David Davis

  • RTO and RPO Benchmarks: What Recovery Targets Are Realistic?

    RTO and RPO Benchmarks: What Recovery Targets Are Realistic?

    Ask ten IT directors what their RTO is and most will quote a number from a business impact analysis written three budget cycles ago. Ask how long the last full restore actually took, and the room goes quiet. Industry surveys have repeatedly found that a majority of organizations — around 60% in recent studies — need six hours or more to complete a full restore, while only about 5% finish inside an hour. That gap between the declared number and the tested number is where DR programs fail audits, and it is where this brief starts.

    Below: a clean tier-by-tier benchmark table for RTO and RPO targets as of mid-2026, an honest mapping of which technology actually delivers each tier — Zerto, Veeam, and Rubrik each earn a place, and each has limits — and the diagnostics to tell whether your declared targets are real or fiction.

    The benchmarks: four recovery tiers, as of mid-2026

    Most published tier models are either vendor marketing or academic. Here is the version I use when a client asks what “realistic” means. These are targets that well-run enterprises actually hit in tested recoveries — not aspirational numbers for the audit binder.

    WorkloadsRTO targetRPO targetTechnology that delivers itRelative cost
    Tier 1 — Mission-criticalPayments, order capture, EHR, trading, identityUnder 15 minutes1–5 minutes (seconds achievable)Journaled CDP replication; active-active where justified~10x Tier 2
    Tier 2 — Business-criticalERP, core databases, key line-of-business apps1–4 hours15–60 minutesSnapshot-based replication plus frequent backup~10x Tier 3
    Tier 3 — ImportantInternal apps, file services, collaboration4–24 hours4–24 hoursStandard backup with instant-VM recoveryBaseline backup spend
    Tier 4 — DeferrableArchives, dev/test, reporting24+ hours24 hours or moreStandard backup, cold or cloud tierLowest

    Two rules make this table useful. First, the tier is defined by the business cost of downtime, not by what the application team wants — everyone believes their app is Tier 1 until they see the invoice. Second, RTO and RPO travel together: a sub-15-minute RTO paired with a 24-hour RPO means you will be back online quickly with yesterday’s data, which for a payments platform is not recovery at all.

    The reality gap: declared RTOs are fiction without testing

    The survey math deserves a second look. If roughly 60% of organizations need six-plus hours for a full restore and only about 5% finish under an hour, then most of the sub-one-hour RTOs written into DR plans are unfunded promises. The declared number describes the technology the organization wishes it had bought.

    The failure modes are consistent. Restore throughput is measured against a single VM, then extrapolated to 400. Dependencies — DNS, identity, load balancers — are not in the runbook, so the application is “restored” but nobody can log in. And the plan has never been exercised end to end, because a full failover test is disruptive and nobody wants to own the outage. The fix is procedural, not technical: a tested tier assignment beats an ambitious untested one every time. I covered how often each tier should be exercised, and what DORA now requires of financial entities, in our brief on DR testing cadence.

    The takeaway for the meeting: an RTO that has never been demonstrated in a test is a hypothesis, and the board should hear it described that way.

    Matching technology to tier: Zerto, Veeam, Rubrik

    Vendors will happily sell you Tier 1 technology for Tier 3 workloads. Mapping honestly saves seven figures at renewal.

    Zerto: the Tier 1 specialist

    Zerto, now sold as HPE Zerto Software, built its reputation on journal-based continuous data protection: every write is replicated and logged, so you can rewind to a checkpoint seconds before corruption hit. For genuine Tier 1 workloads — where a five-minute RPO is a requirement, not a preference — journaled CDP is the honest answer, and Zerto remains the reference implementation. The 10.9 release (May 2026) added cross-hypervisor replication between VMware and HPE VM Essentials, which matters if Broadcom pricing has you planning a hypervisor exit for part of the estate. The limits are equally clear: per-VM licensing makes it expensive to spread across the whole environment, and it is a replication-first product — most shops still pair it with a separate backup platform for long-term retention. Fit: your top 5–10% of workloads, not your standard.

    Veeam: the Tier 2–3 workhorse

    Veeam Data Platform v13, shipped in November 2025, is where most of the market lives. Instant VM recovery boots workloads directly from backup storage in minutes — degraded performance until storage migration completes, but running — which is what makes a 1–4 hour Tier 2 RTO achievable from backup infrastructure rather than replication. v13 added instant recovery into Azure with a cleanroom validation step and made backups immutable by default, both of which harden the ransomware case. Veeam’s strengths are breadth of workload coverage and cost per protected VM; its CDP capability exists but is younger and narrower than Zerto’s journaling, and instant-recovery performance depends heavily on the repository hardware underneath it. Fit: the 70–80% of the estate sitting in Tiers 2 and 3.

    Rubrik: when the threat model is ransomware, not floods

    Rubrik Security Cloud approaches the same problem from the security side: an immutable filesystem, anomaly detection on backup data, and threat hunting inside recovery points so you restore a clean copy instead of reinfecting yourself. Through 2025 it kept widening coverage — Okta recovery, PostgreSQL, Red Hat OpenShift Virtualization, Azure DevOps and GitHub repositories. The trade-offs: RPOs are bounded by snapshot frequency, so it is not a CDP play and will not deliver Tier 1 minute-level RPOs, and its pricing sits at the premium end of the backup market. Fit: security-driven Tier 2 and Tier 3 estates where the recovery scenario you actually rehearse is a cyberattack, and where paying more for forensic confidence is defensible. In a ransomware event, RTO includes the time spent proving the restore point is clean — Rubrik’s bet is that this is where the hours actually go, and the survey data on six-hour restores suggests the bet is reasonable.

    Diagnostics: where you actually stand

    Run your current plan against these thresholds:

    • Declared RTO under 1 hour, recovery method is backup restore: you do not have a Tier 1 plan, you have a Tier 1 label. Either fund CDP replication for those workloads or re-tier them honestly.
    • Last tested restore took more than 2x the declared RTO: re-tier or re-platform. The gap will not close by itself, and an auditor will find it before you do.
    • Claimed RPO under 15 minutes on nightly backup: arithmetic says no. Your real RPO is up to 24 hours; write that down or change the technology.
    • No full-scale restore test in the last 12 months: assume you are in the six-plus-hour majority regardless of what the plan says, and schedule the test before the renewal conversation.
    • Recovery copies all live on the same platform or site: your RTO is hostage to a single failure domain — the 3-2-1-1-0 rule exists precisely because restore speed means nothing if the copy you need is encrypted alongside production.

    The cost curve: every tier jump costs an order of magnitude

    The dirty secret of recovery tiers is the pricing curve. Moving a workload from Tier 3 backup to Tier 2 snapshot replication roughly triples to ten-times the protection cost — replica storage, WAN bandwidth, orchestration licensing. Moving from Tier 2 to Tier 1 CDP does it again: journal storage, per-VM replication licensing, and in many designs a warm second site or reserved cloud capacity that sits idle waiting for a disaster. As of mid-2026, list pricing varies too much to quote responsibly, but the shape holds across vendors: each tier jump is an order of magnitude, which is exactly why “everything is Tier 1” is a budget request, not a strategy.

    For organizations that cannot fund a second site, DRaaS has become the middle path — Tier 1-adjacent RTOs at a subscription price, with trade-offs we priced out in our DRaaS pricing brief. The discipline that matters is the ratio: if annual protection cost for a workload exceeds the cost of the outage it prevents, the workload is over-tiered. Most enterprises that run this math for the first time move 20–30% of their “critical” list down a tier and fund proper CDP for the handful that genuinely need it.

    Frequently asked questions

    What is a realistic RTO for most businesses?

    For the bulk of the application estate, 4–24 hours is realistic on standard backup infrastructure with instant-recovery features. Sub-hour RTOs are realistic only for workloads protected by replication or CDP — and only if the failover has been tested end to end, dependencies included.

    Can you achieve zero RPO?

    Effectively, yes — synchronous replication and journaled CDP can hold data loss to seconds or less. But true zero RPO requires synchronous writes, which imposes distance and latency limits and roughly doubles infrastructure cost. Most Tier 1 programs settle for near-zero RPO via asynchronous CDP and spend the savings on testing.

    Is a lower RTO always better?

    No. Every hour you shave off an RTO costs progressively more, and past a certain point the spend exceeds the downtime cost it avoids. The right RTO is the one where protection cost and outage cost cross — for many internal workloads that crossover sits comfortably at 12–24 hours.

    How often should RTO and RPO targets be tested?

    Tier 1 workloads: quarterly failover tests at minimum. Tier 2: twice a year. Everything else: an annual full restore test. Regulated industries increasingly have this dictated for them — DORA in particular has turned testing cadence from best practice into obligation for financial entities operating in the EU.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.

  • vSphere 8 Support Ends October 2027: Your Decision Timeline

    vSphere 8 Support Ends October 2027: Your Decision Timeline

    October 11, 2027. That is the date vSphere 8 hits End of General Support — five years after its October 2022 GA, per Broadcom’s standard lifecycle policy. It sounds comfortably far away until you do the arithmetic the other direction: Gartner has pegged comprehensive VMware migration programs at 18 to 48 months, and even a disciplined in-place platform upgrade across a large estate eats two to four quarters. Run that math backward from October 2027 and the pay-or-leave decision is not due next year. It is due now, in 2026 — and most of the IT teams I talk to have not internalized that.

    This brief lays out the three options — upgrade to VCF 9, buy extended support, or execute an exit — with the dates, the cost signals, and a quarter-by-quarter timeline you can hold your team to.

    What changed

    Three facts define the situation. First, vSphere 8’s End of General Support date is October 11, 2027 — after that, no patches, no security fixes, no support tickets under standard terms. Second, vSphere 8 was the last VMware release you could hold on a perpetual license. Everything forward is subscription, on Broadcom’s terms, and those terms moved again in 2025 when the per-CPU licensing minimum jumped from 16 to 72 cores. Third, the destination Broadcom wants you at is VMware Cloud Foundation 9, which went GA in June 2025.

    Here is the part teams underestimate: VCF 9 is not a version bump. Practitioners who have run the upgrade describe it as an infrastructure redesign — it restructures how storage, networking, and operations tooling fit together, folding vSAN, NSX, and the Aria-era management stack into a single opinionated platform. Upgrade paths are constrained, too: getting to the current 9.x releases requires specific source versions, so estates on older VCF or standalone vSphere builds face a multi-hop sequence, not one maintenance window. If you budgeted this as “another vSphere upgrade,” you budgeted it wrong.

    Why it matters

    Because every option takes longer than the calendar suggests. An exit to another hypervisor at enterprise scale runs 18 to 48 months when you count discovery, procurement, pilot, migration waves, and the operational retraining nobody budgets for. A VCF 9 adoption at scale is realistically 6 to 12 months of design and execution. And the money has its own clock: FY2027 budgets get locked in during 2026 planning cycles. If the line item is not in the budget you are building right now, you have already chosen — you have chosen to pay whatever the renewal costs, from a position of zero leverage. Broadcom’s negotiators know exactly where October 2027 sits on your calendar; the honest framing is in our companion brief on negotiating a Broadcom VMware renewal.

    The takeaway a VP can repeat in a meeting: the deadline is October 2027, but the decision deadline is Q4 2026. Miss the second one and the first one gets expensive.

    Option 1: Upgrade to VCF 9 and stay with Broadcom

    The case for staying is real. VMware’s platform remains the most feature-complete virtualization stack in the market, your operations team already knows it, and the ecosystem of backup, monitoring, and DR tooling around vSphere is unmatched. For estates deep in vSAN and NSX, VCF 9 genuinely consolidates what used to be four products’ worth of lifecycle management. If you are running thousands of VMs with hard availability SLAs and heavy VMware-specific automation, staying is often the lowest-risk path.

    The case against is the cost structure and the loss of optionality. You are trading perpetual licenses you own for a subscription priced per core, with a 72-core minimum per CPU that punishes smaller hosts, and you are buying the full VCF bundle whether or not you want NSX and Aria. List pricing varies by commitment, but budget for a multiple of your old maintenance spend — the renewal shocks documented since 2024 have run from 2x to well past 5x. The full picture is in our brief on VMware licensing changes in 2026. Who it fits: large, VMware-native estates where migration risk outweighs subscription cost, and organizations that can negotiate multi-year terms before their leverage evaporates.

    Option 2: Buy extended support and rent time

    Broadcom has historically offered paid extended support past End of General Support, typically sold per year at a premium over standard support — as of mid-2026, expect it to be offered, priced to discourage, and capped at roughly two years of runway. Understand what it is: security patches and break-fix, no new features, no certification of new hardware. It is a bridge, not a destination.

    Used well, extended support is the tool that turns a panicked 2027 migration into an orderly 2028 one. Used badly, it is an annual tax on indecision. The test is simple — if you have a signed migration plan with dated waves, buying a year of extended support is rational insurance. If you are buying it because the decision meeting keeps slipping, you are paying premium rates to avoid a conversation. Who it fits: organizations mid-exit whose migration waves genuinely cannot finish by October 2027, and regulated shops with change-freeze calendars that make a 2027 cutover reckless.

    Option 3: Execute an exit

    The two exit destinations that come up in nearly every evaluation are Nutanix and Proxmox, and they sit at opposite ends of the market.

    Nutanix AHV: the enterprise landing zone

    Nutanix offers the closest thing to feature parity with vSphere — HA, live migration, integrated storage, DR orchestration, and a mature management plane in Prism. Its Move tool automates VMware-to-AHV migrations with replication-based cutover, which materially shortens migration waves, and mainstream backup vendors support AHV natively. The honest caveat: Nutanix is premium-priced. You are trading one enterprise vendor for another, and if your exit is purely about cost you may be disappointed at quote time — the savings versus VCF are real but usually not dramatic. Where Nutanix wins is operational simplicity for hyperconverged estates and a vendor relationship that currently wants your business. Who it fits: enterprises above roughly 200 VMs that need support SLAs, want a supported migration path, and are exiting for predictability as much as price.

    Proxmox VE: the open-source counterweight

    Proxmox VE, built on KVM and LXC, has moved from homelab favorite to a credible enterprise contender, with a native VMware import wizard since version 8.1 and support subscriptions that cost a fraction of any commercial hypervisor. Clustering, HA, live migration, and integrated backup are all in the box. The honest caveats: management tooling at very large scale trails vCenter, the third-party ecosystem is thinner (though Veeam now supports it), and support is subscription-based European-business-hours engineering, not a global TAC. Who it fits: Linux-capable teams, estates under a few hundred hosts, edge and branch deployments, and organizations for whom the licensing line item is the whole point. Our full ranking is in VMware alternatives for 2026.

    VCF 9 (Broadcom)Extended supportExit (Nutanix / Proxmox)
    Decision deadlineQ4 2026 (renewal leverage)Mid-2027 at the latestQ3–Q4 2026
    Execution time6–12 monthsWeeks (contractual)18–48 months full program
    Cost signalMultiple of legacy maintenancePremium over standard, per yearNutanix: moderate savings; Proxmox: large savings
    Best fitLarge VMware-native estatesMid-exit or change-frozen orgsCost-driven or leverage-seeking estates
    Main riskLock-in, future price risesPaying to defer, not decideMigration effort, ops retraining

    The backward-planned timeline

    Plan backward from October 11, 2027, and the quarters assign themselves:

    • Q3 2026 (now): Inventory the estate — hosts, cores, VMware-specific dependencies (vSAN, NSX, SRM, vendor appliances). Get budget placeholders into FY27 planning for both the stay and leave scenarios.
    • Q4 2026: Decision quarter. Run pilot workloads on at least one alternative, get real quotes from Broadcom and one challenger, and put a signed direction in front of leadership. This is also your maximum-leverage renewal window.
    • Q1–Q2 2027: Execute the first migration waves or the VCF 9 design-and-upgrade sequence. Staying put should mean upgrade runbooks tested in a non-production pod by Q2.
    • Q3 2027: Bulk migration waves or production VCF cutover. Anything still undecided here should trigger an extended-support purchase — deliberately, not by default.
    • Q4 2027: vSphere 8 is out of general support. Whatever remains on it is now technical debt with a meter running.

    What to do about it

    Three moves, in order. One: treat Q4 2026 as the real deadline and put the decision meeting on the calendar this month — with the estate inventory as pre-read. Two: price all three options for your actual core counts, because the 72-core minimum and bundle composition change the math in ways a spreadsheet from 2023 will not predict. Three: whichever way you lean, run a pilot on an alternative anyway — a working Nutanix or Proxmox proof of concept is worth double-digit percentages in a Broadcom negotiation, even if you ultimately stay.

    The short version: October 2027 is not the deadline. It is the consequence. The deadline is this fiscal year.

    Frequently asked questions

    When does vSphere 8 support end?

    vSphere 8 reaches End of General Support on October 11, 2027 — five years after its October 11, 2022 GA under the standard lifecycle policy. Technical Guidance typically extends about two years beyond that, but without patches or new bug fixes.

    Can I keep running vSphere 8 after October 2027?

    Technically yes — the software keeps running. But you lose security patches and support entitlement, which most security frameworks and auditors treat as a compliance finding. For internet-adjacent or regulated workloads, running an unsupported hypervisor is a risk most CISOs will not sign off on.

    Do I have to move to VCF 9, or can I buy vSphere on its own?

    Broadcom’s packaging as of mid-2026 centers on VCF for enterprise estates, with vSphere Foundation as the slimmer tier. Standalone perpetual vSphere is gone — vSphere 8 was the last perpetually licensed release, so any forward path with Broadcom is a subscription.

    How long does a VMware exit actually take?

    Gartner’s range for comprehensive migration programs is 18 to 48 months. Small, simple estates with tools like Nutanix Move or the Proxmox import wizard can finish in one to two quarters; large estates with NSX, SRM, and deep automation sit at the long end.

    Is extended support available for vSphere 8?

    Broadcom has historically sold extended support past end-of-support dates, priced per year at a premium. Terms are negotiated, not published — treat it as available but expensive, and as bridge financing for a migration already in motion, not a strategy.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.

  • Rubrik vs Cohesity in 2026: Two Cyber-Resilience Playbooks

    Rubrik vs Cohesity in 2026: Two Cyber-Resilience Playbooks

    In December 2024, Cohesity closed its acquisition of Veritas’ enterprise data protection business and became the largest data-protection software vendor in the world — roughly $1.7 billion in combined revenue, as of the companies’ own figures. Then in June 2026 it bought Stone Ram, a small UK firm whose Tranzman tooling exists for one purpose: moving NetBackup estates onto other platforms without the original backup software. That second deal tells you everything about where this market is going. “Cohesity” no longer means a product. It means a portfolio — and if you are comparing it against Rubrik in 2026, you need that decoded before you sign anything.

    This brief covers what actually separates the two platforms, where each one earns its keep, where each one will frustrate you, and what NetBackup customers — the people googling this hardest right now — should do at renewal.

    The verdict

    Pick Rubrik when security leads the purchase. If your CISO co-owns the decision, if you want a single product with a single SaaS control plane, and if a vendor-managed, logically air-gapped vault matters more to you than infrastructure consolidation, Rubrik is the cleaner story. Pick Cohesity when scale and breadth lead. If you are consolidating backup, file services, and dev/test copies onto one platform, if you need to restore hundreds of VMs at once after a wide-blast ransomware event, or if you already run NetBackup, Cohesity’s portfolio fits more of your estate. Neither choice is wrong. The mistake is buying one vendor’s story while your actual requirements match the other’s.

    What changed

    Two things reshaped this comparison since 2024. First, the Veritas merger made Cohesity a two-flagship company: DataProtect (its original scale-out backup software) and NetBackup (the most widely deployed enterprise backup product of the last two decades) now live under one roof, with Helios positioned as the unified management plane across both. Cohesity has said publicly that NetBackup customers will not be forced to migrate, and that both products remain supported and on active roadmaps.

    Second, the June 2026 Stone Ram acquisition put real machinery behind the migration path. Tranzman recovers and moves backup data without needing the original backup application, and Cohesity claims it can cut migration and upgrade time by as much as 75 percent. Read that plainly: the “no forced migration” promise stands, but Cohesity is now investing in making the NetBackup-to-DataProtect move as frictionless as possible. That is a roadmap signal, and buyers should treat it as one.

    Rubrik spent the same period sharpening a different blade. It has repositioned entirely as a cyber-resilience company — anomaly detection, threat hunting inside backup data, sensitive-data discovery, and identity recovery for Active Directory and Entra ID, all delivered through Rubrik Security Cloud. Gartner named it a Leader in the 2026 Magic Quadrant for Backup and Data Protection Platforms, positioned furthest in vision. The two vendors are no longer running the same race at different speeds. They are running different races.

    Side-by-side comparison

    RubrikCohesity
    Core architectureAtlas — append-only, immutable filesystem; backups never exposed over writable NFS/SMBSpanFS — distributed scale-out filesystem consolidating backup, files, and objects
    Control planeRubrik Security Cloud (SaaS)Helios / Cohesity Data Cloud, being unified across DataProtect and NetBackup
    Isolated vaultRubrik Cloud Vault — vendor-managed, logically air-gapped, immutableFortKnox — SaaS cyber vault with virtual air gap
    Ransomware toolingAnomaly detection, Threat Hunting and Turbo Threat Hunting, sensitive-data discoveryDataHawk threat protection, anomaly detection, Gaia AI-assisted search
    Mass recoveryOrchestrated recovery, strong per-workload granularityInstant Mass Restore — hundreds of VMs concurrently from SpanFS snapshots
    NetBackup pathCompetitive replacement onlyNative — Helios management plus Stone Ram/Tranzman migration tooling
    Gartner Peer Insights (mid-2026)4.7 across ~776 reviews4.8 across ~1,330 reviews

    Where Rubrik wins

    Rubrik’s advantage is architectural coherence in service of one job: surviving an attack. The Atlas filesystem is append-only, which means ransomware — or a compromised admin credential — has no write path to your snapshots. That is a stronger default posture than immutability bolted on as a feature flag. Rubrik Cloud Vault extends it off-site as a fully managed service, so the isolated copy exists even if your entire on-prem environment is owned. If you are evaluating vault architectures across vendors, our cyber recovery vault comparison breaks down how these isolation models actually differ.

    The threat-hunting story is genuinely differentiated. Turbo Threat Hunting scans backup metadata using pre-computed hashes rather than crawling files, and Rubrik claims internal testing found clean recovery points across 75,000 backups in about a minute. Treat vendor benchmarks as vendor benchmarks — but the design approach is sound, and finding a clean restore point fast is the single most underrated variable in real ransomware recovery. Add identity resilience for AD and Entra ID, and Rubrik covers the two things attackers actually target first: your directory and your backups.

    Where Cohesity wins

    Cohesity’s advantage is scale — in three senses. First, technical scale: SpanFS was built as a general-purpose distributed filesystem, so one cluster consolidates backup, file shares, object storage, and dev/test data copies. If your storage team wants fewer platforms, that consolidation is real money. Second, recovery scale: Instant Mass Restore brings back hundreds of VMs concurrently because SpanFS serves them directly from snapshots. After a wide-blast encryption event, the difference between restoring 40 VMs at a time and 400 is the difference between a bad week and a bad quarter.

    Third, market scale. Post-Veritas, Cohesity has the largest install base and the broadest workload coverage in the industry — NetBackup’s workload matrix remains unmatched for legacy and exotic enterprise systems. FortKnox gives it a credible SaaS vault answer to Rubrik Cloud Vault, and the Peer Insights numbers — 4.8 across roughly 1,330 reviews versus Rubrik’s 4.7 across roughly 776, as of mid-2026 — suggest the customer base is not merely large but satisfied. For NetBackup shops, Cohesity is the only vendor offering continuity and modernization in the same contract.

    Honest downsides, both sides

    Rubrik’s costs run high. List pricing varies by capacity and edition, but Rubrik is rarely the cheap option in a three-way bake-off, and capacity-based subscription costs compound as data grows. It is also not a consolidation play — you are buying a security and recovery platform, not a general-purpose storage layer, so the “fewer platforms” argument goes to the other side. Its review base is smaller, and shops that just want boring, inexpensive backup may find themselves paying for a security posture they never operationalize.

    Cohesity’s risk is the merger itself. Running two flagship backup products while unifying management planes and, eventually, filesystems is one of the hardest integration jobs in enterprise software, and roadmap ambiguity is the tax customers pay while it happens. Helios unification across DataProtect and NetBackup is still in progress. And even with Tranzman, a NetBackup migration is a project with real risk, not a button. Buyers should also remember that “no forced migration” is a promise about today’s roadmap, not a contractual term — unless you make it one.

    What to do about it

    If you run NetBackup: do not panic, but do use the moment. Your renewal is leverage. Ask Cohesity for the Helios unification timeline and the NetBackup support horizon in writing, request a Tranzman-based migration assessment even if you never intend to move, and get a competing Rubrik quote to price-check the renewal. The worst position is renewing for three years without asking any of those questions.

    If you are buying fresh: run a recovery bake-off, not a backup bake-off. Measure time-to-clean-recovery for your top 20 applications — including the time to find an uninfected restore point — and make each vendor demonstrate it live. My rule of thumb: if you cannot demonstrate clean recovery of your critical applications inside 24 hours, that gap matters more than any feature on either datasheet. And widen the field before you narrow it — our Veeam vs Rubrik and Commvault vs Veeam briefs cover the adjacent matchups most shortlists should include.

    The takeaway for the meeting: Rubrik sells a security platform that does backup; Cohesity sells a data platform that does security. Buy the one that matches who is signing the check.

    Frequently asked questions

    Is Cohesity better than Rubrik?

    Neither is categorically better. Cohesity leads on consolidation, mass-restore scale, and workload breadth, and holds a slight Peer Insights edge — 4.8 versus 4.7 as of mid-2026. Rubrik leads on security architecture, threat hunting, and its managed cloud vault. Match the platform to whether security or infrastructure owns the purchase.

    What does the Cohesity-Veritas merger mean for NetBackup customers?

    NetBackup remains supported with an active roadmap, and Cohesity says migration to DataProtect is optional. Helios is becoming the common management plane, and the Stone Ram acquisition adds tooling that Cohesity claims cuts migration time by up to 75 percent. Get support horizons in writing at renewal.

    Will Cohesity force NetBackup customers to move to DataProtect?

    Cohesity has stated publicly that it will not force migrations and will keep selling and supporting both products. The Stone Ram deal signals it wants the move to be easy, not mandatory. Treat the promise as a roadmap statement and negotiate contractual support commitments if NetBackup continuity is critical to you.

    What is the main architectural difference between Rubrik and Cohesity?

    Rubrik’s Atlas filesystem is append-only and purpose-built so backup data can never be modified in place, prioritizing attack survival. Cohesity’s SpanFS is a general-purpose distributed filesystem that consolidates backup, files, and objects on one scale-out cluster, prioritizing platform consolidation and restore concurrency.

    Is Rubrik worth the cost?

    For organizations where a ransomware event is a board-level risk and the CISO is involved in data-protection decisions, usually yes — the immutability, threat hunting, and managed vault reduce real recovery risk. For cost-driven shops that only need dependable backup, cheaper options exist and the premium is harder to justify.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.

  • The 3-2-1-1-0 Backup Rule: How to Actually Implement It

    The 3-2-1-1-0 Backup Rule: How to Actually Implement It

    Veeam’s ransomware research found that attackers went after backup repositories in 96% of incidents — and got to them roughly three times out of four. Organizations whose backups were compromised faced recovery costs around eight times higher than those whose backups survived. That gap is the entire argument for the 3-2-1-1-0 backup rule. The old 3-2-1 rule assumed your backups fail by accident. The two new digits assume they fail because someone with domain admin credentials wanted them to.

    This guide maps each digit to a real 2026 implementation — not the whiteboard version. The short version: the “+1” means an immutable copy an attacker cannot alter even with your credentials, the “0” means recovery you have actually verified, and immutability is not the same thing as an air gap, no matter how many vendor decks conflate the two.

    What the digits actually require

    Requirement2026 implementation
    3Three copies of the dataProduction + primary backup + a copy job to a second target
    2Two different media or platformsDisk repository plus object storage, tape, or a different failure domain — not two LUNs on one array
    1One copy offsiteCloud object storage, a second data center, or a managed vault
    +1One copy immutable or air-gappedS3 Object Lock in compliance mode, a hardened appliance, or offline tape
    0Zero errors on verified recoveryAutomated restore testing — Veeam SureBackup, Rubrik recovery validation, or scripted sandbox restores

    The takeaway for the meeting: 3-2-1 protects you from hardware and human error; the +1 protects you from an attacker; the 0 protects you from your own untested assumptions. Most shops I talk to have the first three digits and neither of the last two.

    3-2-1: the part you probably already do

    Three copies, two media, one offsite has been table stakes since tape libraries were the interesting part of the data center. Two honest checks are still worth running. First, “two media” means two failure domains — a backup repository sitting on the same SAN as production, or in the same vSphere cluster, is one ransomware event away from being zero copies. Second, “offsite” must mean a separate administrative domain, not just separate geography. A DR site joined to the same Active Directory forest with the same admin credentials fails exactly when you need it. If your offsite copy can be deleted from the same console that manages production backups, you have distance, not separation.

    The +1: immutable is not air-gapped

    Most content ranking for this term treats “immutable” and “air-gapped” as synonyms. They are different controls with different failure modes, and a mature program eventually wants both.

    Immutability is a software or firmware guarantee that written data cannot be modified or deleted for a retention window — S3 Object Lock in compliance mode is the reference implementation. It is online, fast to restore from, and cheap to operate. Its weakness is that it is only as strong as the platform enforcing it: governance-mode locks that privileged accounts can lift, retention windows set shorter than attacker dwell time, or a storage admin account that can destroy the whole bucket’s account-level container. Compliance mode, MFA on the storage plane, and retention at least as long as your threat-hunting lookback are the minimum bar.

    An air gap is a network or physical separation — offline tape, removable media, or storage that is only reachable during controlled windows. It survives platform compromise entirely, but restores are slow, testing is awkward, and “logical air gaps” that amount to a firewall rule deserve skepticism. Verdict: run immutable object storage as your working +1, and add a true offline copy for the crown-jewel 5–10% of data where a multi-week outage is existential. If you can restore from it in minutes, it is not an air gap — and that is fine, as long as you stop calling it one.

    Building the immutable copy: Veeam, Object First, Wasabi, Rubrik

    Four approaches dominate the conversations I see in mid-market and enterprise accounts. They are not interchangeable.

    Veeam: assemble the stack yourself

    Veeam Data Platform gives you three routes to the +1: a hardened Linux repository with immutability flags, direct-to-object backups against any Object Lock-capable S3 target, and Veeam Data Cloud Vault, its managed cloud storage with immutability and egress bundled into a flat per-terabyte price. SureBackup covers the 0 by booting workloads in an isolated lab and running verification tests. Strengths: flexibility and the largest ecosystem of Veeam Ready storage targets. The honest downside is that Veeam sells you the software and the responsibility — a hardened repo is only hardened if your team actually locks down SSH, patches the box, and resists the temptation to join it to the domain. The 96%-of-attacks statistic comes from Veeam’s own incident research; the company is clear-eyed that its customers’ repositories are the target.

    Object First: turnkey on-prem immutability for Veeam shops

    Object First’s Ootbi appliance exists to remove that operational burden. It is S3 Object Lock storage that ships immutable by default with a zero-access design — no root shell for an attacker to find, no immutability toggle for a rushed admin to disable. As of mid-2026 the appliance line spans roughly 20 TB to 432 TB per node and clusters into the petabyte range, with ingest fast enough to serve as the primary backup target, not just a copy tier. The fit is narrow and deliberate: Ootbi only speaks Veeam. If you run Commvault or Rubrik alongside, it does nothing for those workloads, and you are paying appliance margins over commodity disk. For a Veeam shop that wants on-prem immutability without a hardening project, it is the shortest path.

    Wasabi: the cheap immutable offsite tier

    Wasabi’s pitch is economic: hot cloud object storage with full Object Lock support, Veeam Ready certification for immutability, flat per-terabyte list pricing, and no egress fees — which matters enormously the day you restore 200 TB in anger. It is an excellent answer for the “1 offsite” and “+1 immutable” digits in a single move. The limits: Wasabi is storage only, so restore speed is bounded by your internet pipe, and minimum-retention billing means churny short-retention jobs cost more than the headline rate suggests. Model your restore-time math before you rely on it as the only immutable copy; our backup storage cost-per-TB analysis runs those numbers across the major targets.

    Rubrik: immutability as architecture

    Rubrik takes the opposite approach from the assemble-it-yourself model: its append-only filesystem is immutable by design, not by configuration, so there is no setting to get wrong. Rubrik Security Cloud layers on anomaly detection, threat hunting across backup history, and orchestrated recovery validation — effectively bundling the +1 and the 0 into the platform. The trade-offs are real: it is a platform replacement rather than a bolt-on, pricing sits at the premium end, and you are committing to one vendor’s stack for backup, immutability, and security analytics together. For organizations that want the rule enforced by architecture rather than by process discipline, that bundle is exactly the point.

    For a deeper side-by-side of these targets — including hardened repos, tape, and the hyperscaler options — see our immutable backup storage comparison.

    The 0: verified recovery, not green checkmarks

    A successful backup job proves data was written. It proves nothing about whether the application boots, the database mounts, or the restore completes inside your RTO. The 0 digit demands automated, scheduled verification: Veeam SureBackup boots VMs in an isolated network and runs heartbeat, ping, and custom application tests; Rubrik and others offer equivalent recovery validation and clean-room recovery workflows. The benchmark I hold clients to: every tier-1 workload restore-tested at least quarterly, automated verification running weekly, and at least one full DR exercise a year that the infrastructure team does not schedule themselves. If your last full restore test predates your last major hire, you do not have a 0 — you have a hope. Regulated shops should map this cadence to their obligations; our DR testing cadence guide for DORA covers what supervisors now expect in writing.

    What to do about it

    • This month: inventory which digits you actually have. Check every immutability setting — compliance mode or it does not count. Verify the backup platform has its own identity plane, separate credentials, MFA everywhere.
    • This quarter: stand up one genuinely immutable copy — Object Lock bucket, Ootbi node, hardened repo, or a managed vault — and set retention longer than 30 days, since attacker dwell time routinely exceeds short lock windows.
    • This half: automate recovery verification for tier-1 workloads and put the results in front of leadership monthly. The 0 is a reporting artifact as much as a technical one.
    • Ongoing: add an offline or truly isolated copy for existential data, and rehearse restoring from it once a year.

    The rule is cheap insurance against an expensive certainty. Attackers already treat your backups as the primary target; 3-2-1-1-0 is simply the posture that assumes they will.

    Frequently asked questions

    What is the 3-2-1-1-0 backup rule?

    Keep three copies of your data on two different media with one copy offsite, plus one copy that is immutable or air-gapped, and verify recovery with zero errors. The last two digits extend the classic 3-2-1 rule for ransomware, where attackers deliberately destroy backups before encrypting production.

    Is an immutable backup the same as an air-gapped backup?

    No. Immutability is a software guarantee that data cannot be changed or deleted during a retention window; an air gap is physical or network isolation. Immutable storage is online and fast to restore from but depends on the platform enforcing it. An air gap survives platform compromise but restores slowly. Mature programs use immutable storage as the working copy and reserve a true offline copy for critical data.

    Does the 3-2-1 rule still apply in the cloud?

    Yes, and SaaS data counts too. A cloud workload backed up to the same cloud account is one compromised credential away from total loss. Cross-account or cross-provider copies with Object Lock — for example, Veeam writing to Wasabi or to Veeam Data Cloud Vault — satisfy the offsite and immutable digits without a second data center.

    How often should backups be tested?

    Automated verification weekly, restore tests for tier-1 workloads at least quarterly, and a full DR exercise annually. Tools like Veeam SureBackup or Rubrik’s recovery validation make the weekly cadence practical by booting and testing workloads automatically in an isolated environment.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.

  • Microsoft 365 Backup: What Microsoft Covers — and What It Won’t

    Microsoft 365 Backup: What Microsoft Covers — and What It Won’t

    “Does Microsoft back up my data?” is still one of the most-searched questions in enterprise data protection, and for the first time the honest answer is: partially, for a fee, with conditions. For years the answer was a flat no — Microsoft replicated your data for availability, kept recycle bins and retention policies, and told you in the services agreement to use third-party backup. Now Microsoft sells Microsoft 365 Backup as a native, metered service, and every renewal conversation I’ve sat in this year has included some version of “can we just use Microsoft’s?”

    Sometimes you can. This brief lays out what the native service actually covers, where it stops, how the third-party platforms — Veeam, Druva, Keepit, AvePoint — genuinely differ, and a decision rule that works better than any feature checklist: choose by threat model.

    The short answer

    Microsoft 365 Backup is a recovery-speed product that lives inside the Microsoft trust boundary. Third-party backup is a survivability product that lives outside it. That is the entire decision.

    If your worst realistic day is a user deleting a SharePoint library or ransomware encrypting OneDrive content, the native service is credible and fast. If your worst realistic day includes tenant-level compromise, a rogue global admin, a licensing or billing lockout, or a regulator asking for four years of mailbox history, native cannot get you there — retention caps at one year and every copy sits with the same vendor, in the same tenant, inside the same failure domain. Backup that can’t survive the failure of the thing it protects isn’t backup. It’s a faster undo button.

    What Microsoft’s native backup covers

    Microsoft 365 Backup protects three workloads: Exchange Online, SharePoint Online, and OneDrive. Restore points land roughly every ten minutes for the first two weeks, then weekly snapshots carry you out to a maximum of one year. Pricing is consumption-based — as of mid-2026, roughly $0.15 per GB per month of protected data, metered to an Azure subscription, with restores themselves free. Because the data never leaves Microsoft’s platform, bulk restores are dramatically faster than anything pulling content back through public APIs.

    What it does not do matters just as much. There is no retention beyond twelve months. There is no export of backup data to storage you control. Teams chat, Planner, Loop, and Entra ID objects are not first-class citizens. And there is no independent restore path — if your tenant is suspended, compromised, or in a billing dispute, the backup is exactly as unreachable as the production data. Microsoft has also opened the same engine to partners as Microsoft 365 Backup Storage, which is why several third-party vendors can now offer native-speed restores under their own control plane — more on that below.

    Native vs third-party, side by side

    Microsoft 365 Backup (native)Third-party platforms
    Where copies liveInside your tenant, Microsoft infrastructureVendor cloud (AWS, Azure, or vendor-owned) — outside the tenant
    Max retention1 yearMulti-year to unlimited, policy-driven
    Restore points~10-minute for 2 weeks, then weeklyTypically 1–4x daily; varies by vendor
    WorkloadsExchange, SharePoint, OneDriveAdds Teams fidelity, Entra ID, groups; varies
    Survives tenant compromiseNo — same trust boundaryYes — independent access and restore path
    Pricing model~$0.15/GB/month, Azure-meteredMostly per-user/month; list pricing varies

    Where the third-party platforms differ

    Veeam

    Veeam Data Cloud for Microsoft 365 is the SaaS packaging of the most widely deployed M365 backup engine in the enterprise, and Veeam still lets you self-host the software edition if you want to own the storage tier. Strengths: restore granularity, a huge installed base, and the option to consume Microsoft’s Backup Storage APIs for express restore speed while keeping Veeam’s control plane. The trade-off is portfolio complexity — editions, licensing tiers, and a heritage in infrastructure backup that can feel heavy if all you want is a SaaS checkbox. It fits enterprises already running Veeam for the datacenter (we’ve compared that side of the house in Veeam vs Rubrik) that want one data-protection vendor.

    Druva

    Druva is 100% SaaS on AWS — no software, no storage to size, per-user pricing. Its March 2026 Identity Resilience launch is the most interesting strategic move of the group, extending protection to Entra ID, on-prem Active Directory, and Okta in one platform. Strong for teams that want zero infrastructure and a security-led posture. The flip side: there is no self-hosted option, and data residing in Druva’s AWS environment can complicate strict sovereignty requirements.

    Keepit

    Keepit runs its own vendor-owned data centers — not AWS, not Azure — which makes it the cleanest answer to “is my backup truly outside Microsoft’s blast radius?” Coverage is broad across SaaS workloads including Entra ID. It’s a strong fit for European buyers with data-residency mandates and for anyone whose auditors ask pointed questions about infrastructure independence. The honest caveat: Keepit is a smaller vendor with a narrower enterprise ecosystem than Veeam, and that matters if you want one platform across SaaS and datacenter.

    AvePoint

    AvePoint Cloud Backup sits inside a broader Microsoft 365 governance and management platform, and that context is its edge: the deepest Teams and collaboration fidelity of the group, strong Entra ID coverage, and real traction with MSPs. Two caveats. Its backup infrastructure runs largely in Azure, which is operationally separate from your tenant but closer to Microsoft’s cloud than Keepit’s model. And the value case is strongest when you adopt the wider platform — as a standalone backup line item it competes on fidelity, not price.

    The honest downsides — both directions

    Native’s weaknesses are structural: the one-year ceiling, no export, workload gaps, and shared fate with the tenant. But third-party isn’t a free win. Per-user subscription fees compound quietly as M365 data grows — our backup storage cost-per-TB benchmarks show SaaS backup is routinely the most expensive tier per terabyte an enterprise pays for. Bulk restores through Graph APIs are throttled and slow unless the vendor integrates Microsoft’s Backup Storage. And a second vendor is a second security surface — your backup platform holds a copy of everything and deserves the same access scrutiny as the tenant itself.

    The adjacent risk: identity

    Here’s the gap most M365 backup RFPs still miss: restoring mailboxes doesn’t restore access. If Entra ID objects, conditional-access policies, or group memberships are deleted or maliciously rewritten, a content-only backup leaves you with perfectly preserved data nobody can sign in to reach. Druva cites incident-response data suggesting the large majority of investigations now trace back to identity compromise — treat the exact figure with caution, but the direction is right.

    The market has responded: Druva’s Identity Resilience covers Entra ID, AD, and Okta; Veeam Data Cloud and AvePoint both back up Entra ID; Keepit covers Entra ID within its independent cloud. Microsoft’s native service does not. Takeaway for the meeting: any M365 backup evaluation in 2026 should score identity-object protection as a mandatory line item, not a nice-to-have.

    How to decide

    • Retention under 12 months, threat model is user error and content ransomware: native is defensible. Budget ~$0.15/GB/month against your protected volume and move on.
    • Regulated retention (3–7+ years), legal hold beyond a year, or provable restore independence: third party, full stop. Native cannot satisfy any of these today.
    • Apply the 3-2-1-1-0 rule honestly: a native-only copy fails the independent-copy test, because every copy shares one trust boundary. It counts as a recovery tier, not an off-site copy.
    • The emerging pattern is both: native (or a vendor consuming Backup Storage) for fast operational restore, plus a third-party copy for long retention and tenant-failure survivability.
    • Put identity in the RFP. If the shortlist can’t restore Entra ID state, it’s protecting the library while ignoring the keys.

    Frequently asked questions

    Does Microsoft automatically back up Office 365 data?

    No. Microsoft replicates data for availability and provides recycle bins and retention policies, but none of that is backup. True point-in-time recovery requires either the paid Microsoft 365 Backup service or a third-party platform. The shared responsibility model puts the data itself on your side of the line.

    Is Microsoft 365 Backup enough for compliance?

    Usually not on its own. Retention is capped at one year, and most regulated industries — finance, healthcare, public sector — carry multi-year retention obligations that only third-party platforms can meet. Native works as an operational recovery layer alongside a compliance-grade copy.

    How much does Microsoft 365 Backup cost?

    As of mid-2026, roughly $0.15 per GB per month of protected data, billed as Azure consumption, with restores free. Third-party platforms mostly price per user per month, and list pricing varies — the crossover point depends heavily on how much data your average user carries.

    What is the shared responsibility model in Microsoft 365?

    Microsoft is responsible for infrastructure uptime and service availability. You are responsible for the data — its retention, its recoverability, and its protection against deletion, ransomware, and account compromise. Every backup decision flows from that split.

    Can third-party tools restore faster than Microsoft’s native backup?

    Generally no for bulk restores — API throttling limits anything pulling data back from outside. The exception is vendors that integrate Microsoft 365 Backup Storage, which combines native-speed restore with an independent control plane. Ask shortlisted vendors specifically whether they use it.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.

  • DRaaS Pricing in 2026: What Disaster Recovery Really Costs

    DRaaS Pricing in 2026: What Disaster Recovery Really Costs

    Try to find a published price for disaster recovery as a service and you will mostly find lead-capture forms. The numbers exist — they are just buried in procurement files. Reference-checked ranges put DRaaS at roughly $50–$200 per protected VM per month with replicated storage billed on top. A typical 30-VM managed environment at a provider like Expedient runs $8,000–$30,000 per month depending on recovery tier and immutability options, and full engagements land between $250,000 and $3 million in total contract value over three to five years.

    This brief decodes where that money goes, which contract terms actually move the number, and how four structurally different vendors — Expedient, Zerto, 11:11 Systems, and Cohesity — shape what you pay. All ranges are as of mid-2026; list pricing varies by region, deal size, and how hard you negotiate the test schedule.

    The benchmark numbers

    Typical range (as of mid-2026)Billing basis
    Per-VM subscription$50–$200 per VM/monthPer protected workload
    Replicated storageBilled on top, tiered by performance and immutabilityPer GB/month
    Recovery computeHeavily discounted until you declareReserved or burst, per vCPU/GB
    Replication bandwidthOften bundled; metered at hyperscaler targetsPer Mbps or egress GB
    30-VM managed environment$8,000–$30,000/monthBlended monthly bill
    Full engagement$250K–$3M total contract value3–5 year term

    Treat these as the shape of the market, not a rate card. The spread inside each range is not noise — it is the recovery SLA. A four-hour contractual RTO with annual testing sits at the bottom of the band; a 15-minute RTO with quarterly witnessed tests and immutable replica storage sits at the top. The number itself is less useful than knowing which lever put you where you are.

    The anatomy of a DRaaS bill

    Every DRaaS quote, whatever the logo, decomposes into a base subscription per protected workload plus three consumption components. The subscription covers replication software, orchestration, and the provider’s support obligation. Consumption covers recovery compute (cheap while idle, full price the moment you declare), replicated storage, and replication bandwidth.

    Storage is the line that grows while nobody is watching. Journals, retained snapshots, and immutability copies compound the same way backup storage does — our cost-per-TB benchmark applies almost unchanged here, and the same $/TB discipline should be in your DRaaS renewal file. The takeaway for the meeting: the per-VM rate is the headline, but storage growth is what your year-three bill will actually be about.

    The three questions that move the price

    Declared vs. contractual recovery SLAs

    Many quotes quietly price a declared objective — a target the provider aims for — rather than a contractual SLA with remedies. The gap between the two is often 30–50% of the bill. Decide which workloads genuinely need a contractual 15-minute RTO and which can live with a four-hour target; our RTO/RPO benchmarks give defensible tiers. Paying SLA money for target language is the most common DRaaS procurement mistake I see.

    Failover testing frequency

    Testing is where DRaaS quotes hide margin in both directions. One included annual test is the default; each additional witnessed test typically bills as a professional-services day plus recovery compute. Quarterly testing can add 10–20% to the annual bill — and it is usually worth it, because an untested runbook is a fiction. Regulated shops should reconcile the test schedule against the cadence argued in our DR testing and DORA brief before signing, not after the first audit finding.

    Does failover require IP and DNS changes?

    This is the sleeper question. If recovered workloads come up on new addresses, every failover — including tests — drags in DNS cutover, firewall rework, and application re-pointing. That shows up as longer real RTOs and larger services bills. Expedient’s SDN-based approach is the notable counterexample: its push-button failover preserves network identity, so workloads recover without IP or DNS changes. Other providers solve it with stretched networking or scripted re-IP, with varying elegance. Ask the question in every evaluation; the answer predicts your true test cost better than the per-VM rate does.

    How four vendors structure the bill

    Expedient

    Expedient is a full-stack operator: it runs the target cloud, the network, and the service desk, with DRaaS offerings for both VMware and Nutanix estates. Pricing is a managed monthly bill — the $8K–$30K figure for a 30-VM environment is the working planning range, with recovery tier and immutable storage driving the spread. Strengths: the push-button, no-re-IP failover noted above, and witnessed testing handled by the provider rather than your staff. Where it fits less well: shops committed to recovering into their own hyperscaler tenancy, or teams that want software they operate themselves. You are buying an outcome, and the premium over raw software reflects that.

    Zerto (HPE)

    Zerto is the replication engine, not the service. Its continuous data protection and journal-based recovery deliver the lowest RPOs in this group — seconds, not minutes — and it is licensed per protected VM, run by your team or consumed through an MSP. HPE has owned Zerto since 2021 and, as of late 2025, also distributes it through Commvault, so expect the same engine to appear on several quotes under different letterheads. Strength: best-in-class RPO and hypervisor-level flexibility. The honest downside: buying Zerto directly means you own orchestration, the DR target’s infrastructure bill, and the testing calendar. The software line is only part of your real DRaaS cost.

    11:11 Systems

    11:11 Systems is the consolidation play — the rollup of iland, Green Cloud, and Sungard AS recovery assets — and it sells managed DRaaS on more than one replication engine, with Zerto- and Veeam-based offerings targeting its own cloud or Azure. That breadth is the strength: one provider can quote continuous replication for tier-0 and cheaper snapshot-based DR for everything else. It is also the caveat: two 11:11 quotes are not automatically comparable, so make the account team state which engine, which target, and which SLA class each line item carries. Fits buyers who want managed service economics with engine choice.

    Cohesity

    Cohesity — the largest independent data-protection vendor since the Veritas merger closed — comes at DR from the backup side. Recovery is orchestrated from snapshots on its platform, with FortKnox providing an isolated cyber vault, and pricing follows its data-protection licensing plus cloud consumption rather than a per-VM DRaaS subscription. Realistic RPOs are minutes to hours, not seconds. That makes Cohesity the wrong answer for sub-minute tier-0 replication and a genuinely strong answer for the consolidation question: if backup, ransomware recovery, and DR for the long tail of workloads can share one platform, the blended cost often undercuts running a separate DRaaS contract for everything.

    Reading your own quote

    • Blended cost above ~$250/VM/month: you are paying tier-0 rates across the estate. Re-tier — most environments need contractual aggressive SLAs on fewer than 20% of workloads.
    • Blended cost below ~$40/VM/month: check what you actually bought. That price usually means replicated backups with no recovery compute reserved and no orchestrated failover — backup with extra steps, not DR.
    • One test per year in the contract: your real RTO is unknown. Budget the extra 10–20% for quarterly tests on tier-0 or accept that the SLA is decorative.
    • Storage line growing faster than VM count: journal retention and immutability copies are compounding. Renegotiate retention tiers before renewal, not at it.

    What to do about it

    Run every DRaaS evaluation against the same four asks. First, contractual SLAs with remedies on tier-0, declared targets everywhere else — and price both tiers separately. Second, the testing schedule in the contract, with per-test pricing fixed for the term. Third, a written answer on failover network identity: no IP or DNS changes, or the exact mechanism and its cost. Fourth, storage growth assumptions in the order form, so year-three pricing is a formula rather than a surprise. Providers that answer all four crisply are the ones worth shortlisting; the ranges in this brief tell you whether their number is honest.

    Frequently asked questions

    How much does DRaaS cost per VM?

    Published and reference-checked ranges run roughly $50–$200 per protected VM per month as of mid-2026, with replicated storage billed on top. Aggressive contractual RTO/RPO, quarterly testing, and immutable replica storage push toward the top of the band.

    Why don’t DRaaS providers publish pricing?

    Because the bill is mostly configuration: SLA class, storage volume, test frequency, and network design change the number by multiples. Publishing a rate card would anchor every deal at the bottom of the range, so providers price through discovery instead.

    Is DRaaS cheaper than running a second data center?

    Almost always, below a few hundred workloads. A warm second site carries facilities, hardware refresh, and staffing whether or not you ever fail over; DRaaS converts that to a monthly fee with recovery compute discounted until declaration. At very large scale, or with strict data-sovereignty constraints, owned capacity can win again.

    What should a DRaaS contract include for testing?

    At minimum: one included full failover test per year, fixed per-test pricing for additional tests, and non-disruptive test capability so exercises do not touch production. Regulated firms should align frequency with their resilience obligations — quarterly on tier-0 is the defensible norm.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.

  • Pure Storage vs NetApp in 2026: Picking Your All-Flash Platform

    Pure Storage vs NetApp in 2026: Picking Your All-Flash Platform

    On February 23, 2026, Pure Storage announced it was dropping “Storage” from its name entirely — the company now trades as Everpure, same PSTG ticker, same FlashArray and FlashBlade product lines. If you shortlisted “Pure Storage vs NetApp” for a refresh this year, the first thing to know is that one of the two names on your shortlist has changed. The second thing to know is that the products underneath have not, and the real differentiators between these two platforms are the ones most comparison pages still miss.

    I have sat through this exact bake-off more times than I can count over 20+ years of running enterprise infrastructure. This brief covers what actually separates FlashArray from AFF in 2026: data-reduction guarantees, first-party cloud presence, refresh economics, and raw performance ceilings — plus a decision framework you can defend in the meeting.

    The verdict up front

    File-heavy and hybrid-cloud estates lean NetApp. Ops simplicity and refresh economics lean Pure. That is the whole decision in two sentences, and everything below is evidence.

    If your environment runs serious NFS or SMB volumes, or you already replicate to Amazon FSx for NetApp ONTAP or Azure NetApp Files, NetApp’s unified ONTAP stack is the safer bet — no other array vendor has first-party services inside all three hyperscalers. If your estate is block-first, your storage team is small, and you are tired of forklift migrations every five years, Pure’s Evergreen model and famously low administrative overhead are the stronger argument. Neither answer is wrong. Picking the one that fights your actual workload profile is.

    What changed: Pure Storage is now Everpure

    The rebrand is more than a logo swap. Pure’s leadership has been explicit that the company wants to sell data management and AI-readiness to the C-suite, not just arrays to storage admins — hence a name without “Storage” in it. Operationally, nothing changes for customers: contracts, certifications, support entitlements, and the FlashArray//X, FlashArray//XL, FlashArray//C, FlashArray//E, and FlashBlade lines all carry forward. The ticker stays PSTG. We covered the strategic implications in our full analysis of the Everpure rebrand; the short version for buyers is that the roadmap is intact and the go-to-market ambition got bigger.

    One practical note: expect a messy 12–18 months of documentation, partner portals, and procurement systems using both names. Write “Everpure (formerly Pure Storage)” into your RFPs and save your sourcing team the confusion.

    Side-by-side: FlashArray vs AFF

    Everpure (Pure) FlashArrayNetApp AFF A-Series
    ArchitectureScale-up, active/passive controllers, custom DirectFlash modulesScale-out ONTAP clusters up to 24 nodes, standard NVMe SSDs
    ProtocolsBlock-first (FC, iSCSI, NVMe-oF); file on FlashArray//File, FlashBlade for scale-out file/objectUnified NFS, SMB, S3, and block in one OS — the strongest multi-protocol story in the market
    Data-reduction guarantee5:1 average claimed; sizing backed by Right-Size Guarantee4:1 guaranteed on SAN workloads under its efficiency program
    Performance ceilingFlashArray//XL targets consistent sub-150-microsecond latencyTop A-Series clusters advertise scale-out into the tens of millions of IOPS (~40M at full cluster width)
    Cloud presencePure Cloud Block Store on AWS and Azure; no first-party hyperscaler serviceFirst-party: FSx for ONTAP (AWS), Azure NetApp Files, Google Cloud NetApp Volumes
    Refresh modelEvergreen//Forever — controller upgrades included, no data migrationAdvance program with controller upgrades; traditionally tied to refresh cycles
    Consumption optionEvergreen//One STaaS with performance and efficiency SLAsKeystone STaaS with comparable SLA-backed tiers

    Treat vendor performance ceilings as directional, not gospel — a 24-node ONTAP cluster hitting tens of millions of IOPS and a single //XL holding sub-150-microsecond latency are answering different questions. Almost no real workload needs either extreme. What matters is which shape of headroom matches your growth.

    Where NetApp wins: cloud and file

    NetApp’s structural advantage is that ONTAP runs natively inside AWS, Azure, and Google Cloud as a first-party service — sold, billed, and supported by the hyperscaler itself. Nobody else in enterprise storage has that. If your DR strategy is “SnapMirror to FSx for ONTAP,” you get replication, snapshots, and failover with the same tooling on both ends. For a VP trying to reduce data-center footprint without rewriting applications, that is a genuinely differentiated path, and it is why NetApp keeps winning hybrid-cloud RFPs it would have lost on hardware specs alone.

    The second win is file. ONTAP has been doing enterprise NFS and SMB for three decades, and features like FlexClone, multi-tenancy via SVMs, and mature quota management still set the bar. NetApp has also pushed hard on security — its autonomous ransomware protection sits directly in the array, part of a broader industry shift we examined in our brief on storage-native ransomware detection. Rule of thumb: if more than roughly a third of your capacity is file workloads, NetApp starts the evaluation ahead.

    Where Pure wins: simplicity and refresh economics

    Pure’s advantage is the total cost of owning the thing, not the sticker. Evergreen//Forever means controller generations are included in the subscription and swapped non-disruptively — no data migration weekend, no repurchase of capacity you already own. Over a ten-year horizon, skipping two forklift refreshes is real money and, more importantly, real risk removed. When I model storage TCO for clients, the migration labor and outage exposure of a traditional refresh cycle routinely add 20–30% on top of hardware costs. Pure’s model was built to delete that line item, and after a decade in market it has proven durable rather than a marketing gimmick.

    The second win is operational load. FlashArray is the array you give to a two-person infrastructure team that also owns virtualization, backup, and the help desk. Pure1 management, proactive support, and a genuinely minimal knob count mean the platform mostly runs itself. Pure’s higher data-reduction guarantee — 5:1 claimed average against NetApp’s 4:1 SAN guarantee — also compounds in your favor on block workloads, though both numbers depend heavily on your data mix; databases with compression already enabled will reduce far less. Demand a sizing guarantee in writing from whichever vendor you pick.

    The honest downsides of both

    Neither platform deserves a free pass, and a credible evaluation names the weaknesses out loud.

    • Pure/Everpure: block-first DNA shows. FlashArray//File is serviceable but not an ONTAP peer for complex multi-protocol estates, and scale-out file means buying a second product (FlashBlade). No first-party hyperscaler service means cloud DR is a marketplace exercise. List pricing runs premium, and the subscription model — as of mid-2026 — makes exit costs easy to underestimate. The rebrand itself adds near-term noise for procurement.
    • NetApp: ONTAP’s depth is also its weight. The learning curve is real, and a lightly staffed team can misconfigure its way out of the efficiency numbers the guarantee assumes. The portfolio sprawls — AFF, ASA, FAS, StorageGRID, E-Series — and picking wrong inside NetApp’s own catalog is a genuine failure mode. Keystone has improved, but Pure still sets the pace on subscription simplicity, and NetApp’s per-feature licensing history still colors renewal negotiations.

    What to do about it

    Run the decision on workload profile and team shape, not benchmark slides. Three rules of thumb I give clients: first, if file is over a third of capacity or first-party cloud file services are on the roadmap, shortlist NetApp first. Second, if your storage team is under three FTEs or you have a forklift migration scarring the org’s memory, shortlist Pure first. Third, whichever way you lean, price the ten-year path — including refreshes, capacity growth at your actual reduction ratio, and exit costs — not the three-year quote. Both vendors will sharpen pencils dramatically when they know the other is in the room, so keep both in the room until the final round.

    And do not let the primary-array decision swallow the whole budget conversation — the economics of what sits behind it are shifting too, as we detailed in our analysis of all-flash backup target economics. A cheaper primary array paired with a slow recovery tier is a false saving.

    Frequently asked questions

    Is Pure Storage the same company as Everpure?

    Yes. Pure Storage rebranded as Everpure in February 2026 to reflect a broader data-management and AI positioning. The stock ticker remains PSTG, and products, contracts, and support carry forward unchanged.

    Which is better, Pure Storage or NetApp?

    Neither is categorically better. NetApp AFF is the stronger choice for file-heavy and hybrid-cloud environments because of ONTAP’s multi-protocol depth and first-party services in AWS, Azure, and Google Cloud. Pure FlashArray is stronger for block-centric estates that value operational simplicity and non-disruptive refresh economics.

    Is NetApp cheaper than Pure Storage?

    On initial acquisition, NetApp often quotes lower; list pricing varies widely with discounting. Over a full lifecycle, Pure’s included controller upgrades can close or reverse the gap by eliminating refresh repurchases. Model ten years, not three, before deciding which is cheaper for you.

    Does Pure Storage work with AWS and Azure?

    Yes, via Pure Cloud Block Store, which runs Pure’s software in AWS and Azure. The difference is that NetApp’s cloud offerings are first-party hyperscaler services — FSx for ONTAP, Azure NetApp Files, Google Cloud NetApp Volumes — which simplifies billing, support, and integration.

    What is the data reduction guarantee for each vendor?

    Pure claims a 5:1 average reduction and backs sizing with its Right-Size Guarantee; NetApp guarantees 4:1 on SAN workloads under its efficiency program. Actual results depend on your data — pre-compressed or encrypted datasets reduce far less, so insist on a written guarantee against your own workload profile.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.

  • Nutanix vs VMware: The Real 3-Year TCO Math in 2026

    Nutanix vs VMware: The Real 3-Year TCO Math in 2026

    The published 2026 models agree on the headline: a VMware Cloud Foundation per-core subscription runs 30–60% above a comparable Nutanix stack on three-year TCO. That number is real. It is also not the number that should drive your decision, because both vendors’ calculators quietly omit the line item that decides whether the savings ever show up — migration execution, which in our planning work eats 12–30% of the projected gap.

    This brief walks the honest math: how each stack prices as of mid-2026, what a real migration costs on a ~2,000-VM estate, and the break-even test that tells you whether the TCO gap survives contact with your environment.

    The verdict

    If your Broadcom renewal quote came in at 2.5x prior spend or worse and you run 500+ VMs on mainstream x86 workloads, Nutanix wins the three-year math even after honest migration costs. If you negotiated VCF down to deep-discount territory on a multi-year term, or your estate leans hard on NSX, VCD, or a large VDI plant tuned for vSphere, the gap narrows to the point where migration risk outweighs it. Most enterprises sit between those poles — which is why the break-even test in this brief matters more than either vendor’s calculator.

    How the two stacks price in 2026

    VMware by Broadcom sells subscriptions only, per core, with a 16-core minimum per CPU. VCF lists around $350 per core per year as of mid-2026; realized enterprise pricing varies widely with term and estate size, and the discount you extract is the single biggest variable in this whole comparison. NSX, vSAN, and Aria are no longer sold standalone — you pay for them inside VCF whether you deploy them or not. That bundling is Broadcom’s pitch and its tax at the same time. Before you take any quote at face value, read our companion brief on negotiating a Broadcom VMware renewal — the spread between list and realized pricing is enormous.

    Nutanix prices its Cloud Infrastructure (NCI) stack per core as well, in Starter, Pro, and Ultimate editions. The AHV hypervisor is included in the NCI license at no separate charge, which is the structural advantage: the line item VMware customers have paid for two decades simply is not there. List pricing varies by edition and term, and Nutanix discounts aggressively when it smells a VMware exit — expect the sales team to model your Broadcom quote for you, and expect that model to flatter Nutanix.

    VMware Cloud Foundation (Broadcom)Nutanix Cloud Platform (NCI + AHV)
    Licensing modelPer-core subscription, 16-core min per CPUPer-core subscription, Starter/Pro/Ultimate
    Hypervisor costInside the VCF subscriptionAHV included with NCI — no separate SKU
    BundlingNSX, vSAN, Aria bundled — paid even if unusedModular; storage, DR, management priced by edition
    Renewal dynamicsQuotes of 3–10x prior perpetual+support are commonSteep first-bid discounts; renewal discipline required
    3-yr TCO (like-for-like)BaselineModels show 30–60% below VCF, before migration
    Migration costNone (incumbent)$350K–$1M all-in for a ~2,000-VM estate

    The 3-year TCO math

    Run the like-for-like model — same core counts, comparable resilience, equivalent management tooling — and the published 2026 numbers put a Nutanix stack 30–60% below VCF over three years. The spread depends mostly on two things: how hard you negotiated Broadcom, and how much of the VCF bundle you actually use. A shop consuming NSX and Aria in anger sits at the narrow end. A shop that bought VCF but runs plain vSphere-plus-vSAN workloads is paying bundle tax on software it never touches, and lands at the wide end.

    Both calculators hide the same thing. VMware’s model assumes you were going to pay list-adjacent renewal pricing anyway. Nutanix’s model assumes migration is roughly free. Neither assumption survives a real project. The honest three-year figure is: (VCF spend − Nutanix spend) − migration cost — and that third term is bigger than most first-pass business cases admit.

    What migration actually costs

    Verified planning numbers for a ~2,000-VM estate: $150K–$400K in external services, plus $200K–$600K of internal effort you will absolutely spend even if the PO never captures it. Call it $350K–$1M all-in. Against a multi-million-dollar three-year gap that still clears easily; against a well-negotiated VCF deal it can consume a third of the savings.

    The tooling is good but not magic. Nutanix Move handles the bulk VMDK-to-AHV conversions competently, and the current releases extend Move to migrations landing on external storage — see our brief on running Nutanix with external storage for a VMware exit if you are not ready to abandon your arrays. But Move has fidelity limits at scale. Three realities to plan around:

    • Deep snapshot chains are hard blockers, not warnings. Collapse them before you schedule a single cutover wave — on a neglected estate that cleanup alone is weeks of work.
    • Oddball VMs — RDMs, shared-disk clusters, appliances with vendor-locked virtual hardware — fall out of the automated path and become manual projects. Budget 5–10% of the estate as exceptions.
    • Timeline discipline: mid-size estates (50–500 VMs) typically run 12–24 weeks end to end. A 2,000-VM estate is a multi-quarter program, and you are paying both vendors during the overlap.

    Honest downsides — both sides

    Where VMware still hurts you

    Renewal quotes at multiples of prior spend, a bundle you cannot unbundle, and a vendor whose post-acquisition behavior has burned negotiating goodwill across the industry. Roadmap and channel churn under Broadcom remain real planning risks, and the 16-core minimum punishes low-core-count edge hosts disproportionately.

    Where Nutanix hurts you

    The ecosystem gap is honest and material: fewer third-party integrations, a thinner talent pool than twenty years of vSphere produced, and some backup, security, and monitoring tools that treat AHV as a second-class citizen. Your first renewal is where Nutanix recovers its acquisition discount — model year-four pricing before you sign, not after. And the migration itself is your risk, on your change calendar, with your people.

    When the gap survives — and when it doesn’t

    The rule of thumb we give clients: commit to the exit only if the modeled three-year gap is at least 2x your honest migration estimate. At 2x, normal project slippage still leaves you ahead. Below 1.5x, you are doing the migration for strategic reasons — leverage, roadmap distrust, exit optionality — not for savings, and you should say so in the business case.

    Above the line: estates of 500+ VMs on commodity workloads, renewal quotes at 2.5x prior spend or worse, light NSX dependency. Below the line: sub-300-VM estates where fixed migration costs dominate, deep NSX/VCD entanglement, or a VCF deal negotiated into genuinely defensible territory. If you are below the line but still want out, the broader field — Proxmox, Hyper-V, OpenShift Virtualization — is covered in our 2026 VMware alternatives rundown; Nutanix is the most complete replacement, not the only one.

    What to do about it

    • Build the model yourself. Take Broadcom’s real quote and Nutanix’s real quote, then add a migration line of $175–$500 per VM all-in. Reject any business case without that line.
    • Run a 50-VM pilot wave through Nutanix Move before you commit. It surfaces your exception rate and snapshot debt for a few weeks of effort.
    • Negotiate both sides simultaneously. A credible, piloted exit plan is worth more off your VCF renewal than any procurement tactic.
    • Whatever you choose, cap the term at three years. This market is repricing too fast for five-year certainty.

    Frequently asked questions

    Is Nutanix cheaper than VMware?

    On like-for-like 2026 subscription pricing, published models put a Nutanix NCI/AHV stack 30–60% below VMware Cloud Foundation over three years. But migration execution typically consumes 12–30% of that gap, so the net answer depends on your estate size and how well you negotiated each side.

    How much does it cost to migrate from VMware to Nutanix?

    Planning numbers for a ~2,000-VM estate run $150K–$400K in external services plus $200K–$600K in internal effort — $350K–$1M all-in, or roughly $175–$500 per VM depending on estate complexity and exception rate.

    Is Nutanix AHV as good as VMware ESXi?

    For mainstream server virtualization, AHV is functionally competitive and operationally simpler. ESXi retains the edge in third-party ecosystem depth, niche workload support, and available talent. The honest framing: AHV covers 90%+ of typical enterprise workloads without drama; the last few percent are where diligence belongs.

    How long does a VMware to Nutanix migration take?

    Mid-size environments (50–500 VMs) typically take 12–24 weeks from kickoff to final cutover using Nutanix Move. A 2,000-VM estate is a multi-quarter program — budget for dual-running costs during the overlap.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.

  • Veeam vs Rubrik in 2026: Architecture, Cost, and Recovery

    Veeam vs Rubrik in 2026: Architecture, Cost, and Recovery

    Search “Veeam vs Rubrik” and most of what ranks is the two vendors attacking each other — Veeam’s page on why Rubrik is overpriced, Rubrik’s page on why Veeam is insecure. Neither is a useful basis for a purchase that will sit in your environment for five to seven years. I have run both platforms in production environments and sat through the renewal meetings for each, and the honest answer is that this is not a “which product is better” question. It is a “which trade-off does your organization want” question.

    This brief lays out that trade-off as of mid-2026: what changed with Veeam v13, what Rubrik’s architecture actually buys you, where the money goes at 100TB and at 1PB, and a set of decision rules you can defend in front of a CFO.

    The verdict up front

    Veeam is flexibility plus a lower entry cost. Rubrik is structural security plus operational simplicity. That is the whole comparison in one line.

    Veeam remains hardware-agnostic — you bring your own repositories, your own dedupe appliances, your own object storage — and its instance-based Veeam Universal License means costs track workload count, not data growth. With v13, it also closed the security gap Rubrik spent years selling against: the new Veeam Software Appliance is a pre-hardened, DISA STIG-compliant Linux platform with mandatory 2FA and high-availability clustering. Rubrik, by contrast, is immutable by design. Its Atlas filesystem exposes no writable NFS or SMB protocols to the network and refuses non-append-only writes at the API level, so even an attacker holding admin credentials cannot remotely destroy your backups. You pay for that assurance with capacity-based licensing that grows with your data. Neither posture is wrong. But one of them is wrong for you.

    Side-by-side comparison

    VeeamRubrik
    ArchitectureSoftware-defined, hardware-agnostic; v13 ships as a hardened Linux appliance or self-managed installIntegrated platform (Rubrik Security Cloud) built on the proprietary Atlas immutable filesystem
    LicensingInstance-based (Veeam Universal License) — scales with workload countCapacity-based subscription — scales with front-end data protected
    ImmutabilityAvailable and mature (hardened repositories, object lock), but you configure and own itStructural — append-only by design, no writable network protocols exposed
    Security posture (2026)v13 appliance: DISA STIG hardening, mandatory 2FA, Security Officer approval workflow, SSH off by defaultLogical air gap by architecture; ransomware detection and threat hunting native to the platform
    OperationsMore components, more knobs, more staff hours — and more controlPolicy-driven SLA domains replace backup jobs; lean-team friendly
    Peer reviews~4.6 on Gartner Peer Insights across roughly 2,000 reviews (as of mid-2026)~4.6 across roughly 800 reviews (as of mid-2026)
    Best fitHeterogeneous estates, cost-sensitive buyers, teams that want repository choiceRansomware-mandate buyers, lean ops teams, security-led purchasing

    What changed in 2025–26

    The most consequential shift is Veeam’s. For years, the credible knock on Veeam was its Windows-based backup server — a large attack surface sitting in the exact blast radius ransomware crews target first. Version 13 addressed that head-on. The Veeam Software Appliance is a prebuilt, Rocky Linux-based, just-enough-OS platform: DISA STIG hardened, SSH disabled by default, mandatory 2FA for admin and Security Officer accounts, and a four-eyes approval model for destructive actions like deleting backup data. Veeam also added active/passive clustering for the backup server itself and a browser-based console that finally breaks the dependence on a Windows management box.

    That release changes the sales conversation. Rubrik’s strongest argument — “Veeam’s control plane is your weakest link” — now lands only against organizations still running v12 on Windows, which, to be fair, is most of Veeam’s installed base for the next couple of years. Migration is a project, not a checkbox.

    Rubrik’s evolution has been steadier: the company has kept pushing Rubrik Security Cloud beyond backup into data security posture — anomaly detection, sensitive-data discovery, threat hunting inside backup snapshots. Its pitch has moved from “we back up your data” to “we are your last line of cyber resilience,” and boards have been receptive. The same platform logic applies in our Rubrik vs Cohesity comparison, where the two integrated players fight on security depth rather than price.

    Pricing and TCO at 100TB and 1PB

    Neither vendor publishes meaningful list prices, and street discounts vary widely, so treat any blog quoting exact per-TB figures with suspicion. The shape of the cost curves, though, is consistent and verifiable in any competitive bid.

    At 100TB — roughly a few hundred VMs plus file data — Veeam almost always carries the lower entry cost. Instance licensing on a mid-sized estate is modest, and you can land backups on storage you already own or on commodity object storage with immutability enabled. Rubrik at this size means a subscription priced on those 100 front-end terabytes plus either appliance hardware or certified partner hardware. Expect the Rubrik bid to come in meaningfully higher; what you get back is a platform one admin can run in a few hours a week.

    At 1PB, the math tightens. Veeam’s license cost stays tied to workload count, but the hidden line items grow: repository hardware refreshes, the staff time to design and patch a sprawling backup fabric, and the engineering discipline to keep immutability correctly configured everywhere. Rubrik’s capacity subscription at a petabyte is a large number — and it keeps growing at your data growth rate, which is the figure to negotiate hardest on. Rule of thumb: if your data is growing above roughly 25 percent a year, model Rubrik’s renewal at year three before you sign, because that is where capacity-based deals bite. If your ops team is understaffed, price that reality too — Veeam’s lower invoice is partly a transfer of cost from the vendor to your payroll.

    Where each platform falls short

    Veeam’s honest weaknesses

    Flexibility is sprawl by another name. A large Veeam estate accumulates proxies, repositories, gateways, and tape servers, and every component is something your team designs, patches, and can misconfigure. Immutability is available and solid — hardened Linux repositories, object lock — but it is opt-in, and audits keep finding shops that never turned it on, a gap we dig into in our immutable backup storage comparison. The v13 appliance is genuinely strong, but it is new; the WebUI still trails the legacy console in places, and the migration off Windows is real work that most of the installed base has not started.

    Rubrik’s honest weaknesses

    Cost, and the direction of cost. Capacity licensing means your backup bill is indexed to data growth, and nobody’s data shrinks. Lock-in is structural: Atlas is proprietary, so leaving Rubrik means migrating or aging out every snapshot it holds. Repository choice is limited compared with Veeam’s bring-anything model. And for edge cases — unusual applications, legacy platforms, odd hypervisors — Veeam’s twenty years of accumulated workload coverage still runs deeper.

    What to do about it

    • Choose Veeam if your estate is heterogeneous, your team has real infrastructure skills, and cost per protected workload is the metric your CFO watches. Deploy v13 as the hardened appliance from day one — do not replicate the old Windows design.
    • Choose Rubrik if the purchase is security-led — a board ransomware mandate, a cyber-insurance requirement, a lean team that cannot own hardening. You are buying an outcome, not a toolkit, and the premium is the price of that outcome.
    • Already on Veeam v12? The cheapest security upgrade available to you is the v13 migration plus hardened repositories — likely a fraction of a platform switch, as the numbers in our Commvault vs Veeam analysis also suggest.
    • Negotiating Rubrik? Cap the renewal uplift and model three years of data growth into the quote before signature.

    The takeaway for the meeting: Veeam and Rubrik both protect data well — peer scores are effectively tied — so buy the operating model, not the feature list.

    Frequently asked questions

    Is Rubrik better than Veeam?

    Neither is categorically better — both hold roughly 4.6 ratings on Gartner Peer Insights as of mid-2026. Rubrik wins on built-in immutability and operational simplicity; Veeam wins on flexibility, workload coverage, and entry cost. The right answer depends on whether security posture or infrastructure control drives your purchase.

    Is Veeam still Windows-based?

    Not anymore. Veeam Backup & Replication v13 ships as a pre-hardened, Rocky Linux-based software appliance with DISA STIG compliance, mandatory 2FA, and a web console. Existing v12 deployments remain on Windows until they migrate, and that migration is the key project for current Veeam shops.

    How much does Rubrik cost compared to Veeam?

    Rubrik typically carries a higher upfront cost because its subscription is priced on front-end capacity and usually includes platform hardware. Veeam’s instance-based licensing is generally cheaper to enter, but you supply and operate the backup storage yourself. List pricing varies; competitive bids are the only reliable comparison.

    Can Veeam backups be made immutable?

    Yes — via hardened Linux repositories and object storage with object lock. The difference is that Veeam’s immutability is something you configure and verify, while Rubrik’s Atlas filesystem is append-only by design and exposes no writable network protocols at all.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.

  • VMware Licensing 2026: What Broadcom Changed, What It Costs

    VMware Licensing 2026: What Broadcom Changed, What It Costs

    Somewhere in your renewal folder is a VMware quote that is 3x to 10x what you paid Dell, HPE, or VMware directly three years ago — and that range is not an outlier, it is the pattern I hear from IT directors across every vertical since Broadcom closed the acquisition in late 2023. The licensing model that produced that quote is genuinely different: per-core subscriptions only, a 16-core minimum per CPU, a 72-core minimum per order, and — as of the 9.0 release in June 2025 — no standalone vSphere SKU at all.

    This brief is the plain-English decoder: what Broadcom actually changed, what the bundles contain, how the minimums distort the math for small and edge sites, and what to do before your renewal lands. No vendor spin, no consultant gatekeeping.

    What changed

    Broadcom collapsed a catalog of 160-plus VMware products into a handful of subscription bundles. Perpetual licenses are gone — you cannot buy one, and existing perpetual keys keep running but receive no updates once support lapses. Everything is now licensed per physical core, with a floor of 16 cores counted per CPU even if the socket has fewer.

    Two later moves matter just as much. In April 2025, Broadcom added a 72-core minimum per order, which quietly repriced every small deployment. And with the 9.0 release in June 2025, vSphere stopped being a product you can buy at the current version: vSphere 9 ships only inside VMware Cloud Foundation (VCF) or vSphere Foundation (VVF). The standalone vSphere Standard and Enterprise Plus SKUs top out at version 8 Update 3. A “vSphere renewal” in 2026 is really a decision about which bundle to move to — that is the part most quotes bury.

    The 2026 bundle decoder

    As of mid-2026 the practical menu is three items. VCF is the full private-cloud stack — vSphere, vSAN, NSX networking, automation, and operations tooling as one integrated platform, now on release 9.1. VVF is the middle tier: vSphere plus operations management and a smaller vSAN entitlement, aimed at shops that want current vSphere without the full stack. vSphere Standard survives as a budget SKU, but only at the 8.x code line.

    vSphere StandardVVF (vSphere Foundation)VCF (Cloud Foundation)
    Current version8 Update 3 only9.x9.x
    What’s insideCore hypervisor, vCentervSphere 9, VCF Operations, limited vSANFull stack: vSphere, vSAN, NSX, automation, operations
    vSAN entitlementNone0.25 TiB per core1 TiB per core
    Who it fitsLegacy estates coasting to a migration decisionVirtualization-first shops that skipped NSXCommitted VMware private-cloud strategies
    Trap to watchvSphere 8 support ends in 2027vSAN entitlement rarely covers real capacityYou pay for NSX and automation whether you deploy them or not

    Credit where due: VCF 9 is the most coherent private-cloud platform VMware has ever shipped. Broadcom’s engineering consolidation produced one aligned release instead of a loose federation of products, and for enterprises that actually run vSAN and NSX at scale, the bundle can pencil out against buying the pieces separately in the old catalog. The criticism is not that VCF is bad software. It is that VCF is the only door, and the door has a cover charge.

    The minimums that change the math

    Run the numbers on a typical edge site: two hosts, each with a single 12-core CPU. Physically that is 24 cores. The 16-core-per-CPU floor rounds it to 32. The 72-core order minimum then more than doubles it again — you are billed for 72 cores to run 24. Branch offices, retail back rooms, factory floors, and small DR sites all hit this wall, and it is why the 2025 change generated more anger than the original subscription pivot.

    • Below roughly 72 physical cores per site, you are paying for phantom capacity — consolidate sites onto shared clusters or move those workloads off VMware.
    • Between 72 and a few hundred cores, high-core-count CPUs are your friend: fewer sockets at 32 or 48 real cores waste less against the 16-core floor than many small sockets.
    • Above that, the minimums stop mattering and the negotiation is purely about per-core rate and term length.

    The takeaway a VP can repeat: VMware now prices like a data-center platform, so anything smaller than a data center is structurally overpaying.

    What a renewal actually costs now

    List pricing varies by geography, term, and tier, so treat any single number you read online with suspicion. The shape of the market as of mid-2026: organizations coming off perpetual-plus-support agreements report first quotes at 3x to 10x their prior annual spend, with the worst multiples hitting small estates (the minimums) and vSphere-only shops being pushed up-tier into VVF or VCF. Three-year commitments price meaningfully better per core than one-year terms, which is exactly the lock-in they are designed to buy.

    Do the true comparison before you sign anything. Your old number was license amortization plus roughly 20 percent annual support. Your new number is the subscription — but the honest comparison also prices the alternative: migration cost plus the competing platform’s subscription. Broadcom’s negotiators know most enterprises cannot migrate before the renewal date, and the quote reflects that leverage. Your counter-leverage is a credible, costed exit plan — we cover the tactics that have actually moved quotes in our Broadcom renewal negotiation playbook.

    Why it matters

    This is not a procurement annoyance; it is an architecture decision with a deadline. Staying current on VMware now means adopting a bundle strategy, and coasting on vSphere 8 only works until general support runs out — see our timeline analysis in vSphere 8 end of support: what October 2027 really means. After that, an unpatched hypervisor under everything you run stops being a cost decision and becomes an audit finding.

    Budget owners should also note what the model does to forecasting. Perpetual licensing front-loaded cost and made support predictable. Per-core subscription converts your hypervisor into a recurring line item that reprices at every renewal — on Broadcom’s schedule, not yours.

    What to do about it

    Three moves, in order. First, inventory your real core counts per site and model them against the 16-core and 72-core floors — that spreadsheet is the single highest-leverage hour of work available to you this quarter. Second, segment your estate: workloads that genuinely benefit from VCF’s integrated stack, workloads that just need a hypervisor, and edge sites the minimums punish. Third, price the exits honestly. Proxmox, Nutanix, Hyper-V, and OpenShift Virtualization each fit a different segment of that split, and we have compared them head-to-head in our guide to VMware alternatives in 2026.

    The verdict: if you are large, standardized, and using the full stack, VCF at a negotiated three-year rate is defensible. Everyone else should be running a funded migration evaluation right now — not because leaving is mandatory, but because a credible option to leave is the only thing that changes the quote.

    Frequently asked questions

    Can you still buy VMware perpetual licenses?

    No. Broadcom ended perpetual sales in early 2024. Existing perpetual licenses keep running, but without an active support contract you get no patches or updates — and vSphere 9 was never released as a perpetual product at all.

    What is the minimum number of cores for VMware licensing?

    Two floors apply: every CPU is counted as at least 16 cores regardless of its actual core count, and since April 2025 new orders carry a 72-core minimum. Small sites frequently pay for two to three times the cores they physically run.

    Is vSphere 9 available as a standalone product?

    No. vSphere 9 ships only inside VMware Cloud Foundation 9 or vSphere Foundation 9. The standalone vSphere Standard and Enterprise Plus SKUs are frozen at version 8 Update 3.

    How much did VMware prices increase under Broadcom?

    There is no single official increase, but as of mid-2026 organizations moving from perpetual-plus-support to subscription commonly report quotes 3x to 10x their prior annual spend. Small estates hit hardest because of the core minimums; large multi-year commitments negotiate materially better rates.

    What is the difference between VCF and VVF?

    VCF is the full private-cloud stack — vSphere, vSAN (1 TiB per core), NSX, automation, and operations. VVF is vSphere plus operations tooling with a smaller vSAN entitlement (0.25 TiB per core). VCF costs more per core and is worth it only if you deploy the stack you are paying for.

    Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.