Ransomware has encrypted your vCenter. You shouldn’t restore blind into the same network — VMware Live Recovery Cloud ships snapshots of your vSphere VMs to an immutable cloud file system, then recovers them into VMware Cloud on AWS — through an isolated clean room that scans each VM when the cause is ransomware.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers VMware Live Recovery Cloud — the SaaS cyber and disaster recovery service, formerly Live Cyber Recovery. The on-premises product, VMware Live Recovery (now VCF Protection and Recovery), has its own page. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Snapshots of your VMs sit in an immutable cloud copy, and an isolated clean room checks them before they return to production.
What consolidation actually replaces, dimension by dimension.
| Dimension | A second data centre and nightly backups | VMware Live Recovery Cloud |
|---|---|---|
| The DR site | A second data centre you power all year | A VMware Cloud on AWS SDDC, sized for the day |
| Copies after an attack | Backups the attacker may have deleted | Immutable snapshots outside your vCenter |
| Finding a clean copy | Restore, boot, hope, repeat | Entropy and change rate point to a snapshot |
| Checking for malware | Booted on the production network | Scanned inside an isolated clean room |
| Data you can lose | Everything since last night’s backup | Up to the snapshot interval: 30 min at best |
| What it is NOT | — | Continuous replication, or recovery anywhere but VMC on AWS |
The cheapest test is one protection group: snapshot a handful of tagged VMs, run the recovery plan in test mode, and time the live mount.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A virtual appliance deployed into your vCenter takes the protection-group snapshots and ships them out over SSL; an internet proxy between it and the cloud is not supported.
Snapshots land in an immutable cloud file system, kept in native VMDK form, inside a VMware Cloud on AWS account dedicated to your organisation, in the region you activate.
The cloud orchestrator holds protection groups and recovery plans, drives test and real failovers, and runs the guided ransomware workflow from the Protection and Recovery console.
VMs mount straight from the file system into a VMware Cloud on AWS SDDC, with no rehydration; the same SDDC becomes the isolated clean room for a ransomware recovery.
A connector in vCenter and a clean room in the cloud — snapshots kept immutable, VMs recovered into VMware Cloud on AWS.
VMware Live Recovery Cloud keeps immutable snapshots of your vSphere VMs off-site and recovers them, checked, into VMware Cloud on AWS.
Groups pick up VMs by name pattern, vSphere tag or folder each time a snapshot runs, so new VMs are covered without a manual step.
Delta-only snapshots run every 30 minutes without VM-level snapshots; a 15-minute schedule for up to 200 VMs is still in preview.
High-frequency snapshots can quiesce applications on ESXi 8.0 U3b, though not when the protected site is itself on VMware Cloud on AWS.
Recovered VMs run directly off the cloud file system as an NFS datastore, then move to SDDC storage by vMotion when you are ready.
Plans set the VM order, network mapping and IPv4 changes, and the same plan runs as a test or a real failover from the console.
Failback plans return recovered VMs to the protected site; Broadcom pays that egress up to half of your protected capacity.
The recovery SDDC becomes an isolated recovery environment with preset network isolation levels, or custom firewall rules you write.
Next-generation antivirus and behaviour analysis check each VM in validation for suspect OS activity, malware and known flaws.
Change rate and file entropy guide you to a snapshot before encryption began, and you can swap in a different snapshot per VM.
A Broadcom overview, the Accuris customer story, a long session from the Live Cyber Recovery days and a 2023 demo under the old name VMware Ransomware Recovery. All from VMware’s official channels.
Broadcom’s overview of the Live Recovery family, including the cloud clean room this page covers.
Accuris on faster recovery and application availability with the service, in under two minutes.
A long session from when the service was sold as Live Cyber Recovery: clean room, scans and restore-point choice.
Recorded in 2023, under its old name VMware Ransomware Recovery; the guided workflow still follows this shape.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
After an attack, the recovery SDDC on VMware Cloud on AWS turns into an isolated recovery environment with preset network isolation. Embedded antivirus and behaviour analysis check each VM, and change rate and file entropy point you to the last clean snapshot. Building that clean room yourself means a spare site, tools and firewall work.
Snapshots leave your site through the connector and sit in an immutable cloud file system in a VMware Cloud on AWS account dedicated to you. They sit outside the vCenter and storage an attacker reaches first, the place where on-site snapshots are most exposed.
Snapshots stay in native VMDK form and mount straight into a vSphere SDDC, so nothing is converted to another cloud’s format and your team runs the recovered estate with vCenter as before. Failback plans bring VMs home, and Broadcom pays that egress up to half of your protected capacity.
It is snapshot-based, never continuous: 30 minutes at best, 15 only in preview. It protects vSphere VMs alone and recovers only into VMware Cloud on AWS, whose hosts are billed apart. There is no list price, it is sold in USD with a 10 TiB floor per region, and no Windows 11, vTPM or secure-boot VM can fail over yet.
List the VMs that matter, then rule out vTPM, secure-boot, Windows 11, encrypted, RDM and shared-disk VMs before sizing.
Count protected VMs and TiB per region (10 TiB minimum), model VMC on AWS hosts, and confirm the Mumbai region on the quote.
Activate the region, deploy the connector OVA in vCenter, open the network paths with no proxy, and build tag-based groups.
Run a recovery plan in test mode, time the live mount and storage move, then rehearse failback and check the egress used.
Pick an older snapshot, walk it through the clean room with scans, and write the run book your board will ask for.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“In the drill, entropy flagged two snapshots as encrypted, and we restored from the one just before them without guessing.”
“We closed our second data centre. The steady bill is now protected capacity plus two pilot-light hosts, which finance can follow.”
“Protection groups by vSphere tag were the quiet win; new VMs with the tag were in the next snapshot without a ticket.”
“Check the caveats list early. Two vTPM-enabled VMs could not be protected, and we found out during onboarding.”
“Live mount meant our ERP was answering in the cloud before storage migration had finished; users barely noticed.”
“The service is solid, but sizing VMs, TiB and VMC hosts in USD took three rounds before finance would sign it.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the disaster recovery market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Per VM plus per TiB, 10 TiB floor a region; no list price.
The grid nobody publishes — how tight the recovery point is vs how much help a product gives you to recover clean after ransomware.
30-minute snapshots; clean room, antivirus and entropy-guided restore.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against HPE Zerto Software, Azure Site Recovery, AWS Elastic Disaster Recovery, Veeam Data Platform and Nutanix Disaster Recovery — on workloads, recovery point, failback, price, the bill on top, ransomware defence, support and India.
| Dimension | VMware Live Recovery Cloud | HPE Zerto Software | Azure Site Recovery | AWS Elastic Disaster Recovery | Veeam Data Platform | Nutanix Disaster Recovery |
|---|---|---|---|---|---|---|
| What it is | SaaS cyber + DR | Journaling DR software | Azure-run DR service | AWS-run DR service | Self-run backup + DR | Built into Nutanix |
| Deployment | Connector + SaaS | Appliances per site | Vault + local appliance | Agent + staging area | Your servers, your site | A second cluster |
| Workloads and target | vSphere in, VMC out | VMs to many clouds | Many in, Azure out | Any server, AWS out | Broad, to your site | Nutanix to Nutanix |
| Recovery point | Snapshots, 30 min | Seconds, by HPE | 5-minute points | Seconds, by AWS | CDP in seconds | Down to zero |
| Orchestration and tests | Plans, test or real | Plans, sandbox tests | Plans of 100 | Plans since Aug 2026 | Runbooks in Premium | Recovery plans |
| Failback | Failback plans | Reverse Protect | Physical comes back VM | Failback Client ISO | Documented failback | Documented failback |
| Pricing model | Per VM + per TiB | Per protected VM | Per instance, monthly | Per server-hour | Per workload (VUL) | Add-on to NCI |
| Published entry price | Not published | No list price | $25/instance/month | $0.028/server/hour | ~$350–450 reported | Quote only |
| Billed on top | VMC on AWS hosts | Target and journal | Storage and compute | Often 2× the fee | The DR site itself | Second cluster or NC2 |
| Ransomware defence | Clean room + scans | Encryption alerts | Copies what lands | Roll back a point | Immutable, scanned | Not covered here |
| India DR site | Mumbai; confirm | Wherever you target | Four Indian regions | Mumbai and Hyderabad | Your site; Vault India | Your second cluster |
| Support | Production support | HPE Tech Care | Paid plan from $29 | Paid AWS plan | 24/7, 1-hour Sev 1 | Ask with the quote |
| Lock-in and exit | VMware at both ends | Native VMs, Move | Azure is the exit | AWS is the exit | Portable VUL | Nutanix at both ends |
| Best fit | vSphere, no 2nd site | Seconds, many targets | Azure as the DR site | AWS as the DR site | Veeam shops, own site | Nutanix estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
VMware Live Recovery Cloud is one of 27 disaster recovery products TechBag carries. The Disaster Recovery guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (VMs you protect; IT staff-hour cost). Estimates model the staff time spent rebuilding VMs, hunting for a clean backup and re-entering lost work after an outage or ransomware attack, at an assumed 1.5 hours per VM a year, with 70% of it saved by off-site snapshots, recovery plans and a ready clean room. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Broadcom publishes no price for VMware Live Recovery Cloud and directs buyers to an account representative. It is sold per protected VM plus per protected TiB, with a minimum of 10 TiB in each region and 1 TiB steps after that, as a commit subscription charged upfront in USD that does not renew automatically. VMware Cloud on AWS hosts for recovery are billed separately, and overages are enforced. It is an add-on for VMware Cloud Foundation or vSphere Foundation customers; Broadcom shows no rupee price. TechBag sizes your VMs, TiB and hosts first, then quotes in INR with GST.
Counts every VM you protect
Best for a broader rollout
Counts the TiB you keep in the cloud
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Are all protected workloads vSphere VMs, with no vTPM, secure boot, Windows 11, RDM or shared disks among them?
Is 30 minutes of data loss acceptable, or do some VMs need seconds, which only continuous replication gives?
Is AWS Mumbai still open to new customers for your order, and is it written into the quote and contract?
Will you keep pilot-light hosts on VMC on AWS, or deploy on demand, and who pays for the hosts during a real event?
How many TiB will you protect in each region? The 10 TiB floor applies per region, and overages are enforced.
Who runs the clean-room analysis on the day, and which isolation level or custom firewall rules will they use?
Can the connector reach the cloud without a proxy, and does your network avoid the 10.68.97.0/28 proxy range?
Is the quote itemised by VM, TiB and term in USD, with INR and GST shown, and the renewal date in your calendar?
Check your VMs against Broadcom’s caveat list first, or let a TechBag advisor size VMs, TiB and VMware Cloud on AWS hosts together, confirm the Mumbai region and get the quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.