Backup that survives a bad day
Backup gets attention twice: at budget time and after an incident. The gap between those two moments is where estates quietly drift into trouble: retention grows past the hardware, restore tests stop happening, and the backup copy ends up on the same network with the same credentials as production, which is exactly what ransomware counts on.
The baseline hasn't changed: three copies, two media, one off-site or offline. What has changed is that the off-site copy needs to be immutable, because attackers now go for the backups first. A purpose-built appliance with deduplication makes retention affordable; immutability and separated credentials make it survivable.
What actually determines the answer
| Factor | Why it matters |
|---|---|
| Restore time, not backup time | The question that matters is how long a full restore of your most critical system takes. Design backward from that number. |
| Change rate and retention | Protected capacity, daily change rate, and retention windows size the appliance. Dedupe ratios are workload-dependent; size on your data, not the brochure. |
| Immutability and credential separation | A backup the attacker can encrypt or delete is not a backup. Retention lock and separate credentials are the difference. |
| What you already run | The appliance should integrate with your existing backup application, not force a rip-and-replace of it. |
The paths, with their trade-offs
Purpose-built backup appliance
When you have a working backup application and need a better target: dedupe, immutability, replication.
Trade-off: The appliance is the target, not the brain; your backup software still does the scheduling and cataloging.
Configured BOM
DD6900 - consolidated backup target
- Appliance PowerProtect DD6900, capacity licensed to your backup set
- Integration DD Boost configuration for your backup application
- Replication Optional site-to-site replication to a second appliance
- Support 4-year ProSupport, next business day
Two-site replication
When recovery must survive a site-level event, not just a deleted volume.
Trade-off: Doubles the appliance footprint. The second site's copy is the one that saves you, so it can't be the afterthought.
Rework the whole backup design
When restore tests are failing or nobody is sure what's actually protected.
Trade-off: More engagement than a hardware refresh, but hardware can't fix a design problem.
What deployment involves
Typical scope: appliance install, integration with your backup application, policy and retention configuration, and a witnessed restore test before handover.
The restore test is not optional. A backup design is finished when a restore has been demonstrated, not when the jobs go green.