plan.

Exit costOverlap, tested

Vendor-tied vaults

Veeam Vault, Air Gap Protect, FortKnox, Rubrik Cloud Vault and Alta are each for their own backup product; leaving the backup product leaves the vault.

Exit costVault follows the product

The rehearsal evidence

Clean-room test reports and scan histories live in the old platform; export what the insurer and regulator may ask for before the contract ends.

Exit costExport the evidence

Locked-tail cost, overlap and evidence export for your estate: [TechBag to confirm] — TechBag scopes it from your retention locks and vault sizes.

What it costs

Per TB in the vault — and then the day itself

What you may already hold, the vaults and platforms priced the way they are sold in USD and INR, and what the licence line leaves out — which, for cyber recovery, is the clean room on the day and the responders on the phone.

01

Do you already own one?

Four places immutability may already be within reach. Two of them are real if configured.

Object lock on the cloud storage you already use
Partly S3 Object Lock, Azure immutable blob and AWS Backup Vault Lock / Azure immutable vault are real, storage-enforced immutability — if the bucket or vault was created with it, in compliance mode, and the backup product supports it. The storage is cheap; the configuration is the product.
Your backup product's immutability setting
Often Veeam, Commvault, Cohesity, Rubrik, Acronis, NinjaOne and Barracuda all support it. Supported is not enabled; enabled is not compliance mode. Check which, today.
Tape or an offline copy
Partly A physical air gap nobody argues with — slow to restore, easy to neglect, and documented at Veeam and the base backup products. Honest for the last-resort copy, not the first.
Your EDR
No The endpoint product sees the encryption start and protects the backup server as a host; it holds no copy. Prevention next door, recovery here.

If the lock you need is a setting you already pay for, we say so — and then we check the mode with you. It costs us a sale and saves you one.

02

What the rest actually cost

Published and reported vault and platform meters (INR for scale), then worked at 10 / 100 / 1,000 TB in the immutable copy per year. Only Veeam publishes a vault list; the rest are reported or quoted. The clean room, the retainer and the rehearsal are stated apart, below.

10TB in the vault · per year
  • Veeam Data Cloud Vault(list $14 Foundation · $24 Advanced per TB / mo)$1,6802,880 ₹1,39,440₹2,39,040
  • Cohesity FortKnox(reported $150–300+ per TB / yr)$1,5003,000 ₹1,24,500₹2,49,000
  • Cohesity DataProtect platform(reported $150–400 per TB / yr)$1,5004,000 ₹1,24,500₹3,32,000
  • Rubrik Enterprise Edition(reported ~$130 per back-end TB / mo, 3-year)$15,600 ₹12,94,800
  • Barracuda cloud replication(list $799 per TB / yr)$7,990 ₹6,63,170
  • Commvault Air Gap Protect(per TB)Quote
  • Commvault Cleanroom RecoveryQuote
  • Rubrik Cloud Vault(per TB)Quote
  • Veritas Alta Recovery VaultQuote
  • Druva Cyber Resilience(plan tier)Quote
  • Acronis immutable storage(per GB via MSP)Quote
100TB in the vault · per year
  • Veeam Data Cloud Vault(list $14 Foundation · $24 Advanced per TB / mo)$16,80028,800 ₹13,94,400₹23,90,400
  • Cohesity FortKnox(reported $150–300+ per TB / yr)$15,00030,000 ₹12,45,000₹24,90,000
  • Cohesity DataProtect platform(reported $150–400 per TB / yr)$15,00040,000 ₹12,45,000₹33,20,000
  • Rubrik Enterprise Edition(reported ~$130 per back-end TB / mo, 3-year)$1,56,000 ₹1,29,48,000
  • Barracuda cloud replication(list $799 per TB / yr)$79,900 ₹66,31,700
  • Commvault Air Gap Protect(per TB)Quote
  • Commvault Cleanroom RecoveryQuote
  • Rubrik Cloud Vault(per TB)Quote
  • Veritas Alta Recovery VaultQuote
  • Druva Cyber Resilience(plan tier)Quote
  • Acronis immutable storage(per GB via MSP)Quote
1,000TB in the vault · per year
  • Veeam Data Cloud Vault(list $14 Foundation · $24 Advanced per TB / mo)$1,68,0002,88,000 ₹1,39,44,000₹2,39,04,000
  • Cohesity FortKnox(reported $150–300+ per TB / yr)$1,50,0003,00,000 ₹1,24,50,000₹2,49,00,000
  • Cohesity DataProtect platform(reported $150–400 per TB / yr)$1,50,0004,00,000 ₹1,24,50,000₹3,32,00,000
  • Rubrik Enterprise Edition(reported ~$130 per back-end TB / mo, 3-year)$15,60,000 ₹12,94,80,000
  • Barracuda cloud replication(list $799 per TB / yr)$7,99,000 ₹6,63,17,000
  • Commvault Air Gap Protect(per TB)Quote
  • Commvault Cleanroom RecoveryQuote
  • Rubrik Cloud Vault(per TB)Quote
  • Veritas Alta Recovery VaultQuote
  • Druva Cyber Resilience(plan tier)Quote
  • Acronis immutable storage(per GB via MSP)Quote

Storage and the day — stated apart from the licence, on purpose

The vault is storage. The lines above are the immutable copy’s storage, not the backup licence that writes to it — that is the backup guide’s bill. Your own object lock costs the bucket (~$10–20 per TB per month at hyperscalers, ~$7 at S3-compatible providers) plus the configuration you must get right; a vendor-operated vault costs the custodian.
The clean room and the responders. Clean-room compute is metered for every test and for the real event (Commvault, Rubrik, Veeam Orchestrator flows); an incident-response retainer (Coveware by Veeam) is a separate contract. Price a fortnight of clean-room compute, not an hour.
Detection, separately. ThreatWise, Rubrik’s monitoring and hunting (in Enterprise Edition), Veeam Premium’s scanners, Cohesity’s CyberScan, Druva’s Curated Recovery — the scan that tells you which copy is clean is a product, a tier or a plan, not a feature of the vault.
Tier-match: governance is not compliance. Acronis governance is not Acronis compliance; Veeam Vault Foundation meters restores and Advanced does not; Veeam Premium has the scanners and Foundation does not; Rubrik Enterprise Edition has the hunting and monitoring. Price the mode and the tier that cannot be lifted.
Term-match: per TB per month, per TB per year, three-year. Veeam Vault per TB per month; FortKnox and Cohesity per TB per year reported; Rubrik per back-end TB per month on three-year terms; Acronis per GB through an MSP. The grid normalises to a year per TB; your quote will not.
The India line. Veeam Vault (India Central), Commvault’s India SaaS regions, Druva (Mumbai) and Acronis (Mumbai) document the region for the immutable copy; the rest is your design or not documented. Indian quotes arrive in USD and in INR with GST; TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The clean room on the day

Isolated compute for the duration of the recovery and for every scheduled test — metered, not licensed. A fortnight of production-size clean room is the number to model; most business cases model an hour.

The responders and the retainer

Coveware by Veeam sells an incident-response retainer with a 15-minute SLA; other vendors point to partners. Negotiation, forensics and the decision whether to pay are a separate contract — and a separate night.

The rehearsal

Finding the last clean snapshot, restoring the crown jewels into the clean room, producing the evidence — quarterly, with an owner. Tools automate the scan; the drill is yours. Your hours: [TechBag to confirm].

Before you commit

What goes wrong

Documented defaults and modes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover with the attacker still inside.

'Immutable' that a domain admin can override

Governance mode by default, a role that can shorten retention, a bucket created without object lock. The product supported compliance; nobody switched it on. Ask who can delete, and what it takes — from the documentation page.

Air gap that is a network rule, not an air gap

A firewall between the backup server and the repository, both administered with the same credentials. The attacker had those. A custodian you cannot reach, or an offline copy, is an air gap; a rule is a rule.

Restoring re-infected data because nobody scanned it

The last three weeks of backups carried the implant; the restore put it back. Anomaly detection and a malware / IOC scan of the backups are products — Veeam Premium, Rubrik, Cohesity, Druva, Acronis — not assumptions.

No clean room to restore into

The copy was clean; the network it was restored into was still the attacker's. Commvault, Rubrik and Veeam document isolated recovery environments; the rest is your design.

Discovering during an incident that immutability was never enabled

The renewal said immutable; the configuration said supported. The first check in any engagement is to log in as the backup admin and try to delete yesterday's copy.

The vault priced, the day not

Per-TB storage was in the budget; a fortnight of clean-room compute, the responders' retainer and the egress were not. Price the event.

Replication trusted as the plan

The DR replica carried the encryption within seconds. DR assumes the copy is trustworthy; this page is for when it is not.

One custodian for data and lock, unexamined

Platform-enforced locks (append-only, DataLock) are strong and still one vendor, one appliance, one console. For the crown jewels, a second custodian — a vendor-operated vault or tape — is the honest shape.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Backup & Cyber Resilience map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.