For thirty years backup was insurance against accident. A disk failed, a database was corrupted, someone deleted the wrong directory, a data centre flooded. The threat model was bad luck and human error, and neither of those goes looking for your backups.

Ransomware operators do. The standard playbook now involves locating and destroying backup infrastructure before encrypting anything, because an organisation that can restore does not pay.

That change is why the category is called data resilience rather than backup, and Forrester's own framing of the market makes the shift explicit: enterprises must not only back up data across diverse environments but secure that data, and the backup infrastructure itself, from cyberthreats.

The backup stopped being passive insurance and became a contested asset. Everything else about this category follows from that.

What the category covers

Forrester defines these solutions as encompassing backup and recovery functionality alongside data security and governance needs.

In practice the scope spans several things that used to be separate purchases. Backup and restore across on-premises systems, hyperscale infrastructure, containers, and SaaS applications. Immutable storage and isolated recovery environments. Anomaly detection to spot encryption events in the backup stream. Orchestrated recovery, including to alternate infrastructure. Automated testing of whether restores actually work. And governance and compliance reporting over what is protected and where it sits.

The criteria in the current evaluation reflect that breadth: hyperscale cloud and infrastructure-as-a-service coverage, regulatory and compliance features, directly supported SaaS platforms, recovery to alternate infrastructure, and protection for generative AI models and data.

Backup sources have proliferated too. Forrester assessed Veeam's strengths across Kubernetes and containers, common and vendor-specific storage systems, hyperscale infrastructure coverage, and backup storage targets, alongside recovery to alternate infrastructure and automated testing.

That last item deserves its own section.

Inside the evaluations

The Forrester Wave: Data Resilience Solution Suites, Q4 2022, published on 8 December 2022 and authored by Brent Ellis, scored nine providers against forty criteria across current offering, strategy, and market presence: Cohesity, Commvault, Dell Technologies, Druva, IBM, Rubrik, Veeam Software, Veritas, and Zerto.

Commvault took the top current offering score in that edition, with the highest marks in backup and restore functionality and in automation and orchestration. Cohesity also placed as a Leader.

Two of those nine subsequently combined, with Cohesity acquiring Veritas, which is the most significant structural change this market has seen.

The Forrester Wave: Data Resilience Solutions, Q4 2024 dropped Suites from the name. Commvault again placed as a Leader with the top current offering score, taking the highest possible marks in thirteen criteria including hyperscale cloud, regulatory and compliance features, directly supported SaaS platforms, protection for generative AI models and data, and recovery to alternate infrastructure.

Veeam also placed as a Leader, credited for a strategy combining in-house development with targeted acquisitions, strengths in innovation and partner ecosystem, and a roadmap including expanded SaaS support, vault provisioning enhancements, proactive threat assessment, and improved incident response workflows.

Note what appears in that roadmap description: threat assessment and incident response workflows. Those are security operations concepts arriving in a backup product.

Recovery time is mostly fiction

The uncomfortable truth in this category is that most organisations do not know whether they can recover.

Backup completion is monitored obsessively. Dashboards report successful jobs, coverage percentages, and retention compliance. All of that measures whether data went in.

Recovery measures whether data comes out, at scale, in order, into an environment that works, within a time the business can tolerate. It is tested rarely, partially, and usually on the systems that are easiest to test rather than the ones that matter.

The gap shows up during an actual incident. Restoring a single file is fast. Restoring several hundred systems with interdependencies, in a sequence that respects what needs to exist before what, into infrastructure that may itself be compromised, is a different exercise. Recovery time objectives written in a policy document are frequently estimates nobody has validated.

This is why automated testing of backups and restores is a scored criterion and why recovery to alternate infrastructure matters. If your production environment is compromised, restoring into it reintroduces whatever was there. Recovery has to land somewhere clean, which means the alternate environment needs to exist, be provisioned, and have been tested.

The practical question for any buyer is not what the platform can back up. It is how long a full recovery of your top ten business services would actually take, and when that was last demonstrated rather than calculated.

Immutability, and the assumptions underneath

The technical response to backups being targeted is immutability: storage that cannot be altered or deleted for a defined retention period, regardless of credentials.

The mechanism is sound and it has assumptions worth understanding.

Immutability protects the data and not necessarily the ability to use it. If the backup catalogue, the encryption keys, or the management infrastructure is compromised, immutable data may be intact and unreachable.

Retention windows must exceed dwell time. Attackers frequently sit in an environment for weeks before acting. If the immutable window is fourteen days and the compromise began sixty days ago, the clean copy has already aged out.

And administrative control is the real boundary. The strongest configurations put deletion authority outside the reach of any single set of credentials, including the backup administrator's, because insider risk and credential compromise produce the same outcome.

Air-gapped and isolated recovery vaults address these, at the cost of operational complexity and recovery speed. The trade-off is genuine and organisations tend to resolve it by buying the capability and configuring it permissively, which is how you end up with immutability on paper.

Backing up an AI system

Protection for generative AI models and data appearing as a scored criterion in 2024 marks something new, and it is worth thinking through what it actually requires.

An AI system's state is distributed across several things that traditional backup does not treat as a unit. Fine-tuned model weights, which may be large and expensive to reproduce. Vector databases holding embeddings, which are derived from source content but costly to regenerate. The source content itself. Prompt templates, evaluation sets, and configuration. And increasingly the agent definitions, tool permissions, and memory stores that determine what a system does.

Several of those are recoverable by reconstruction rather than restore, if the inputs and the process survive. Reconstruction takes time and compute, which may or may not be acceptable depending on what the system does.

The harder question is consistency. Restoring a vector database to Tuesday and the source content to Thursday produces a system that retrieves from an index describing documents that have changed. That kind of mismatch is silent, and it produces confidently wrong output rather than an error.

Most organisations have not classified their AI assets for recovery purposes at all, which means the criterion is scoring a capability that few buyers are yet asking for. That will change quickly as these systems move into production paths.

Regulation is making testing mandatory

The regulatory direction is worth noting because it converts a good practice into an obligation, particularly in Europe.

The EU's Digital Operational Resilience Act applies to financial entities and their critical technology providers, and its requirements go beyond having a recovery capability to testing it, documenting the testing, and reporting on operational resilience. Similar expectations appear in other sectoral regimes and in critical infrastructure rules.

That changes the buying conversation. A platform that can demonstrate, evidence, and report on recovery testing is producing regulatory artefacts, not just operational assurance. Commvault's maximum score in regulatory and compliance features sits in exactly that space.

For organisations in scope, the useful question to put to vendors is what documentation the platform produces for a supervisor, rather than what recovery capability it has. Those are different products in practice.

Where the category sits now

Data resilience has completed a migration from IT operations into security, and the vendor positioning shows it. Threat assessment, incident response workflows, anomaly detection, and integration with security operations tooling are now standard parts of the pitch.

That migration is correct on the merits and it creates an organisational question most enterprises have not settled. Backup has historically been owned by infrastructure teams, funded from IT operations, and measured on completion rates. Resilience against a deliberate adversary is a security discipline, measured on recovery under adversarial conditions.

Where those two functions have different budgets, different reporting lines, and different definitions of success, the platform tends to be bought by the first and depended on by the second.

The organisations that handle this well run recovery exercises jointly, treat the backup environment as a protected security asset with its own access controls, and measure the thing that matters, which is time to restore business function rather than time to restore data.

The ones that do not discover the difference during an incident, which is the most expensive possible moment to learn it.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of data resilience, mapped in a Q2 2022 Now Tech report of 20 providers and scored in The Forrester Wave: Data Resilience Solution Suites, Q4 2022, covering nine providers against 40 criteria, and in The Forrester Wave: Data Resilience Solutions, Q4 2024.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.