RPO and RTO are the only two numbers in this category — and most organisations have never tested whether theirs are real.

A DR product keeps a second, runnable copy of your systems somewhere else — replicated continuously, periodically, or rebuilt from backups — and fails the estate over to it in an order that works, then brings it back. The copy is the easy half. The order, the network and the failback are the product.

Veeam documents continuous data protection with RPOs in seconds for vSphere. Druva documents failover into AWS Mumbai from backups it already holds, at an RPO of hours. Both are “disaster recovery”. They are not the same purchase.

Already decided — before the runbook demo

Your RPO and RTO, per applicationseconds, minutes or hours — honestly
Where you can runa second site you own, your cloud, or the vendor's
Your regulatordecides the India site and the drill evidence

Still yours to weigh

Mechanismcontinuous · periodic · from backup
Failbackthe half most plans break on
Testingwithout touching production
If you’ve never bought one

What disaster recovery software actually is

A way to run your systems somewhere else when the place they run is gone — power, flood, fibre cut, a hypervisor cluster that will not come back. The product keeps a second runnable copy (by continuous replication, periodic replication, or by standing up backups), fails over to it in a dependency-ordered plan — domain controllers before databases before applications — re-IPs and re-points what must change, and, when the site is back, fails back without losing what happened in between.

Two numbers define every product here. RPO — how much data you lose (seconds for continuous replication, minutes for periodic, hours for backup-based). RTO — how long until users are working again (minutes with orchestration and a warm target; hours to days by hand). Everything else is a variable: where the target is, who hosts it, whether failback is a button or a project. The data-only half of this decision is the backup and recovery guide; what to do when the second copy is also the attacker’s is the cyber-recovery guide.

The most common mis-purchase

A replication product bought as the ransomware plan. Replication copies the encryption to the second site within its RPO — seconds, if you paid for the good tier. DR assumes the source is trustworthy. Cyber recovery assumes it is not.

Often confused withBackup & Recovery — restoring data, versus restoring operations·Cyber Recovery — when the replica is the attacker's copy too·SaaS Backup — Microsoft runs the service; DR for your own estate is this page

The four routes of backup and cyber resilience — and which one is yours

Boundary — the terms this buyer confuses

RPO vs RTO · DR vs HA vs backup

Two pairs this buyer confuses, and nothing more. The first pair is two numbers that get used interchangeably; the second is three mechanisms that get sold as tiers. They are not tiers — they answer different failure modes.

RPO — how much you lose

Recovery point objective: the age of the last good copy when the failure hits. Continuous replication (Veeam CDP, Cohesity SiteContinuity) — seconds. Periodic replication (Commvault, NetBackup) — minutes. Backup-based recovery (Druva, Acronis, Rubrik recovery plans, Barracuda) — hours. A tight RPO costs storage, WAN and a warm target; it says nothing about how fast you are back.

RTO — how long until you are back

Recovery time objective: the time from failure to users working. Orchestration with boot order, re-IP and a warm target — minutes. Hand-built failover from backups — hours to days. A product can have a five-minute RTO on paper and a two-day RTO over your network. It is measured, or it is a guess.

HA vs DR

High availability keeps a system up through a component failure — a cluster, a second node, a load balancer — in the same place, automatically, with no data loss. DR moves the estate to another place after the place itself fails. HA does not survive the site; DR does not survive a bad transaction being replicated. Most estates need both; they are different purchases.

DR vs backup

Backup restores data to a point in time, slowly, anywhere — it is the copy of record. DR restores operations, fast, to a prepared place — from replicas or from backups stood up in order. Backup without DR is a long outage; DR without backup is a fast failover to whatever was replicated, including the corruption.

These are not tiers of the same product. HA survives a component, DR survives a site, backup survives time — and none of them survives an attacker who planned for all three, which is the cyber-recovery guide. A tool that handles a flooded data centre perfectly may be useless against deliberate destruction replicated in seconds.
The decision variables

Six things decide this purchase. The feature grid is none of them.

Seven variables decide this purchase. The instrument tests the ones documentation can verify (RPO class, target, orchestration, scope, India site); achievable RTO, failback time and the regulator’s expectations are prose because the honest answers come from your last drill, not a datasheet.

01

Achievable RPO and RTO — tested, not claimed

Seconds / minutes / hours by mechanism; then the number you measured in a real drill with the real application stack over the real network. If it has never been measured, it is unknown.

02

Failover target

A second site you own, your own cloud account (AWS, Azure, GCP, OCI), or the vendor's hosted DRaaS. Decides who pays for the target on a quiet day and on the day.

03

Orchestration and runbook automation vs manual failover

Boot order, dependencies, re-IP, scripts, one click — or a wiki page and a phone tree. The RTO lives here.

04

Failback

Bringing the estate home without losing what happened while you were away — and the step where most DR plans actually break. Documented as one operation at most products here; flagged where not.

05

Testing without disrupting production

Isolated test networks, automated reports, drill evidence for the auditor. Documented everywhere here; done quarterly almost nowhere.

06

RBI and sectoral business-continuity expectations

Documented RPO/RTO, periodic drills with evidence, data in India for regulated entities. Your design artefact on most products; hosted for you on one.

07

India DR site availability

A vendor-hosted failover target in India (Druva's AWS Mumbai DRaaS), your own second Indian site or India cloud region (the rest), or not documented (flagged).

The narrowing instrument · the reasoning is the product

Narrow 9 products to your shortlist

Set what is true for you. Products that miss a constraint fade and carry the reason; where documentation cannot settle your case they are flagged, not removed. Every chip is reversible.

The RPO you need

Where it fails over to

What must fail over

How it fails over

India

Estate size

Measured RTO, failback duration and regulator expectations are in the notes below, not chips — they are drill results and design artefacts, not datasheet lines.

Still in9/ 9
Veeam logo

per workload (VUL) / year reported for Advanced (CDP) and Premium (Recovery Orchestrator, automated testing, ransomware warranty); the DR site and its compute are yours

VMware-centric estates that want replication and continuous data protection to a second site or cloud, with one-click failover plans, automated testing and documented failback — on the licence they already run for backup.

The catch: CDP is VMware-only (vSphere); the secondary site, its hypervisor and its storage are your cost and your build; Recovery Orchestrator is Premium — Foundation has replication without the orchestration.

CDP (seconds RPO)Orchestrator (Premium)Your DR site
Intel page →
Commvault logo

per VM / instance or per front-end TB on quote; replication to a second site or to AWS, Azure, GCP and OCI; recovery groups with boot order; the target is yours

Mixed estates that want replication, cross-hypervisor and cloud-target failover and policy-driven recovery groups from the same platform that backs them up.

The catch: Periodic replication rather than continuous (minutes, not seconds); the failover target — second site or cloud account — is yours to run and pay for; quote-only.

Cross-cloud targetsRecovery groupsQuote
Intel page →
Commvault logo

per protected cloud application / resources on quote; rebuilds the whole cloud application — infrastructure, configuration, dependencies — in a new account or region

Cloud-native estates (AWS, Azure, GCP) that need the application, not only its data, rebuilt after an account compromise or region loss — with periodic rebuild tests.

The catch: Cloud-native applications only — no VMware, no physical; RPO follows the snapshot schedule; failback to the original account after rebuild is not documented as a one-step operation.

Cloud app rebuildAccount-loss scenarioCloud-native only
Intel page →
Cohesity logo

licensed on the Cohesity platform (per TB) on quote; continuous replication for VMware to a second Cohesity cluster or to AWS; application-level runbooks

Cohesity estates that want near-zero RPO for VMware workloads and orchestrated, tested failover to a second cluster or to AWS, from the backup platform's console.

The catch: Continuous replication is VMware-centric; the second cluster or the AWS account is yours to own; Hyper-V and Nutanix are backup-level protection, not continuous DR here; quote-only.

Near-zero RPO (VMware)RunbooksSecond cluster or AWS
Intel page →
Cohesity logo

enterprise licensing on quote alongside NetBackup (per front-end TB); resiliency orchestration across data centre and cloud with rehearsals

Large NetBackup estates that want cross-site and cloud recovery orchestration, rehearsal and reporting on the platform they already operate.

The catch: Enterprise-priced and enterprise-operated; the orchestration layer is a separate licence from NetBackup itself; the DR site is yours.

Enterprise orchestrationRehearsalsNetBackup estates
Intel page →
Rubrik logo
Included in Enterprise Edition

part of Rubrik Security Cloud Enterprise Edition (reported ~$130 per back-end TB / month on three-year terms); recovery plans with boot order and test mode for VMware and Azure

Rubrik estates that want application-level recovery plans — boot order, dependencies, test mode — from backups and replicas in the same console as the cyber-recovery posture.

The catch: Recovery from backups and replicas, not continuous data protection — RPO is the backup interval, not seconds; VMware and Azure are documented, other hypervisors are not; the target site is yours.

Recovery plansFrom backups/replicasVMware · Azure
Intel page →
Druva logo

per protected VM / month on quote on top of Hybrid Workloads; failover into your AWS account (Mumbai region available); one-click runbooks, failback to on-prem; no second site to build

Organisations without a second data centre that want VMware, Hyper-V and physical servers failed over into AWS — in India — from the backup copies Druva already holds, with documented failback.

The catch: RPO is the backup frequency (hours), not replication; AWS only as the target, and the failover compute runs in your AWS account at your cost; quote-only.

DRaaS to AWSMumbai regionNo second site
Intel page →
Acronis logo

per-GB storage plus compute points consumed during test and production failover, through MSPs; runbooks; failover into Acronis Cloud; failback to original or new hardware

MSP-run SMBs that want servers and VMs recoverable into Acronis Cloud in minutes with runbooks and a test failover they can actually run, on the same agent as backup and security.

The catch: Billed in compute points and GB through a partner — no public rate card; whether the Mumbai data centre hosts DR (not only backup storage) is not documented; enterprise scale is not where it is documented.

DRaaS via MSPRunbooksCompute points
Intel page →
Barracuda logo

per TB / year list for replication to Barracuda Cloud (appliance or Vx priced apart); LiveBoot runs VMs from the appliance or from Barracuda Cloud; site-to-site replication between appliances

Mid-market sites with a Barracuda appliance that want VMs bootable from the local appliance or from Barracuda's cloud after a site loss, at a flat replication price.

The catch: No runbook orchestration — LiveBoot is per VM, not a dependency-ordered plan; RPO is the backup interval; an India region for Barracuda Cloud is not documented; VMware and Hyper-V only.

LiveBootFlat cloud priceNo runbooks
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

Seconds of RPORules out Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration) and NetBackup — Resiliency Platform & IT Analytics (Cohesity) — periodic replication (minutes), not continuous; Commvault Cloud Rewind, Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication — recovers from backups or snapshots (hours), not replication. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium) and Cohesity SiteContinuity (DataProtect DR).

Minutes of RPORules out Commvault Cloud Rewind, Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication — recovers from backups or snapshots (hours), not replication. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Cohesity SiteContinuity (DataProtect DR) and NetBackup — Resiliency Platform & IT Analytics (Cohesity).

Vendor-hosted failoverRules out Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity) and Rubrik Orchestrated Application Recovery — fails over to a site or cloud account you own and run. That leaves Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication.

Your cloud account as the targetRules out Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication — does not fail over into your cloud account. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery and Druva Disaster Recovery as a Service (AWS).

Your own second siteRules out Commvault Cloud Rewind, Druva Disaster Recovery as a Service (AWS) and Acronis Disaster Recovery (Cyber Protect Cloud add-on) — vendor-hosted or cloud-only failover. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery and Barracuda Backup — Cloud LiveBoot & replication.

Hyper-VRules out Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR) and Rubrik Orchestrated Application Recovery — Hyper-V not documented for DR here. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication.

Physical serversRules out Commvault Cloud Rewind and Rubrik Orchestrated Application Recovery — physical servers not documented. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication.

Cloud-native applicationsRules out Druva Disaster Recovery as a Service (AWS), Acronis Disaster Recovery (Cyber Protect Cloud add-on) and Barracuda Backup — Cloud LiveBoot & replication — on-prem workloads only. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity) and Rubrik Orchestrated Application Recovery.

Orchestrated runbooksRules out Barracuda Backup — Cloud LiveBoot & replication — per-VM failover, no dependency-ordered plan. That leaves Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium), Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration), Commvault Cloud Rewind, Cohesity SiteContinuity (DataProtect DR), NetBackup — Resiliency Platform & IT Analytics (Cohesity), Rubrik Orchestrated Application Recovery, Druva Disaster Recovery as a Service (AWS) and Acronis Disaster Recovery (Cyber Protect Cloud add-on).

Failback documentedRules nothing out on published terms. It flags Commvault Cloud Rewind — Failback to the original environment not documented as a single operation — marked on the cards, not removed.

DR site in IndiaRules nothing out on published terms. It flags Veeam Data Platform — Replication, CDP & Recovery Orchestrator (Advanced · Premium) — Your second site or your cloud region, Commvault Cloud Disaster Recovery (replication · Live Sync · failover orchestration) — Your second site or your cloud region, Commvault Cloud Rewind — Your second site or your cloud region, Cohesity SiteContinuity (DataProtect DR) — Your second site or your cloud region, NetBackup — Resiliency Platform & IT Analytics (Cohesity) — Your second site or your cloud region, Rubrik Orchestrated Application Recovery — Your second site or your cloud region, Acronis Disaster Recovery (Cyber Protect Cloud add-on) — An India-hosted failover target is not documented and Barracuda Backup — Cloud LiveBoot & replication — An India-hosted failover target is not documented — marked on the cards, not removed.

Above 1,000 VMsRules nothing out on published terms. It flags Acronis Disaster Recovery (Cyber Protect Cloud add-on) — Unverified above 1,000 VMs and Barracuda Backup — Cloud LiveBoot & replication — Unverified above 1,000 VMs — marked on the cards, not removed.

Tested, not claimedEvery product here documents a non-disruptive test (Veeam SureReplica and Orchestrator reports, Commvault recovery validation, Cohesity and NetBackup rehearsals, Rubrik test mode, Druva and Acronis test failover, Barracuda LiveBoot). None of that is your RPO and RTO. Those are the numbers you measured the last time you failed over the real application stack and came back; if the honest answer is never, the honest RPO is unknown. TechBag's delivery figures for real failover and failback times are [TechBag to confirm].

DR versus cyber recoveryReplication is the fastest way to copy ransomware to the second site. A DR product assumes the source is trustworthy; the moment it is not, you need an immutable backup and a clean room — the cyber-recovery guide. Veeam, Commvault, Cohesity, Rubrik and Druva sell both halves; they are different SKUs and different rehearsals.

RBI and sectoral business-continuity expectationsRBI's IT Governance and outsourcing directions, SEBI's CSCRF and IRDAI's guidelines expect documented RPO/RTO, periodic DR drills with evidence, and data in India for regulated entities. Druva's AWS Mumbai DRaaS is the documented India-hosted target here; every other product leaves the site in your hands, which for most regulated buyers means a second Indian data centre or an India cloud region — your design, and documented as such.

Network and DNSNo product on this page fails over your network. Re-IP, DNS cut-over, firewall rules, identity and the VPN are your runbook's first pages; the orchestration tools (Veeam Orchestrator, Commvault, Cohesity, Rubrik, Druva, Acronis) can script the re-IP and some DNS steps — test that they did.

Under 50 VMsRules nothing out on documentation: Acronis DR and Barracuda LiveBoot are built for the small estate; Druva DRaaS and Veeam replication start at any size; the orchestration products (Orchestrator, SiteContinuity, NetBackup resiliency) are enterprise-positioned. Where the small estate should stop at backup-plus-a-plan is delivery judgement: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the RPO named

Each shortlist names the mechanism (continuous, periodic, from backups) and where the estate would run. If you have no second site, start from the second row.

VMware, two data centres, and a real RPO in seconds

Why: Veeam CDP (Advanced) and Cohesity SiteContinuity document continuous replication for vSphere with orchestrated failover and failback to a second site you own.

The trade-off: Continuous replication doubles the storage and the WAN; the second site's compute is the bill — and replication will faithfully copy the ransomware.

No second data centre — fail over into a cloud we pay for only on the day

Why: Druva fails VMs over into your AWS account (Mumbai available) from copies it already holds; Acronis fails over into Acronis Cloud through an MSP on compute points; Veeam replicates to a cloud target you run.

The trade-off: RPO is hours for the DRaaS pair (backup frequency, not replication); the cloud compute during a real event is the number nobody modelled.

Mixed hypervisors and clouds — one orchestration layer

Why: Commvault replicates across VMware, Hyper-V, Nutanix and into AWS, Azure, GCP and OCI with recovery groups; NetBackup's resiliency layer orchestrates across data centre and cloud for large estates; Veeam Orchestrator covers replicas, CDP replicas, backups and storage snapshots in one plan.

The trade-off: Breadth is periodic (minutes) rather than continuous; the plan is only as good as the last rehearsal — and someone has to own it.

Cloud-native — an AWS or Azure account or region is the thing that can be lost

Why: Cloud Rewind rebuilds the application — infrastructure, configuration, dependencies — in a new account or region; Commvault and Veeam replicate and recover cloud instances and data.

The trade-off: Rebuilding the application is a different test from restoring its data — run the rebuild quarterly, and price the second region's compute for the day.

Rubrik estate — recovery plans without a replication product

Why: Rubrik's Orchestrated Application Recovery gives boot order, dependencies and test mode over backups and replicas in the console you already run; Commvault is the like-for-like if continuous replication becomes the requirement.

The trade-off: RPO is the backup interval — honest for most applications, wrong for the one database that cannot lose an hour.

The regulator wants an India DR site and drill evidence

Why: Druva's AWS Mumbai DRaaS is the documented India-hosted target; Veeam and Commvault fail over to the second Indian site or India cloud region you design, with test reports as drill evidence.

The trade-off: Only one product here hosts the India site for you; the rest make the site your cost and your compliance artefact — which many regulated buyers prefer.

MSP-run SMB with a few servers and no DR plan at all

Why: Acronis DR adds runbooks and cloud failover to the agent the MSP already runs; Barracuda LiveBoot boots VMs from the appliance or the cloud at a flat replication price; Druva DRaaS needs no second site.

The trade-off: Barracuda has no dependency-ordered runbooks; Acronis is billed in compute points through the partner — ask what a week of production failover costs.

Enterprise on NetBackup or Commvault with a DR audit due

Why: NetBackup's resiliency orchestration and Commvault's recovery groups produce the rehearsal evidence auditors ask for across the estates those platforms already protect; Veeam Orchestrator does the same for the VMware share.

The trade-off: Orchestration licences sit on top of the backup licence; the drill is a project with an owner, not a feature.

The spine of the decision

Three mechanisms, three targets, one step everyone skips

Every product here “does DR”. Place each on its mechanism and its target before comparing anything, then ask about the step back.

Mechanism 1

Continuous replication — seconds

Every write shipped to the target as it happens (Veeam CDP, Cohesity SiteContinuity — both vSphere-centric). The tightest RPO, the most storage and WAN, a warm target you pay for every day — and the fastest way to replicate an attack.

Mechanism 2

Periodic replication — minutes

Snapshots shipped on a schedule to a second site or cloud account (Commvault, NetBackup, Veeam replication). Cross-hypervisor and cross-cloud breadth; RPO in minutes; the target is still yours.

Mechanism 3

From backups — hours

Stand the estate up from the backup copies, in order, somewhere warm (Druva into AWS, Acronis into its cloud, Rubrik recovery plans, Barracuda LiveBoot, Cloud Rewind rebuilding the application). Cheapest on a quiet day; RPO is the backup interval; the day's compute is the bill.

The failback test

Ask these before the failover demo, in this order.

  • Show me the failback. Every demo fails over. Ask to see the estate come home — with the data written during the outage — as one documented operation. Flagged here where it is not.
  • What fails over the network? Re-IP, DNS, firewall rules, identity, VPN. The product scripts some; your runbook owns the rest.
  • What does a week of production failover cost? Cloud compute (Druva, Cloud Rewind, Commvault/Veeam cloud targets), compute points (Acronis), or a second site’s standing cost (everything else).
  • When was the last full drill, and what were the measured RPO and RTO? If the answer is a datasheet, the answer is unknown.

The India layer

Where the second site is, is a compliance artefact.

  • Hosted for you in India: Druva DRaaS into AWS Mumbai — the one documented vendor-hosted India target on this page.
  • Your design: Veeam, Commvault, Cohesity, NetBackup, Rubrik replicate or recover to a second Indian data centre or an India cloud region you choose — which most regulated buyers prefer, and must document.
  • Not documented: whether Acronis’s Mumbai data centre hosts DR compute (not only backup storage) and whether Barracuda Cloud has an India region — flagged, not ruled out. Ask in writing.
What breaks as you grow

What changes at 50, 500 and 5,000 protected VMs

DR scales by the number of things that must come up in order, and by the network they must come up across. The bill follows the target; the RTO follows the runbook.

50protected VMs

The plan is the constraint

  • Any product here covers it; the difference is whether there is a plan at all. DRaaS (Druva, Acronis) and LiveBoot (Barracuda) give the small estate a target without a second site.
  • RPO of hours is honest for most small estates — say so and buy accordingly.
  • The drill is a day's work; do it once a year at minimum.

Put this in your PoC

Fail over the three servers that matter into the test network and time it. Then fail back. The second number is the finding.

500protected VMs

Dependencies and the target's cost are the constraint

  • Boot order, re-IP and application dependencies stop being a wiki page — orchestration (Veeam Orchestrator, Commvault recovery groups, Cohesity runbooks, Rubrik plans) earns its licence.
  • A warm second site or a cloud account with reserved capacity becomes a standing bill; continuous replication doubles the storage and the WAN.
  • The tier matters: Veeam Foundation replicates, Premium orchestrates; Rubrik plans are in Enterprise Edition.

Put this in your PoC

Ask for a recovery-plan report from an automated test on an estate your size, and the cost of the target on a quiet month and a failover month.

5,000protected VMs

Sovereignty, evidence and the operating model are the constraint

  • Multi-site, multi-cloud, multiple regulators: the DR site's location, the drill evidence and the RPO per application class become board and audit material.
  • Enterprise orchestration (NetBackup resiliency, Commvault, Veeam Orchestrator at scale) plus a named DR owner and a quarterly drill calendar is the honest shape.
  • Cyber recovery is now a separate rehearsal: the replica is the attacker's copy too.

Put this in your PoC

Run a full application-stack failover and failback in a quarter, with measured RPO and RTO per tier. Those two numbers are the only slide.

Veeam, Commvault, Cohesity, NetBackup, Rubrik and Druva document large estates; Acronis and Barracuda are flagged unverified above 1,000 VMs, not ruled out. Where a specific product strains for your application tiers: [TechBag to confirm].

The switching cost

Leaving a DR product means re-seeding the second copy

Replicas and recovery plans are product-specific. Switching means the new product takes its own first copy of everything and you rebuild the runbooks — while the old protection keeps running until the new one has been tested.

The re-seed

The new product's first replication or backup of the whole estate crosses the WAN once more; for continuous replication the target storage is built again. Plan the window and the bandwidth.

Exit costFirst copy, again

The runbooks

Boot orders, re-IP rules, scripts and dependencies live inside the orchestration product; export the logic as a document before you leave and rebuild it — then test it.

Exit costRebuild and re-test

The target

A vendor-hosted target (Druva's AWS account pattern, Acronis Cloud) disappears with the contract; your own second site or cloud account stays and is re-pointed.

Exit costKeep yours, lose theirs

The overlap

Run both until the new product has passed a full drill. Two DR bills for a quarter is the honest cost of not being unprotected for one.

Exit costOne tested quarter, twice

Re-seed bandwidth, runbook rebuild and overlap cost for your estate: [TechBag to confirm] — TechBag scopes it from your application tiers and WAN.

What it costs

The licence is the small number — the target is the bill

What you may already hold, the products priced the way they are sold in USD and INR, and what the licence line leaves out — which, for DR, is the second site or the cloud compute on the day.

01

Do you already own one?

Four places a DR capability may already sit. None of them is a plan.

Hypervisor replication (vSphere Replication, Hyper-V Replica)
Partly Per-VM replication built into the hypervisor, RPO in minutes, no orchestration, no failback plan. A mechanism, not a DR product — and it replicates the corruption.
Storage-array replication
Partly Array-to-array replication is fast and faithful. It gives you a second copy of the LUNs, not a running estate in order; and it needs a second array somewhere else.
Your cloud provider's DR service
Partly Azure Site Recovery and AWS Elastic Disaster Recovery replicate servers into that cloud with runbooks, on consumption. Real DR for that cloud as the target; nothing for the other cloud or a second site.
Your backup product's tier
Often Veeam Advanced/Premium, Commvault, Cohesity, NetBackup, Rubrik Enterprise Edition and Druva all sell DR on the licence you already run. Read the tier — Foundation replicates without orchestrating.

If the mechanism you already own is enough for your RPO and a plan is what is missing, we say so. It costs us a sale and saves you one.

02

What the rest actually cost

Reported and list meters (INR for scale). The licence is the smaller half everywhere here; the three plates price the target — a warm second site, your cloud on the day, or the vendor’s — at three estate sizes, with the licence lines under it. Where a product is quote-only the line says so.

50protected VMs · per year
The target, apart from any licence. A warm cloud target at an indicative ~$70 per VM per month (2 vCPU / 8 GB reserved-equivalent): $42,000 ₹34,86,000 a year standing — or a second data centre’s hardware, power and people. On the day of a real event, add the production-size compute for its duration.
  • Veeam Advanced → Premium(reported $350–450 per workload / yr)$17,50022,500 ₹14,52,500₹18,67,500
  • Barracuda cloud replication(list $799 per TB / yr; ~0.2 TB per VM assumed)$7,990 ₹6,63,170
  • Commvault Cloud Disaster RecoveryQuote
  • Cohesity SiteContinuityQuote
  • NetBackup resiliencyQuote
  • Rubrik(in Enterprise Edition)Quote
  • Druva DRaaS(per VM / mo)Quote
  • Acronis DR(compute points + GB)Quote
  • Commvault Cloud RewindQuote
500protected VMs · per year
The target, apart from any licence. A warm cloud target at an indicative ~$70 per VM per month (2 vCPU / 8 GB reserved-equivalent): $4,20,000 ₹3,48,60,000 a year standing — or a second data centre’s hardware, power and people. On the day of a real event, add the production-size compute for its duration.
  • Veeam Advanced → Premium(reported $350–450 per workload / yr)$1,75,0002,25,000 ₹1,45,25,000₹1,86,75,000
  • Barracuda cloud replication(list $799 per TB / yr; ~0.2 TB per VM assumed)$79,900 ₹66,31,700
  • Commvault Cloud Disaster RecoveryQuote
  • Cohesity SiteContinuityQuote
  • NetBackup resiliencyQuote
  • Rubrik(in Enterprise Edition)Quote
  • Druva DRaaS(per VM / mo)Quote
  • Acronis DR(compute points + GB)Quote
  • Commvault Cloud RewindQuote
5,000protected VMs · per year
The target, apart from any licence. A warm cloud target at an indicative ~$70 per VM per month (2 vCPU / 8 GB reserved-equivalent): $42,00,000 ₹34,86,00,000 a year standing — or a second data centre’s hardware, power and people. On the day of a real event, add the production-size compute for its duration.
  • Veeam Advanced → Premium(reported $350–450 per workload / yr)$17,50,00022,50,000 ₹14,52,50,000₹18,67,50,000
  • Barracuda cloud replication(list $799 per TB / yr; ~0.2 TB per VM assumed)$7,99,000 ₹6,63,17,000
  • Commvault Cloud Disaster RecoveryQuote
  • Cohesity SiteContinuityQuote
  • NetBackup resiliencyQuote
  • Rubrik(in Enterprise Edition)Quote
  • Druva DRaaS(per VM / mo)Quote
  • Acronis DR(compute points + GB)Quote
  • Commvault Cloud RewindQuote

Storage and the DR site — stated apart from the licence, on purpose

The replica storage. Continuous and periodic replication keep a full second copy warm: the same capacity again, on the target, plus journal space for CDP. Object-storage copies for backup-based DR run $14 ≈ ₹1,162$24 ≈ ₹1,992 per TB per month at vault list prices.
The second site. Hardware, power, cooling, the WAN between, and the people — or a cloud account with reserved capacity. Nobody’s licence includes it; most DR budgets forget it was the largest line.
The day itself. Production-size compute in the cloud for the duration of the event (Druva into your AWS, Commvault/Veeam cloud targets, Cloud Rewind), Acronis compute points, or the second site’s surge. Price a week, not an hour.
Tier-match: replication is not orchestration. Veeam Foundation replicates; Advanced adds CDP; Premium adds Recovery Orchestrator and automated testing. Rubrik’s plans are Enterprise Edition. Commvault and Cohesity license DR on the platform. Price the tier with the runbooks in it.
Term-match: per workload per year, per VM per month, points. Veeam is per workload per year; Druva DRaaS per protected VM per month on top of backup; Acronis in compute points and GB through an MSP; Barracuda per TB replicated. The plates normalise to a year and separate the target; your quote will not.
The India line. Druva’s AWS Mumbai DRaaS is the hosted India target; everyone else fails over to the Indian site or region you design. Indian quotes arrive in USD and in INR with GST; TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale at ≈₹83/$; the tier-matched INR quote is ours.

03

What isn’t in the licence price

The DR site

A second data centre or reserved cloud capacity — $420000 ≈ ₹3,48,60,000 a year indicative for a warm 500-VM cloud target before the licence, or a building. The largest line in most DR budgets, and the one most often left out of the business case.

Cloud cost during an actual event

Production-size compute, storage and egress for the duration of the failover, then the transfer back. Nobody models a two-week event; model it.

The drill

A quarterly application-stack failover and failback with measured RPO and RTO, an owner, and the evidence for the auditor. Tools automate the report; the rehearsal is still yours. Your hours: [TechBag to confirm].

Before you commit

What goes wrong

Documented behaviour and drill outcomes, cross-checked against TechBag engagements before any becomes a named case. Each is cheaper to read here than to discover mid-failover.

DR plans never tested end to end

Individual VMs failed over in a test network; the whole application stack never did. The first real failover found the dependency nobody drew. Drill the stack, quarterly.

Failback taking longer than failover

Failover was a button; bringing the estate home with a week of new data was a project. Ask to see failback in the demo — flagged here where it is not documented.

Cloud DR costs during an actual event

The target was cheap while it slept; production-size compute for three weeks was not in the budget. Price a fortnight, not an hour.

Dependency ordering wrong on failover

Applications booted before the database, the database before the domain controller. Boot order is the runbook; the runbook is the product.

Network and DNS not part of the plan

Every VM came up at the second site with the old IPs and nobody could reach them. Re-IP, DNS and firewall rules are pages one to three.

Replication trusted as the ransomware plan

The encryption replicated to the DR site in seconds. DR assumes the source is trustworthy; the cyber-recovery guide is for when it is not.

RPO quoted from the datasheet

Seconds on the slide; the WAN could not sustain the change rate and the journal fell hours behind. Measure the change rate before buying continuous replication.

The India site assumed

The regulator asked where the failover would run; the answer was a region in another country. Druva documents Mumbai; the rest is your design, documented as such.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Backup & Cyber Resilience map →

Evaluating

Get your shortlist scoped against your real estate.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.