Start with the two numbers that define your requirement
Write these two targets down before comparing products. They determine the architecture and narrow the shortlist.
- RPO (Recovery Point Objective). How much data can you afford to lose? Nightly backups allow up to 24 hours of work to disappear; continuous replication reduces that window to minutes, at a higher price.
- RTO (Recovery Time Objective). How long can the service be down? Restoring 8 TB over a 500 Mbps link takes about 36 hours at theoretical line rate and longer in practice. A four-hour RTO therefore requires a local appliance or seeded recovery rather than cloud-only restore.
An RTO often gets shorter once the business prices a full day offline in revenue, payroll and reputation. Do that calculation first; it provides a more defensible budget than a feature list.
What matters when comparing platforms
Immutability and air gap
Ransomware operators may spend days inside a network before encryption and often target backup infrastructure first. If a domain administrator can delete every backup, the attacker can remove the main recovery path and gain substantial leverage.
Look for object-lock style immutability: once written, a backup cannot be modified or deleted by administrators or vendor support until its retention period expires. Ask whether the storage layer enforces that rule or whether it relies on application permissions. Storage-level enforcement is the version designed to survive a compromised admin account.
The 3-2-1-1-0 rule
The extended 3-2-1 rule is a useful checklist for ransomware recovery:
- 3 copies of your data
- 2 different media types
- 1 copy offsite
- 1 copy immutable or air-gapped
- 0 errors, verified by an actual test restore
The SaaS data gap
SaaS data is an easy gap to miss in a small or mid-sized organization. Microsoft and Google both use a shared responsibility model: they provide service availability while customers remain responsible for their data. Their documentation states this and recommends third-party backup.
Recycle bins and retention policies are not independent backups. They may not cover a departing employee’s deletions discovered four months later, ransomware that syncs encrypted files to OneDrive, or an admin error that removes a mailbox. Organizations using Microsoft 365 or Google Workspace should include dedicated SaaS backup in the recovery design.
Restore granularity and speed
Full-image restores may be rare; recovering one mailbox, file or database table is a more routine task. Check whether item-level recovery works without staging an entire image. Also verify whether "instant recovery" can run a VM from backup storage while the full restore streams in, a capability that can determine whether a four-hour RTO is achievable.
The pricing model, and what is not in it
Per-workload, per-TB and per-user pricing can produce very different bills for the same environment. Ask about the costs outside the headline rate:
- Egress and restore fees. Some providers charge nothing to restore; others charge per GB retrieved. A large recovery can therefore create an additional bill during an incident.
- API and retrieval charges on archive tiers. Cheap cold storage frequently has expensive retrieval and a minimum storage duration.
- Overage handling. Does exceeding your allowance stop backups, or silently bill you?
- Whether deduplication and compression are counted before or after when measuring your consumption.
The platforms and where each fits
The entries are grouped by buyer fit rather than treated as a universal ranking. Pricing is indicative list pricing as of August 2026 and changes frequently, so use it as a starting point and obtain a quote.
Veeam Data Platform
Best for mixed and hybrid estates
The broadest workload coverage in this comparison, spanning on-premises VMs, physical servers, cloud workloads and Microsoft 365.
Coverage is Veeam’s main advantage. VMware, Hyper-V, Nutanix, physical Windows and Linux, AWS, Azure, Google Cloud, Microsoft 365, Salesforce and Kubernetes are supported as first-class workloads. An estate spanning several of them can reduce operational fragmentation by consolidating on one platform.
Veeam also supports hardened Linux repositories, object lock on S3-compatible storage and mature instant recovery. That breadth brings complexity: it is a platform that needs an owner, and a small team without dedicated infrastructure staff may find it heavier than necessary.
Strengths
- The broadest workload coverage in the category
- Strong immutability options including hardened repositories
- Mature instant-recovery and granular restore
- Storage-agnostic, avoiding dependence on one cloud
Trade-offs
- Meaningful learning curve; expects a competent administrator
- Per-workload licensing gets complicated in mixed estates
- Self-managed deployments mean you own the backup infrastructure’s own resilience
Acronis Cyber Protect
Best all-in-one for small IT teams
Combines backup, endpoint security, patch management and disaster recovery in one agent and console for small teams with broad responsibilities.
One agent for backup, anti-malware and patching reduces deployment work and puts status in one console. For a two-person IT team supporting 150 staff, that consolidation may matter more than best-of-breed depth in each category.
The corresponding risk is concentration. Bundled security may not match a dedicated endpoint platform, and a compromise of one product can affect both backup and security. Evaluate the security component on its own merits rather than treating it as a free extra.
Strengths
- Backup, anti-malware and patching in a single agent
- Strong MSP tooling and multi-tenancy
- Straightforward for teams without deep backup expertise
- Flexible local and cloud storage combinations
Trade-offs
- Bundled security is not equivalent to a dedicated EDR platform
- Broad feature set means more surface area to configure correctly
- Consolidation concentrates risk in one vendor
Rubrik Security Cloud
Best for enterprise ransomware recovery
Built around the assumption that you will be attacked, with immutability by default, anomaly detection on backup data and tooling for identifying a clean recovery point.
Rubrik treats backup as a security control. Backups are immutable by design rather than by optional configuration, and the platform analyses backup data for encryption or mass deletion. That analysis helps identify which restore point is clean during ransomware recovery.
The capability comes with enterprise pricing. This is not positioned as a small-business product, and the evaluation should involve the security team as well as IT.
Strengths
- Immutable architecture rather than optional immutability
- Anomaly detection helps identify an uninfected recovery point
- Sensitive-data discovery supports compliance work
- Well-regarded for large-scale recovery orchestration
Trade-offs
- Enterprise pricing puts it out of reach for most SMBs
- A substantial platform that requires an implementation project
- Too costly and complex unless ransomware recovery is a board-level concern
Backblaze B2 + a backup client
Best value for storage-heavy workloads
Not a backup application but a storage back end, priced far below the hyperscalers and with no egress charge up to three times your average monthly stored data.
For organizations already running backup software, the storage bill is often the dominant cost, and B2 undercuts S3 substantially while remaining S3-compatible and supporting object lock for immutability. Veeam, MSP360, Restic, Duplicati and most other clients integrate with it directly.
The egress allowance matters because a large restore from a hyperscaler can cost more than a year of storage. B2 does not include a backup application or end-to-end recovery support, however. Your team selects the client, operates it and owns the restore process.
Strengths
- Substantially cheaper than hyperscaler object storage
- Free egress up to 3× average monthly stored data
- Object Lock immutability supported
- S3-compatible, so most backup clients work with it
Trade-offs
- Storage only; you still need to operate backup software
- Fewer regions than AWS, Azure or Google Cloud
- Support covers the storage layer, not your recovery outcome
Datto (Kaseya)
Best for MSP-delivered BCDR
A local appliance plus cloud replication, sold through managed service providers, with the fastest realistic RTO in this list because recovery starts on hardware already in your building.
The hybrid appliance addresses a short RTO directly. A failed server can be virtualised on the local Datto device in minutes, while the cloud copy supplies the offsite disaster-recovery layer. This model can fit a business that cannot tolerate a day of downtime but cannot fund a six-figure enterprise platform.
Datto is generally purchased through an MSP, so service quality depends heavily on that partner, and the local appliance still needs maintenance. Some customers have reported pricing and packaging changes since the Kaseya acquisition; raise both points during negotiation.
Strengths
- Local appliance enables recovery in minutes rather than hours
- Cloud replication provides the offsite copy automatically
- Well-established MSP channel with mature tooling
- Screenshot verification of backup bootability
Trade-offs
- Usually only available via a partner, not direct
- Hardware to buy, house and maintain
- Your outcome depends substantially on your MSP
Dedicated Microsoft 365 backup (Veeam, AvePoint, Dropsuite)
Best for a common SaaS coverage gap
A separate backup for Microsoft 365 or Google Workspace closes a common gap at a relatively low per-user cost.
Exchange Online, SharePoint, OneDrive and Teams data remains the customer’s responsibility under Microsoft’s shared responsibility model. Native retention protects against Microsoft losing data, but not every case of user deletion, attacker deletion or a sync client propagating encryption.
Microsoft now offers first-party backup and it belongs on the shortlist. Some organizations prefer a third party because a backup in the same tenant and under the same identity provider shares part of the production failure domain. At a few dollars per user per month, either route can close a large gap for modest cost.
Strengths
- Closes a genuine and widely underestimated gap
- Fast to deploy and inexpensive per user
- Item-level restore of mail, files, sites and Teams content
- Retains data beyond the license lifetime of departed staff
Trade-offs
- Another vendor and another bill
- Teams backup coverage varies notably between products and needs testing
- Restores into a live tenant need care to avoid duplicates
Comparison at a glance
| Platform | Best for | Immutability | Typical buyer |
|---|---|---|---|
| Veeam | Mixed/hybrid estates | Hardened repos, object lock | IT team with expertise |
| Acronis | All-in-one simplicity | Immutable cloud storage | Small IT team or MSP |
| Rubrik | Enterprise ransomware recovery | Immutable by architecture | Security-led enterprise |
| Backblaze B2 | Cheap storage layer | Object Lock | Team with its own software |
| Datto | Fast RTO via appliance | Cloud-side immutability | SMB buying through an MSP |
| M365 backup | The SaaS gap | Varies by vendor | Microsoft 365 customers |
Indicative positioning based on vendor documentation as of August 2026. Verify current capabilities and pricing directly because this category changes quickly.
Restore testing matters more than the shortlist
Test your restores. Quarterly, on a schedule, with someone other than the person who built the system doing it.
A backup job can report success while excluding a critical volume or writing to a repository nobody has proved readable. A restore drill finds that failure before an incident and answers three questions the dashboard cannot:
- Does the data come back intact? Do not stop at job status; open the restored database and run a consistency check.
- How long does it take? Measure the recovery and compare it with the committed RTO.
- Can someone else do it? If recovery depends on one person’s undocumented knowledge, you have a single point of failure that no amount of redundancy addresses.
A shortlist process that works
- Write down your RPO and RTO, and what an hour of downtime costs. Use those figures to assess the remaining choices.
- Inventory servers, endpoints, SaaS, databases and cloud workloads. SaaS is commonly missing from the first list.
- Shortlist two or three platforms that cover your actual mix without heavy add-ons.
- Run a proof of concept on real data. Restore something. Time it.
- Get restore costs, egress fees and support response times in writing before signing.
- Schedule the first restore drill for 90 days after go-live, and put it in the calendar now.
Frequently asked questions
Does Microsoft 365 back up my data?
Not in the sense you need. Microsoft operates a shared responsibility model: it guarantees service availability and protects against its own infrastructure failures, while your data remains your responsibility. Recycle bins and retention policies have limited windows and will not protect you from deletion, ransomware syncing encrypted files, or an admin error found months later. Microsoft’s own documentation recommends third-party backup.
What is immutable backup and do I need it?
Immutable backups cannot be modified or deleted until their retention period expires, including by an attacker, administrator or vendor. Because ransomware operators target backup infrastructure before encryption, immutability should be a core requirement.
How much should business cloud backup cost?
SaaS backup is typically $3–$8 per user per month. Server and workload backup varies enormously with data volume and retention. As a sanity check, most organizations land between 1% and 3% of their total IT budget. If a quote is far below that, check for excluded egress and restore charges.
How often should I test restores?
Quarterly at minimum, and after any significant infrastructure change. Test a full system restore at least annually, timed, with the results compared against your stated RTO. Have someone who did not build the system perform the drill.
Is cloud backup enough on its own, or do I need local backup too?
It depends on your RTO. Restoring several terabytes over a typical business internet connection takes many hours or days. If that is too slow, use a local copy for speed and a cloud copy for disaster recovery; this is the hybrid appliance model.
What is the 3-2-1-1-0 rule?
Three copies of your data, on two different media types, with one offsite, one immutable or air-gapped, and zero errors verified by an actual test restore. It is the 3-2-1 rule updated for ransomware, and it makes a useful audit checklist.