Acronis Cyber Backup is the backup core that protects server, virtual machine, workstation and application data at image (disk) level or file level, and returns it to a working state after hardware failure, user error or ransomware. The backup destination, retention period and recovery method are all managed from a single protection plan; bare-metal recovery, restore to dissimilar hardware and immutable storage are standard capabilities of this core.
One point of naming needs to be clarified. Although the name "Cyber Backup" is still widely used in the Turkish market, in the current official Acronis licensing scheme the backup core is sold under the Acronis Cyber Protect Standard, Advanced and Backup Advanced editions; the former "Backup Standard" edition is no longer available for purchase and can only be used by existing customers with an active maintenance agreement (Acronis Support KB 73387, 2026). On this page we use the term "Cyber Backup" to mean exactly this backup core, configured without the security add-ons.
The numbers show why backup has stopped being a matter of IT hygiene and has become a security control in its own right. The Verizon 2025 Data Breach Investigations Report analysed 22,052 security incidents and 12,195 confirmed data breaches across 139 countries; ransomware was present in 44% of the breaches analysed (up from 32% the previous year) and appeared in 88% of SMB breaches, while the figure remained at 39% for large organisations (Verizon DBIR 2025). The same report states one of the reasons SMBs are disproportionately targeted quite plainly: they are less likely than large organisations to have current, readily accessible backups.
Against this backdrop, a backup is not a copy kept "just in case" — it is one of the attacker's early targets. This is precisely where the Acronis solution family differentiates itself: backup and cyber protection run on the same agent and in the same console, so the controls that protect the backup itself do not come from a separate product. As an authorised Acronis channel partner, Sora Yazılım delivers licensing, backup architecture design, migration from an existing solution, recovery drills and, on request, a managed operations service — all together.
What is Acronis Cyber Backup and which license editions is it sold under today?
Short answer: the backup core is licensed according to the type of workload being protected, and the choice of edition directly determines which workloads you can cover. According to the official licensing knowledge base, Workstation, Server, Virtual Host and Public Cloud VM workloads can be protected with both the Standard and Advanced editions; by contrast, the Universal License is available only in the Advanced and Backup Advanced editions, while Microsoft 365 and Google Workspace protection sits exclusively on the Backup Advanced side (Acronis Support KB 73387, 2026).
| Workload type | Cyber Protect Standard | Cyber Protect Advanced | Backup Advanced |
|---|
| Workstation | Yes | Yes | Yes |
| Windows Server Essentials | Yes | No | No |
| Server (physical server) | Yes | Yes | Yes |
| Virtual Host (hypervisor) | Yes | Yes | Yes |
| Public Cloud VM | Yes | Yes | Yes |
| Universal License (type-agnostic workload) | No | Yes | Yes |
| Microsoft 365 | No | No | Yes |
| Google Workspace | No | No | Yes |
The official positioning of each edition completes this picture. Standard combines standard backup with multi-layered protection for SMBs; data protection maps, URL filtering and categorisation, continuous data protection and disk health monitoring sit at this tier. Advanced targets larger, more complex environments and adds extra workload support, shared protection plans, safe recovery of backups, malware scanning of backups and security posture assessment. Backup Advanced is built around group management, shared protection plans, off-host data processing, tape support, deduplication and customisable reporting.
On the virtualisation side, the licensing rules deserve particular attention: a Virtual Host or Per-VM license for VMware and Hyper-V is valid in both the Standard and Advanced editions, whereas Azure Stack HCI, KVM, Nutanix and Citrix Hypervisor can only be licensed with Advanced or Backup Advanced. On the Public Cloud VM side, one Per-VM license covers three virtual machines; with a Universal Workload license, one license corresponds to a single workload regardless of whether it is a physical machine, a virtual machine or a host (Acronis Support KB 73387, 2026). Mixing Standard and Advanced licenses in the same environment is not supported; all hosts in a cluster must have a consistent edition and license type. Once we have mapped the host and VM distribution in your environment, we calculate which license type delivers the same coverage with fewer line items and build the licensing plan accordingly.
How do you apply the 3-2-1 backup rule with Acronis?
Short answer: the 3-2-1 rule says you should keep at least three copies of your data, store those copies on at least two different media types, and keep at least one copy off site. In Acronis, this rule is implemented by defining multiple backup destinations within a single protection plan and adding a replication step from the local backup to a cloud destination; no separate product and no separate scheduling engine is required.
The available destinations differ by deployment model. In on-premises management, the officially supported backup destinations are cloud storage, a local folder, a network folder (SMB/CIFS/DFS), Acronis Cyber Infrastructure, an NFS folder (Linux and macOS agents), Secure Zone and SFTP; if no port is specified for SFTP, port 22 is used. The same documentation is equally clear about two limits: backing up to FTP servers is not supported, and a folder open to anonymous access cannot be used as a backup destination (Acronis Cyber Protect 16 Web Help).
In cloud management, one additional destination comes into play: Direct Backup to Public Cloud, which lets you back up straight to public-cloud-compatible storage without deploying a separate gateway component. This option has one prerequisite — backing up to public cloud requires a Local backup storage quota (Acronis Cyber Protect Cloud User Guide). Conversely, SFTP, tape devices, Acronis Storage Node, Acronis Cyber Infrastructure destinations and deduplication are available only in on-premises deployment; tape and Storage Node are additionally absent from the Standard edition (Acronis Cyber Protect 16 Web Help).
| Backup destination | On-premises management | Cloud management | Note |
|---|
| Acronis cloud storage | Yes | Yes | The off-site leg of 3-2-1 |
| Local folder / directly attached disk | Yes | Yes | Fastest recovery tier |
| Network folder (SMB/CIFS/DFS) | Yes | Yes | Anonymously accessible shares not supported |
| NFS folder | Yes | Yes | On Linux and macOS agents |
| Secure Zone | Yes | Yes | Protected partition on the machine's own disk |
| SFTP | Yes | No | Port 22 used if no port is specified |
| Acronis Cyber Infrastructure | Yes | No | ACI-based immutable storage lives here |
| Acronis Storage Node | Yes (Advanced) | No | Not in the Standard edition |
| Tape library | Yes (Advanced) | No | Not in the Standard edition |
| Direct backup to public cloud | No | Yes (Advanced) | Requires a Local backup storage quota |
| Deduplication | Yes | No | Reduces storage consumption |
| FTP server | No | No | Not officially supported |
The architecture we typically build in practice is this: a fast, short-retention backup to a local disk or network folder for critical workloads, replication of that same backup to cloud storage, and long-term retention held on the cloud side. Day-to-day recovery requests are then served from the local copy in seconds to minutes, while the off-site copy remains available in a building- or hardware-level incident. Organisations that prefer on-premises deployment can use tape or a Storage Node managed by Acronis Cyber Protect 16 for the third copy.
What does immutable storage actually deliver against ransomware?
Short answer: immutable storage keeps deleted or modified backup files recoverable for a defined retention period. That means even if an administrator account is compromised and someone tries to delete backups from the console, a point to roll back to remains. This is the most critical difference backup makes in a ransomware scenario, because in modern attacks destroying the backups is a step that comes before encryption.
The technical prerequisites of the feature are set out clearly in the official documentation. In cloud deployment, immutable storage is supported on Acronis-hosted or partner-hosted cloud storage running Acronis Cyber Infrastructure 6.0.1 or later and requires a protection agent of at least version 24.01 (build 24.1.37195); in on-premises deployment, ACI 6.0.1 or later and agent version 16.0.37277 or later are required. Only backups in TIBX (Version 12) format are supported (Acronis Cyber Protect 16 Web Help).
The difference between the two modes matters as much operationally as it does at purchase. In Governance mode, immutable storage can be switched on and off and the retention period can be changed. Compliance mode, by contrast, is irreversible: in this mode immutable storage cannot be turned off, the retention period cannot be changed and you cannot revert to Governance mode. For that reason we recommend Compliance mode only for data sets with a clear legal retention obligation, and only with the scope calculated in advance. The good news is that protection comes on by default: since September 2024, immutable storage in Governance mode with a 14-day retention period has been enabled by default on all Acronis-hosted storage, for all Partner and Customer tenants (Acronis Cyber Protect 16 Web Help).
Encryption is the natural complement to immutable storage. In Acronis backup encryption, the AES algorithm runs in Galois/Counter (GCM) mode with a randomly generated 256-bit key; that key is itself encrypted with AES-256 using the SHA-2 (256-bit) hash of the password as the key, and the password is never stored anywhere on disk or in the backups (Acronis Cyber Protect 16 Web Help). The operational consequence of this design is significant: if the password is lost, the backups cannot be recovered even by Acronis. During deployment we insist that encryption passwords are stored in a corporate password vault and written into the recovery procedure. Scanning backups for malware in order to identify a clean restore point, meanwhile, is a capability that comes with the Acronis Advanced Security + EDR add-on.
How do bare-metal recovery and restore to dissimilar hardware work?
Short answer: because an image-level backup covers the entire disk including the operating system, applications and configuration, it can be restored directly to bare hardware. According to the official Acronis recovery cheat sheet, physical Windows and Linux machines can be recovered both from the Cyber Protect console and with bootable media; physical macOS machines can only be recovered with bootable media. Bootable media is mandatory for bare-metal recovery and for restoring to an offline machine (Acronis Cyber Protect 16 Web Help).
When the hardware changes, the tool that steps in is Universal Restore. In a recovery to dissimilar hardware, if the operating system will not start, Universal Restore updates the drivers and modules that are critical for boot so that the system can start; it applies to Windows and Linux and is run from bootable media (Acronis Cyber Protect 16 Web Help). In practice this means you can replace a failed server with a machine from a different vendor or with a different disk controller and still restore from the same backup; migrating a physical machine into a virtual environment uses the same mechanism.
For organisations that want to open recovery up beyond the IT team, One-click recovery is a separate option — but its scope is limited. The feature can only be used with Acronis Cyber Protect Advanced and Acronis Cyber Protect Backup Advanced licenses, and it supports only Secure Zone, network folder and cloud storage destinations (Acronis Cyber Protect 16 Web Help). In a design that uses tape or SFTP as the backup destination, you need to factor in at the architecture stage that this feature will not work.
The only way to know that bare-metal recovery really works is to try it. In deployment projects we keep the following steps standard: preparing and storing bootable media in advance for every critical workload, testing the media on the hardware where recovery will be performed, verifying access credentials to the network folder and cloud destination from the bootable environment, writing the encryption password into the recovery procedure, and running a full bare-metal drill at least once a year. If you need to recover a large number of machines over the network in an on-premises deployment, a PXE server can be used; this component is offered only in on-premises management and with the Advanced edition (Acronis Support KB 73376, 2025).
How far can you tighten your RPO and RTO targets with Acronis Cyber Backup?
Short answer: RPO (Recovery Point Objective) defines the acceptable data-loss window — the time between the last valid backup and the moment of the incident; RTO (Recovery Time Objective) is the time accepted for a workload to become operational again. In the backup core, RPO is determined by backup frequency and RTO by the recovery method. It is possible to tighten both at once, but doing so increases cost and architectural complexity, which is why targets should be set separately for each workload.
On the RPO side, the most commonly used tool is scheduling: hourly or more frequent incremental backups for critical databases and daily backups for file servers are a typical starting point. If a narrower window is needed, continuous data protection (CDP) comes into play; the current Cyber Protect Cloud documentation defines CDP as part of standard protection and also states its limits: it works only on the NTFS file system, on Windows 7 and later and Windows Server 2008 R2 and later, only for local folders, and it cannot be used together with the Application backup option (Acronis Cyber Protect Cloud User Guide).
On the RTO side, what matters is where the data comes back from and how. Restoring a single file takes minutes, while a full restore of a server to bare hardware depends on the data volume and the bandwidth to the destination. The intermediate layer that shortens this time is Instant Restore: a virtual machine is started directly from a disk-level backup containing an operating system, its disks are emulated from the backup while the machine runs, and storage space is needed only for the changes that accumulate. Acronis recommends keeping this temporary machine for no more than three days and then deleting it or converting it into a permanent virtual machine (Acronis Cyber Protect Cloud User Guide).
| Recovery tier | Typical use | What determines RTO | Prerequisite |
|---|
| File / folder recovery | Accidentally deleted or corrupted file | File size and destination access speed | File or image backup |
| Application object recovery | A single mailbox, database or record | Scope of the application backup | Application backup configuration |
| Bare-metal recovery | An entire failed or encrypted server | Data volume and destination bandwidth | Image backup + bootable media |
| Instant Restore (running a VM from backup) | Keeping the service up while recovery runs | Hypervisor resources and speed of the backup destination | Disk-level backup containing an operating system |
| Disaster Recovery (failover in the cloud) | Site- or infrastructure-level outage | Replication frequency and runbook design | Disaster Recovery add-on and cloud deployment |
Beyond a certain point, targets can no longer be met with backup alone. The official Acronis Advanced Disaster Recovery data sheet explicitly states an RPO and RTO target of under 15 minutes thanks to the RunVM engine (Acronis Advanced Disaster Recovery data sheet, 2022). Targets at that level require the Acronis Disaster Recovery add-on. When setting targets, it is also worth accounting for how long recovery really takes: according to the IBM Cost of a Data Breach Report 2025, 65% of organisations have still not fully recovered from their breach; among those that say they have fully recovered, the process took more than 100 days in 76% of cases and more than 150 days in 26%, while only 2% recovered in under 50 days (IBM & Ponemon, 2025).
Which virtualisation platforms and workloads are in scope?
Short answer: on common hypervisors, backups can be taken at hypervisor level without installing an agent inside the virtual machine; on some platforms, backup is only possible with an agent installed inside the guest operating system. According to the official support matrix, VMware vSphere 4.1 – 8.0 and Hyper-V (Windows Server 2008 – Windows Server 2025) are backed up agentlessly, and Scale Computing HyperCore 8.8 – 9.4 is also supported agentlessly. By contrast, Proxmox VE 7.x and 8.x and Citrix XenServer/Hypervisor 4.1.5 – 8.2 are backed up only with an agent inside the guest operating system (Acronis Cyber Protect 16 Web Help).
For cloud workloads, the rules diverge even further. Microsoft Azure virtual machines can be backed up agentlessly only in cloud deployment mode; Amazon EC2 instances are not supported agentlessly and are protected only with an agent inside the guest operating system. In Red Hat Virtualization 4.2 – 4.5 environments managed with oVirt, agentless backup is possible only in cloud deployment and with an Advanced license (Acronis Cyber Protect 16 Web Help). Because these distinctions change the agent count — and therefore the licensing line items — at the proposal stage, it is important to build the inventory hypervisor by hypervisor.
Edition differences must also be taken into account. According to the Acronis feature comparison knowledge base, hypervisor-level backup for Nutanix and Proxmox is not available in Cyber Protect 16; these capabilities arrive with Cyber Protect 17 in both on-premises and cloud management. In the same source, software inventory, hardware inventory and device discovery with Device Sense are likewise marked only in the 17 column (Acronis Support KB 73376, 2025). When planning a backup architecture in an environment running on Nutanix or Proxmox, the choice of edition is therefore a technical decision, not merely a commercial preference.
Another practical point is agent autonomy: once a protection plan has been deployed to a machine, the agent continues protection operations for 30 days even if communication with the management server is lost (Acronis Cyber Protect 16 Web Help). In branches with weak connectivity or for workloads operating in the field, this behaviour is decisive for continuity of protection. If workload security is to be added alongside backup on the server side, Acronis can be positioned together with server-focused protection solutions such as Trend Micro Deep Security or Bitdefender GravityZone Security for Servers; in that scenario Acronis remains the backup and recovery layer.
KVKK backup obligations and choosing the right package: where should you start?
Short answer: KVKK (Turkey's data protection law) does not mandate a specific product name, but it does define its expectations around backup in concrete terms. The "Backing Up Personal Data" section of the Personal Data Security Guide published by the Turkish Personal Data Protection Authority states that, where data is damaged, destroyed or stolen, the data controller must resume operations as quickly as possible using the backed-up data; that backup strategies against ransomware should be developed; that only the system administrator should be able to access backed-up personal data; and that data set backups must be kept off the network (KVKK Personal Data Security Guide).
These clauses map directly onto the Acronis side. The expectation to "resume operations as quickly as possible" requires the RTO target to be written down and fast recovery paths such as Instant Restore to be tested in advance. The "keep off the network" expectation is met through replication to cloud storage, or with tape in an on-premises deployment. "Only the system administrator should have access" is delivered through role-based access and backup encryption; a strategy against ransomware, meanwhile, means having immutable storage enabled, choosing the retention period deliberately and verifying that the restore point is clean.
Choosing a package comes down to the answers to three questions. The first is whether the management console will run inside the organisation or in the cloud; organisations that want on-premises management head towards Acronis Cyber Protect 16, while those that want subscription-based, centralised management head towards Acronis Cyber Protect Cloud. The second question is whether the security layer will sit on the same agent as backup; if it will, Advanced Security + EDR is added. The third question is whether patching, inventory and remote management will also move into the same console; if so, Acronis Advanced Management comes into play. If you would like to compare other brands and products, you can review the full portfolio on our solutions page.
The infrastructure side of the backup architecture should not be neglected either. Planning storage capacity, making sure backup windows do not collide with production load, setting up monitoring and alerting channels, and putting recovery drills on the calendar all determine the lasting success of the project; this is where our DevOps and infrastructure services come in.
Share your current backup solution, your workload inventory and your recovery objectives, and we will determine together which license edition, which backup destinations and which retention policy are right on the Acronis Cyber Backup side. Let us prepare a proposal covering scope, migration plan and deployment steps. Get in touch via our contact page — we work with local technical support in Turkish, recovery drills and post-deployment operational support included.