Endpoint Management
Backup & Cyber Resilience
Identity & Access
Network Security & SASE
Cyber recovery is four questions the backup product never asked: can anyone with admin rights delete or shorten the copy; is the copy somewhere the attacker’s credentials cannot reach; will you know the data was encrypted before you restore it; and do you have somewhere clean to restore into. Vendors describe materially different answers with the same word.
Acronis documents that its immutable storage is in governance mode by default — an administrator can disable it, with a 14-day grace — and that compliance mode cannot be disabled by anyone, including Acronis support. Rubrik documents that Retention Lock can be removed only by Rubrik Support with two authorised customer officers. Both say “immutable”.
Already decided — before the word immutable
Still yours to weigh
A modern ransomware operator spends days inside the estate before encrypting anything. In those days they find the backup server, its console and its credentials — and delete, shorten or encrypt the backups first, so that the ransom is the only way back. Cyber recovery is the set of controls that survive that: a copy nobody with admin rights can remove inside its retention; an isolation the attacker’s credentials cannot cross; detection that the data in the backups was already encrypted or infected; and somewhere clean to restore into, because the production network is still theirs.
Two things are true at once. Every backup product on the backup guide can be made immutable — and almost none is, by default. And “immutable” covers four materially different guarantees — hardware WORM or object lock in compliance mode (the storage refuses), vendor-controlled (a custodian you cannot reach refuses), software-enforced on the platform (the product refuses, with quorum), and a software flag an administrator can clear (governance mode). The DR guide assumes the copy is trustworthy; this page assumes it is not. Prevention — the endpoint and the backup server’s own EDR — is the endpoint-protection guide.
The most common mis-purchase
“Immutable” that a domain administrator can override — because the product supported compliance mode and the default was governance, or the bucket was created without object lock, or the hardened repository’s console was reachable with the same credentials as everything else. Support is not a default. Ask who can delete a backup, and what it takes.
Often confused withBackup & Recovery — the copy; this page is whether the copy survives the attacker →·Disaster Recovery — assumes the copy is trustworthy; replication copies the encryption →·Endpoint Protection — where the encryption is seen first, and what protects the backup server itself →
The four routes of backup and cyber resilience — and which one is yours →
Three words vendors use interchangeably, and one pair of disciplines buyers merge. None of these is a tier. They answer different failure modes, and a tool that handles one perfectly may be useless against another.
Immutable
The copy cannot be modified or deleted inside its retention. The question is who enforces that: the storage (object lock in compliance mode, hardware WORM — the strongest), a custodian you cannot reach (vendor-operated vaults), the backup platform itself (append-only filesystems, DataLock with quorum), or a software flag (governance mode — an administrator can clear it). Same word, four guarantees.
Air-gapped
The copy sits where the attacker's credentials and network cannot reach. Logical: a separate tenant, separate credentials, no path from production (every vault here). Physical: offline — tape, a rotated drive, a powered-down system (Veeam and the base backup products document tape). A firewall rule between two systems that share an admin is marketing.
WORM
Write once, read many: the storage medium or service refuses overwrites and deletes for a period, at the hardware or object layer — tape WORM, object lock, appliance WORM modes. WORM is one implementation of immutability, not a synonym; software immutability without WORM underneath is as strong as the software's admin model.
Cyber recovery vs DR
Disaster recovery assumes the backup or replica is trustworthy and optimises for speed — and replicates the encryption within its RPO. Cyber recovery assumes the copy, the network and the credentials may all be compromised: lock the copy, isolate it, scan it, restore into a clean room. Different rehearsals, different products, often the same vendor.
Seven variables decide this purchase. The instrument tests the ones documentation establishes (who can lift the lock, custodian, detection, scanning, clean room, delivery form, India); air gap type, retention-lock duration and recovery time from the immutable copy are prose because the honest answers are a configuration and a rehearsal.
Immutability implementation
Hardware WORM or object lock in compliance mode (the storage refuses); vendor-controlled (a custodian you cannot reach); software-enforced on the platform (append-only filesystem, DataLock with quorum); or a software flag an administrator can clear (governance mode). Vendors describe all four identically. The depth section tabulates which is which, from documentation.
Air gap: logical, physical, or marketing
Separate credentials and tenant (logical — every vault here); offline or tape (physical — documented at Veeam and the base backup products); a firewall rule between systems sharing an admin (marketing).
Anomaly and encryption detection in the backup itself
Does this SKU notice that last night's backup is 40% encrypted, or that a decoy was touched — or is detection another product? Separated from storage in the instrument, on purpose.
Clean-room recovery capability
An isolated environment to restore into while production is still the attacker's — documented at Commvault (Cleanroom Recovery), Rubrik (isolated recovery environments) and Veeam (Recovery Orchestrator clean room).
Who can delete a backup, and what it takes
Nobody inside retention; two officers and the vendor; quorum and MFA; an administrator by design; not established. The single most important line on this page.
Retention-lock duration
Configurable everywhere; who can shorten it is the question above.
Recovery time from the immutable copy versus a normal one
A vault in another tenant restores across a network — slower by design. Measured in the rehearsal or unknown.
Set what is true for you. Products that fail a constraint fade with the reason on them; products whose behaviour is not established from documentation are marked unknown and stay. Every chip is reversible — and nothing here is eliminated on marketing copy.
Where you recover to
What it detects
Who can lift the lock
How it is delivered
India
Estate size
Air-gap type, retention-lock duration and restore time from the vault are in the notes below, not chips — the first is a configuration, the second is the lock question asked differently, the third is a rehearsal figure.

per workload (VUL) / year reported for Premium; immutability is the hardened Linux repository (immutable attribute, single-use credentials) or object lock in the mode you choose; tape for an offline copy; Coveware incident-response retainer separate
Veeam estates that want the ransomware layer on the licence they run: inline malware detection, Recon Scanner for the backup infrastructure, YARA scanning before restore, clean-room orchestration and Coveware's responders on retainer.
The catch: Immutability is your build — a hardened repository an attacker with root and console access can still reach, or object lock whose mode (compliance vs governance) you chose; nothing is immutable by default; Premium-tier pricing on quote.

per TB / month list (Foundation locally redundant · Advanced zone-redundant, unlimited restore); always-on immutability in Veeam-managed Azure storage; India Central region
Veeam estates that want the off-site immutable copy to exist without building one — a fixed per-TB price, no egress surprises on the Advanced tier, and nothing to harden.
The catch: Storage only — detection, scanning and the restore engine are the Veeam licence; Veeam's own product only; the Foundation tier meters restores.

per TB / month on quote, or included with Commvault Cloud SaaS plans; Commvault-managed immutable storage on Azure, AWS or OCI, isolated from your tenant; India via Commvault's SaaS regions
Commvault estates that want the isolated immutable copy managed for them — no storage account, no credentials, no bucket policy to get wrong.
The catch: Storage only and Commvault only; detection (Threat Scan, ThreatWise) and the clean room are separate SKUs; per-TB quote.

per protected workload on quote; an on-demand isolated Azure environment, built clean, for recovery testing, forensics and production failover — from Air Gap Protect copies
Regulated and insured estates that must prove recovery works: a clean room stood up on demand, tested on a schedule, with evidence — without keeping a second data centre idle.
The catch: Commvault copies only; the cleanroom's Azure region for Indian buyers is not documented; compute for tests and for a real recovery is metered apart.

per sensor / environment on quote; deception decoys that look like production and backup assets, firing before encryption starts
Estates that want early warning inside the network — attackers touching a decoy backup server or share before they reach the real ones.
The catch: Detection, not storage and not recovery — it holds nothing immutable; Commvault-sold, though decoys are vendor-neutral; quote-only.

per TB / year reported (licence); DataLock WORM on the SpanFS filesystem with quorum / MFA for privileged change; ML anomaly detection and CyberScan on the backups
Cohesity estates that want the appliance's own storage to be the immutable copy, with detection and scanning built into the platform and FortKnox as the off-site vault.
The catch: Software-enforced on the platform you operate — strong (quorum, MFA, WORM on the filesystem) but not a separate custodian; an India region for the BaaS form is not documented.

per TB / year reported; SaaS cyber vault on AWS S3 Object Lock or Azure immutable storage (irrevocable DataLock), Cohesity-operated, virtual air gap with a transfer window; recovery to the source cluster or an alternate location
Cohesity estates that want a second, vendor-operated immutable copy outside their tenant with a documented clean-recovery path to an alternate cluster or cloud.
The catch: Cohesity only; storage and recovery path, not detection (that is DataProtect); India region not documented; quote-priced per TB.

per TB / month on quote; Veritas-managed immutable cloud storage for NetBackup, isolated from the NetBackup domain
NetBackup estates that want the immutable off-site copy operated for them rather than built on their own object storage.
The catch: NetBackup only; storage, not detection; India region not documented; quote-only.

per back-end TB / month reported on three-year terms; append-only filesystem by design, Retention Lock removable only by Rubrik Support with two authorised customer officers; anomaly detection, threat monitoring, quarantine of infected snapshots, isolated recovery environments
Enterprises that want backup and cyber recovery to be one posture — the storage cannot be written over, the lock needs two people and the vendor, the snapshots are scanned, and the recovery can be rehearsed in an isolated environment.
The catch: The most expensive meter on this page on three-year terms; the platform is the custodian (strong, but one vendor for data and lock); India region not documented.

per TB on quote; Rubrik-hosted immutable storage in Azure, isolated from your tenant, under the same Retention Lock rules
Rubrik estates that want the off-site immutable copy hosted by Rubrik with no storage account of their own to protect.
The catch: Rubrik only; storage, not detection; India region not documented; quote-only.

part of Rubrik Security Cloud Enterprise Edition; IOC / YARA hunts across the backup history to find the last clean snapshot and the point of entry
Rubrik estates that need to answer 'which snapshot is clean, and since when' before restoring — without mounting and scanning each one by hand.
The catch: Scanning, not storage — it finds the clean point; the immutability is Enterprise Edition's; Rubrik data only.

included in or added to Druva's Enterprise / Elite plans; Druva-operated AWS with Data Lock that cannot be disabled once set, UEBA and unusual-activity detection, Curated Recovery building a clean restore point, quarantine and rollback actions; AWS Mumbai region
Druva estates — SaaS-only, no storage of their own — that want the air gap, the lock, the detection and the clean restore point as a service in India.
The catch: Druva-protected data only; no isolated clean-room environment as a product (recovery is into your environment or DRaaS); plan-tier pricing rather than a list.

Acronis Cloud storage per GB plus the per-workload licence, through MSPs; immutable storage in governance mode by default (an admin can disable it, 14-day grace) or compliance mode (nobody, including Acronis support); Safe Recovery scans backups; Mumbai data centre
MSP-run estates that want backup, anti-malware and an immutable cloud copy under one agent and one partner, in India — with the lock mode chosen deliberately.
The catch: Governance mode is the default: until compliance mode is switched on, an administrator can lift the immutability; partner pricing; enterprise scale is not where it is documented.

per TB / year list for replication to Barracuda Cloud; cloud copies written once and not modifiable through the appliance or API; local appliance copies are not the immutable ones
Barracuda appliance sites that want the off-site copy to be the one an attacker on the appliance cannot reach.
The catch: Who can delete a cloud copy inside retention, and through what process, is not established from documentation — marked unknown; local copies are mutable; no detection or scanning.

per device / month on top of the RMM plus Ninja cloud storage; AWS S3 Object Lock in governance or compliance mode; cloud copy only — the local copy is not locked
NinjaOne RMM estates that want the endpoint and server backups' cloud copy locked at the storage layer, from the console they already run.
The catch: Devices and servers only (no hypervisor-level VMs); the lock mode is a choice — governance can be lifted by the tenant for a period; no detection or scanning; India region not documented.
An isolated clean roomRules out Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud ThreatWise, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Rubrik Threat Hunting, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud — recovery is into your environment or an alternate site; no isolated recovery environment documented for this SKU. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud Cleanroom Recovery and Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery).
Detects anomalies itselfRules out Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Rubrik Threat Hunting, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud — storage or recovery only; detection comes from another product. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud ThreatWise, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Druva Cyber Resilience — Accelerated Ransomware Recovery and Acronis Cyber Protect Cloud — immutable storage + Advanced Security.
Clean restore pointRules out Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud ThreatWise, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud — no documented malware / IOC scan of the backup data. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud Cleanroom Recovery, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Rubrik Threat Hunting, Druva Cyber Resilience — Accelerated Ransomware Recovery and Acronis Cyber Protect Cloud — immutable storage + Advanced Security.
No single admin can lift itRules out Commvault Cloud ThreatWise and Rubrik Threat Hunting — a detection or scanning product, not a storage mechanism. That leaves Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery), Rubrik Cloud Vault, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud. It flags Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware — Depends on the mode you chose, Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Depends on the mode you chose, Barracuda Backup — immutable cloud copies — Who can delete inside retention is not established from documentation and NinjaOne Backup — S3 Object Lock in the Ninja cloud — Depends on the mode you chose — marked on the cards, not removed.
A vendor-operated custodianRules out Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Cohesity DataProtect — DataLock, anomaly detection, CyberScan and Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) — immutability is enforced on storage you operate: your configuration, your credentials; Commvault Cloud ThreatWise and Rubrik Threat Hunting — a detection or scanning product, not a storage mechanism; NinjaOne Backup — S3 Object Lock in the Ninja cloud — object lock in the vendor's cloud but the mode and lifting are in your tenant's hands. That leaves Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security and Barracuda Backup — immutable cloud copies. It flags Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Acronis-operated storage; the mode (governance vs compliance) is set by your tenant — marked on the cards, not removed.
Vault as a serviceRules out Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware, Commvault Cloud ThreatWise, Cohesity DataProtect — DataLock, anomaly detection, CyberScan, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) and Rubrik Threat Hunting — enforced on a platform or repository you run. That leaves Veeam Data Cloud Vault, Commvault Cloud Air Gap Protect, Commvault Cloud Cleanroom Recovery, Cohesity FortKnox, Veritas Alta Recovery Vault (Cohesity), Rubrik Cloud Vault, Druva Cyber Resilience — Accelerated Ransomware Recovery, Acronis Cyber Protect Cloud — immutable storage + Advanced Security, Barracuda Backup — immutable cloud copies and NinjaOne Backup — S3 Object Lock in the Ninja cloud.
Immutable copy in IndiaRules nothing out on published terms. It flags Veeam Data Platform Premium — Recon Scanner, Threat Hunter, secure restore, Coveware — Your repository or bucket, Commvault Cloud Cleanroom Recovery — India region not documented for this service, Commvault Cloud ThreatWise — India region not documented for this service, Cohesity DataProtect — DataLock, anomaly detection, CyberScan — India region not documented for this service, Cohesity FortKnox — India region not documented for this service, Veritas Alta Recovery Vault (Cohesity) — India region not documented for this service, Rubrik Security Cloud — Enterprise Edition (Retention Lock, Ransomware Monitoring, Threat Containment, Cyber Recovery) — India region not documented for this service, Rubrik Cloud Vault — India region not documented for this service, Rubrik Threat Hunting — India region not documented for this service, Barracuda Backup — immutable cloud copies — India region not documented for this service and NinjaOne Backup — S3 Object Lock in the Ninja cloud — India region not documented for this service — marked on the cards, not removed.
Petabyte-scale vaultsRules nothing out on published terms. It flags Acronis Cyber Protect Cloud — immutable storage + Advanced Security — Unverified at petabyte scale, Barracuda Backup — immutable cloud copies — Unverified at petabyte scale and NinjaOne Backup — S3 Object Lock in the Ninja cloud — Unverified at petabyte scale — marked on the cards, not removed.
Air gap: logical, physical, or marketingEvery product here documents a logical air gap — separate credentials, separate tenant, no network path from production to the copy. A physical (offline) copy — tape, a rotated drive — is documented for Veeam Data Platform (and for Commvault's and NetBackup's base products, which are on the backup guide). A firewall rule between two systems that share an admin is not an air gap; a vendor-operated vault your tenant cannot reach with any credential is. Ask which one the word means in the proposal.
Retention-lock durationConfigurable everywhere (days to years); the question is who can shorten it. Nobody inside retention: Veeam Vault, Air Gap Protect, FortKnox, Alta Recovery Vault, Druva, Acronis in compliance mode. Two people and the vendor: Rubrik. Quorum and MFA: Cohesity DataLock. An administrator, by design: governance modes (Acronis default, NinjaOne's choice, object lock in governance on Veeam targets). Not established: Barracuda.
Recovery time from the immutable copyA vault in another tenant or cloud restores across a network — slower than the local copy, by design. FortKnox, Air Gap Protect, Veeam Vault, Alta and Rubrik Cloud Vault all document restore paths; what they do not document is your hours-per-TB over your line. Measure it in the rehearsal; TechBag's delivery figures per platform are [TechBag to confirm].
Detection is a different product from storageCommvault sells the vault (Air Gap Protect), the early warning (ThreatWise) and the clean room as three SKUs; Rubrik folds monitoring, hunting and isolated recovery into Enterprise Edition and sells the vault apart; Veeam puts detection in Premium and the vault in Data Cloud; Cohesity puts detection in DataProtect and the vault in FortKnox; Druva and Acronis bundle most of it into a plan. The instrument's chips separate them so a vault is never mistaken for a scanner.
Prevention belongs next doorThe backups are the last line; the endpoint is the first. Which EDR the estate runs decides how early the encryption is seen and whether the backup server itself is protected — the endpoint-protection guide. Veeam's Recon Scanner and Commvault's ThreatWise are the two products here that look at the estate before the encryption reaches the backups.
Each shortlist names who can lift the lock in that estate and where the clean restore would happen. Start from the row that names your backup product — the vault decision was made when that decision was.
Why: Premium adds the scanning, the secure restore and Coveware's responders on the licence already running; Veeam Vault gives the off-site copy that is immutable by default instead of by your build.
The trade-off: Until the vault or a compliance-mode object-lock target exists, a hardened repository is as strong as its console access — test it as the attacker would.
Why: Air Gap Protect is the managed immutable copy, ThreatWise fires before encryption reaches it, Cleanroom Recovery stands up an isolated environment to prove the restore — three SKUs that read as one programme.
The trade-off: Three quotes; the cleanroom's Azure region for Indian buyers is not documented — ask.
Why: Five vendor-operated vaults, each for its own backup product: Veeam Vault (published $14 / $24 per TB per month, India Central), Air Gap Protect, FortKnox (S3 Object Lock, irrevocable), Rubrik Cloud Vault, Alta Recovery Vault for NetBackup.
The trade-off: Each vault is tied to its vendor's backup product — the vault decision is made when the backup decision is; only Veeam publishes the per-TB price.
Why: Commvault's on-demand cleanroom with scheduled tests, Rubrik's isolated recovery environments with threat hunting, and Veeam's Recovery Orchestrator clean-room flow with YARA scanning — the three documented isolated-recovery paths here.
The trade-off: Clean-room compute is metered on the day and for every test; the evidence is only as good as the last scheduled rehearsal.
Why: Druva's Data Lock cannot be disabled once set and its Curated Recovery builds the clean restore point from the AWS Mumbai region; Acronis offers immutable storage and Safe Recovery from its Mumbai data centre through an MSP.
The trade-off: Acronis is governance mode until compliance mode is switched on — make the switch part of the onboarding, in writing.
Why: Append-only storage, a Retention Lock that needs two officers and Rubrik Support, monitoring, threat hunting across snapshots, and isolated recovery — with Cloud Vault as the hosted copy.
The trade-off: One custodian for the data and the lock, on the page's most expensive meter and three-year terms.
Why: Acronis and NinjaOne lock the cloud copy with object lock in a mode you choose; Barracuda's cloud copies are written once and unreachable from the appliance.
The trade-off: Modes default to governance (Acronis) or are a choice (NinjaOne); Barracuda's deletion process inside retention is not documented — three flags, not three eliminations.
Why: DataLock on the appliance with quorum and MFA, anomaly detection and CyberScan on the platform; FortKnox as the vendor-operated, irrevocably locked second copy with an alternate-site recovery path.
The trade-off: Two Cohesity SKUs, two per-TB quotes; neither documents an India region for the service form.
Every product on this page says “immutable”. This is where each one’s technical documentation puts it. Products whose mechanism could not be established are listed as unknown, not placed by guess.
Implementation A
Storage-enforced: object lock (compliance) or hardware WORM
The storage layer refuses deletes and overwrites until the retain-until date — no credential in your tenant or the vendor's changes that. FortKnox (S3 Object Lock / Azure immutable, irrevocable). Acronis and NinjaOne use object lock too, but the mode is chosen by the tenant — compliance is this row; governance is row D.
Implementation B
Vendor-controlled: a custodian you cannot reach
The vendor operates the storage in its own tenant; you hold no credential that can delete inside retention. Veeam Vault (always-on), Air Gap Protect, Alta Recovery Vault, Rubrik Cloud Vault (under Retention Lock), Druva (Data Lock cannot be disabled). Barracuda's cloud copies are written once — who can delete inside retention is not documented.
Implementation C
Software-enforced on the platform you run
The backup platform's own storage refuses change by design — Rubrik's append-only filesystem with Retention Lock (two officers plus Rubrik Support to remove), Cohesity DataLock WORM on SpanFS with quorum and MFA. Strong; one custodian for the data and the lock; as reachable as the appliance.
Implementation D
Your build, or a flag an admin can clear
Veeam's hardened repository (Linux immutable attribute, single-use credentials — an attacker with root and console access can still reach it) or object lock on a target you configured, in the mode you chose. Governance mode anywhere (Acronis by default, NinjaOne as a choice, Veeam targets in governance) is a software flag an administrator can lift.
Who can delete a backup, and what it takes
The single most important line, per product — from documentation.
The ransomware-day test
Ask these before the word immutable, in this order.
Cyber recovery scales by the size of the copy that must sit out of reach and by how long a restore from there takes. The bill follows the vault; the confidence follows the rehearsal.
The default is the constraint
Put this in your PoC
Log in as the backup administrator and try to delete yesterday's copy. If you can, the attacker can.
The custodian and the scan are the constraint
Put this in your PoC
Ask for the restore throughput from the vault for an estate your size, and for the documentation page on who can delete inside retention.
The clean room and the evidence are the constraint
Put this in your PoC
Run a clean-room restore of the crown-jewel application from the vault and produce the evidence. Hours and findings are the slide.
Veeam, Commvault, Cohesity, Rubrik and Druva document petabyte estates; Acronis, NinjaOne and Barracuda are flagged unverified at that size. Where a specific vault or platform strains at your size: [TechBag to confirm].
The copies in the vault are immutable by design — they will not move, and they will not be deleted early. Switching means the new immutable copy must exist before the old one stops being refreshed.
The locked tail
Copies in the old vault stay until their retention expires — you cannot shorten it (that was the point). Budget the old vault until the last lock lifts.
No gap
The day the old product stops writing, the new product's immutable copy must already be current and tested. Overlap is not optional; it is the only honest plan.
Vendor-tied vaults
Veeam Vault, Air Gap Protect, FortKnox, Rubrik Cloud Vault and Alta are each for their own backup product; leaving the backup product leaves the vault.
The rehearsal evidence
Clean-room test reports and scan histories live in the old platform; export what the insurer and regulator may ask for before the contract ends.
Locked-tail cost, overlap and evidence export for your estate: [TechBag to confirm] — TechBag scopes it from your retention locks and vault sizes.
What you may already hold, the vaults and platforms priced the way they are sold in USD and INR, and what the licence line leaves out — which, for cyber recovery, is the clean room on the day and the responders on the phone.
Four places immutability may already be within reach. Two of them are real if configured.
If the lock you need is a setting you already pay for, we say so — and then we check the mode with you. It costs us a sale and saves you one.
Published and reported vault and platform meters (INR for scale), then worked at 10 / 100 / 1,000 TB in the immutable copy per year. Only Veeam publishes a vault list; the rest are reported or quoted. The clean room, the retainer and the rehearsal are stated apart, below.
Storage and the day — stated apart from the licence, on purpose
TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.
Isolated compute for the duration of the recovery and for every scheduled test — metered, not licensed. A fortnight of production-size clean room is the number to model; most business cases model an hour.
Coveware by Veeam sells an incident-response retainer with a 15-minute SLA; other vendors point to partners. Negotiation, forensics and the decision whether to pay are a separate contract — and a separate night.
Finding the last clean snapshot, restoring the crown jewels into the clean room, producing the evidence — quarterly, with an owner. Tools automate the scan; the drill is yours. Your hours: [TechBag to confirm].
Documented defaults and modes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover with the attacker still inside.
'Immutable' that a domain admin can override
Governance mode by default, a role that can shorten retention, a bucket created without object lock. The product supported compliance; nobody switched it on. Ask who can delete, and what it takes — from the documentation page.
Air gap that is a network rule, not an air gap
A firewall between the backup server and the repository, both administered with the same credentials. The attacker had those. A custodian you cannot reach, or an offline copy, is an air gap; a rule is a rule.
Restoring re-infected data because nobody scanned it
The last three weeks of backups carried the implant; the restore put it back. Anomaly detection and a malware / IOC scan of the backups are products — Veeam Premium, Rubrik, Cohesity, Druva, Acronis — not assumptions.
No clean room to restore into
The copy was clean; the network it was restored into was still the attacker's. Commvault, Rubrik and Veeam document isolated recovery environments; the rest is your design.
Discovering during an incident that immutability was never enabled
The renewal said immutable; the configuration said supported. The first check in any engagement is to log in as the backup admin and try to delete yesterday's copy.
The vault priced, the day not
Per-TB storage was in the budget; a fortnight of clean-room compute, the responders' retainer and the egress were not. Price the event.
Replication trusted as the plan
The DR replica carried the encryption within seconds. DR assumes the copy is trustworthy; this page is for when it is not.
One custodian for data and lock, unexamined
Platform-enforced locks (append-only, DataLock) are strong and still one vendor, one appliance, one console. For the crown jewels, a second custodian — a vendor-operated vault or tape — is the honest shape.
Vendor-neutral. No gated content.