Acronis Cyber Protect 16 is the on-premises edition of Acronis Cyber Protect, in which the management server runs on the organization's own network. Both the backups and the management plane can stay inside the organization's boundaries; capabilities such as tape libraries, Acronis Storage Node, deduplication, PXE server and Forensic Mode exist only in this model. In return, EDR, Microsoft 365 cloud-to-cloud backup and disaster recovery as a service are offered only in the cloud deployment.
This model is preferred by organizations that are constrained by contract or internal policy over data residency and the location of the management plane. The risk picture behind that decision is clear: the Verizon 2025 Data Breach Investigations Report examined 22,052 security incidents and 12,195 confirmed data breaches across 139 countries and reports that ransomware was present in 44% of breaches; the previous year the figure was 32%, and it rises to 88% in SMB breaches (Verizon DBIR, 2025). The same report cites SMBs' lower likelihood, compared with large organizations, of holding current and readily accessible backups as an advantage for attackers.
At Sora Yazılım we license Acronis Cyber Protect 16 within the Acronis solution family, install the management server, design the protection plans and retention policies, and run the recovery drills. For the subscription-based, cloud-managed equivalent, see the Acronis Cyber Protect Cloud page; the official feature differences between the two models are given as a table on this page.
What is Acronis Cyber Protect 16 and what does the on-premises deployment change?
Short answer: Cyber Protect 16 is the deployment model that uses the same protection agent but runs the management server on the organization's own infrastructure. The official Acronis documentation separates the two deployment models as follows: in the on-premises deployment the management server sits on the organization's network, while in the cloud deployment it sits in one of the Acronis data centers. In both models, once a protection plan has been deployed to a machine the agent continues protection operations for 30 days even if communication with the management server is lost (Acronis Cyber Protect 16 Web Help).
The practical consequences of the on-premises deployment fall under three headings. First, management traffic and console access stay inside the corporate network; protection can be managed in segments that have no internet access or are tightly restricted. Second, the components specific to enterprise backup infrastructure — tape libraries, Acronis Storage Node, deduplication, the PXE boot server — are available only in this model. Third, some capabilities delivered as a cloud service are absent from this model; that is not a shortcoming but an architectural distinction, and it needs to be known before purchase.
According to the official Acronis documentation, perpetual licenses can be used only in the on-premises deployment; the SFTP server, tape devices, Acronis Storage Node and Acronis Cyber Infrastructure backup destinations as well as deduplication are also available only in this model, and moreover tape and Storage Node are not included in the Standard edition (Acronis Cyber Protect 16 Web Help). An honest caveat is due here: the official Acronis licensing knowledge base, updated on June 8, 2026, lists only the subscription and cloud storage licensing schemes and does not mention perpetual licensing (Acronis Support KB 73387). For that reason we verify the expectation "I can buy a perpetual license" together with you at the quotation stage, against Acronis's current official licensing scheme; we do not generalize.
What is the difference between Cyber Protect 16 and Cyber Protect Cloud?
Short answer: the difference is not where the backup is written but where the management server runs and, consequently, which capabilities are switched on. In both models the backup can be written to a local disk, a network folder or the cloud. The table below follows the rows in Acronis's official feature comparison knowledge base; the phrase "Advanced required" indicates that the capability in question requires the Advanced edition.
| Capability | Cyber Protect 16 (on-premises) | Cyber Protect Cloud (cloud) |
|---|
| Location of the management server | The organization's own network | Acronis data center |
| Tape destination and tape management | Yes (Advanced required) | No |
| Acronis Storage Node destination, ASN management and data catalog | Yes (Advanced required) | No |
| Deduplication | Yes (Advanced required) | No |
| SFTP backup destination | Yes | No |
| Immutable storage based on Acronis Cyber Infrastructure | Yes (Advanced required) | No |
| Immutable storage for cloud storage | No | Yes |
| PXE server | Yes (Advanced required) | No |
| Forensic Mode | Yes (Advanced required) | No |
| Rejoining the domain after recovery | Yes | No |
| Centralized dashboard for multiple management servers | Yes | No |
| VMware vSphere Web Client plug-in | Yes | No |
| Endpoint Detection and Response (EDR) | No | Yes (Advanced required) |
| DLP Device Control / DLP Advanced Limited | No | Yes (Advanced required) |
| Microsoft 365 and Google Workspace cloud-to-cloud backup | No | Yes |
| Direct backup to public cloud (Azure, Amazon S3, S3-compatible) | No | Yes (Advanced required) |
| Mobile device backup | No | Yes |
| Agent uninstall protection | No | Yes |
| Disaster recovery as a service | No | Yes |
| One-click recovery, Notary, eSign, Advanced Reports, shared backup policy | Yes (Advanced required) | Yes (Advanced required) |
| Recovery of BitLocker-protected workloads, Intel TDT, Windows Defender management, Synology NAS backup, physical data shipping | Yes | Yes |
The table is compiled from Acronis's official feature comparison knowledge base, updated on October 23, 2025, and from the product documentation (Acronis Support KB 73376, Acronis Cyber Protect 16 Web Help). The same knowledge base also contains columns for Cyber Protect 17: agentless backup for Nutanix and Proxmox, software inventory, hardware inventory and device discovery with Device Sense are capabilities absent from Cyber Protect 16 and introduced with Cyber Protect 17. We take this distinction into account when planning versions.
The decision rule in practice is this: if the management plane must stay inside the organization's boundaries, if a tape or deduplication architecture is in use, and if endpoint detection and response is supplied by another product, then Acronis Cyber Protect 16 is the right choice. If, on the other hand, EDR, SaaS data protection and disaster recovery in the order of minutes are the priority, you need to move to the Acronis Cyber Protect Cloud side. Hybrid designs that use both models are also possible; critical workloads can sit under cloud management while regulated data stays under on-premises management.
Which license edition covers which workload?
Short answer: the edition you choose is directly tied to the type of workload you will protect. The official Acronis licensing knowledge base maps workload types to editions as follows (Acronis Support KB 73387, June 8, 2026):
| Workload type | Standard | Advanced | Backup Standard | Backup Advanced | Email Archiving |
|---|
| Workstation | Yes | Yes | Yes | Yes | No |
| Windows Server Essentials | Yes | No | Yes | No | No |
| Server | Yes | Yes | Yes | Yes | No |
| Virtual Host | Yes | Yes | Yes | Yes | No |
| Public Cloud VM | Yes | Yes | Yes | Yes | No |
| Universal License | No | Yes | No | Yes | No |
| Microsoft 365 | No | No | Yes | Yes | Yes |
| Google Workspace | No | No | Yes | Yes | No |
The point to note in the table is this: the Backup Standard edition is no longer sold; only existing Cyber Protect 15 customers with active maintenance can use it. In new projects, therefore, the choice is in practice made between Standard, Advanced and Backup Advanced. According to Acronis's official positioning, Standard covers standard backup and multi-layered protection for SMBs (data protection maps, URL filtering and categorization, continuous data protection, disk health); Advanced adds support for additional workloads, shared protection plans, safe recovery of backups, malware scanning in backups, dashboard configuration and security posture assessment for larger and more complex environments; and Backup Advanced offers group management, shared protection plans, off-host data processing, tape support, deduplication and customizable reporting (Acronis licensing page).
In virtualization environments the license type is subject to a separate set of rules. According to the same knowledge base, a Virtual Host or Per-VM license is used for VMware and Hyper-V, and these environments are supported with the Standard edition too. Azure Stack HCI, KVM, Nutanix and Citrix Hypervisor environments require a Per-VM or Virtual Host license; however, they are supported only in the Advanced or Backup Advanced editions. On the Public Cloud VM side, one Per-VM license covers three virtual machines and applies to all editions. With the Universal Workload license, one license corresponds to one workload (physical machine, virtual machine or host), and it exists only in the Advanced and Backup Advanced editions (Acronis Support KB 73387).
These rules can mean that two organizations with the same number of servers need completely different license structures. We do not publish prices; once you share your workload inventory and hypervisor mix, we prepare a proposal sized with the right edition and the right license type. You can reach us through our contact page.
Which virtualization platforms and backup destinations are supported?
Short answer: VMware vSphere and Hyper-V are backed up from the hypervisor level (agentless), while some platforms are backed up only with an agent inside the guest operating system. Acronis's official support matrix states the following: VMware vSphere 4.1–8.0 and Hyper-V (Windows Server 2008 – Windows Server 2025) are backed up agentlessly; Scale Computing HyperCore 8.8–9.4 is supported agentlessly; Proxmox VE 7.x/8.x and Citrix XenServer / Hypervisor 4.1.5–8.2 are backed up only with an agent inside the guest OS (Acronis Cyber Protect 16 Web Help).
On the cloud virtual machine side the limits are sharper. Microsoft Azure virtual machines can be backed up agentlessly only in the cloud deployment mode; Amazon EC2 instances are not supported agentlessly and are backed up only with an agent inside the guest OS. For Red Hat Virtualization 4.2–4.5 managed with oVirt, agentless backup is possible only in the cloud deployment and with an Advanced license (Acronis Cyber Protect 16 Web Help). In mixed environments these lines directly shape the decision about which workload is managed under which deployment model.
On the backup destination side, Cyber Protect 16 officially supports the following: cloud storage, local folder, network folder (SMB/CIFS/DFS), Acronis Cyber Infrastructure, NFS folder (Linux and macOS), Secure Zone and SFTP — and if no port is specified for SFTP, port 22 is used. Backup to FTP servers is not supported; backup to a folder with anonymous access is not supported either (Acronis Cyber Protect 16 Web Help). Tape libraries and Acronis Storage Node, meanwhile, are available only in the Advanced edition and only in the on-premises deployment.
Sizing the storage and server layer correctly is the most critical part of this design. The performance of the backup repository directly determines restore time, and in most organizations the bottleneck appears on the read side rather than the write side. If a hardware refresh or a new backup repository design is on the agenda, we plan capacity together through our HPE server solutions and our Dell server solutions; our DevOps and infrastructure services step in for needs on the virtualization, monitoring and automation side.
How are on-premises backups protected against ransomware?
Short answer: two mechanisms are essential — immutable storage and strong encryption. In the on-premises deployment, immutable storage requires Acronis Cyber Infrastructure 6.0.1 or later and a protection agent at version 16.0.37277 or later; only backups in the TIBX (Version 12) format are supported (Acronis Cyber Protect 16 Web Help).
The difference between the two modes of immutable storage matters especially because it involves an irreversible decision. In Governance mode, immutability can be turned off and on again and the retention period can be changed. Compliance mode, once selected, cannot be turned off, its retention period cannot be changed and there is no way back to Governance mode (Acronis Cyber Protect 16 Web Help). In audited organizations Compliance mode produces strong evidence; but because it cannot be undone if it is enabled with the wrong retention period, we do not apply that decision without tying it to a written retention policy.
On the encryption side, Acronis runs the AES algorithm in Galois/Counter (GCM) mode with a randomly generated 256-bit key; that key is encrypted with AES-256, using the SHA-2 (256-bit) hash of the password as the key, and the password is stored nowhere, neither on disk nor in the backups (Acronis Cyber Protect 16 Web Help). If the password is lost the backup cannot be recovered; that is why we set up key storage and handover as a separate procedure.
On top of these two mechanisms, the 3-2-1 approach — at least three copies of the data, two different media, one copy off-site — is embedded as a design principle in the protection plans. Because tape and Acronis Storage Node can be used in the on-premises deployment, the "two different media" condition is met naturally in this model. The trend on the threat side supports the investment too: according to the Acronis H2 2025 Cyberthreats Report, more than 7,600 ransomware victims were publicly disclosed worldwide in the second half of 2025, and the most active group was Qilin with 962 victims (Acronis, 2026). ENISA Threat Landscape 2025, in turn, examined 4,875 incidents between July 1, 2024 and June 30, 2025 and identified the leading initial access routes as phishing (60%) and vulnerability exploitation (21.3%) (ENISA, 2025).
One limit of the on-premises model has to be stated plainly here: Endpoint Detection and Response is listed in the official feature matrix only in the cloud column and only with the Advanced condition; EDR does not appear in the on-premises management server column (Acronis Support KB 73376). Organizations that need attack chain analysis and response at the endpoint either move to cloud management for Acronis Advanced Security + EDR, or source that layer from another product. In server and virtualization-heavy environments Trend Micro Deep Security, and in organizations that want to bring endpoint and server protection into one console Bitdefender GravityZone Security for Servers, can be designed alongside the Acronis backup layer.
How is recovery performed in a disaster, and how does the bare-metal scenario work?
Short answer: the recovery path depends on the state of the target machine. According to the official Acronis "Recovery cheat sheet" document, physical Windows and Linux machines can be recovered both from the Cyber Protect console and with bootable media; physical macOS machines can be recovered only with bootable media; and bootable media is mandatory for bare-metal recovery and for recovery to an offline machine (Acronis Cyber Protect 16 Web Help).
When the hardware changes, a separate tool comes into play. Universal Restore is the tool that, in a recovery to dissimilar hardware, updates the drivers and modules that are critical for boot if the operating system does not start; it applies to Windows and Linux and is run from bootable media (Acronis Cyber Protect 16 Web Help). In server refresh projects, and when a different model of machine replaces failed hardware, the success of the recovery depends largely on this step having been tested in advance.
Instant Restore is used to shorten the service outage: a virtual machine is started directly from a disk-level backup that contains the operating system, its disks are emulated from the backup while the machine runs, and storage space is needed only for the changes that occur. Acronis recommends keeping the temporary machine for no more than three days and then deleting it or converting it into a permanent virtual machine (Acronis user guide). If you want end users to be able to start a recovery without administrator intervention, One-click recovery is brought in; however, this feature can be used only with the Acronis Cyber Protect Advanced and Acronis Cyber Protect Backup Advanced licenses, and it supports only the Secure Zone, network folder and cloud storage destinations (Acronis Cyber Protect 16 Web Help).
None of these tools on its own delivers a recovery time commitment in the order of minutes. The official Acronis Advanced Disaster Recovery data sheet explicitly states an RPO and RTO target of under 15 minutes thanks to the Acronis RunVM engine (Acronis Advanced Disaster Recovery data sheet, 2022); but this add-on requires a cloud deployment and an active Acronis Cyber Protect subscription (Acronis Support KB 73387). For organizations that use on-premises management and at the same time have an aggressive RTO target, we design a hybrid setup; for the details see our Acronis Disaster Recovery page.
The impact of recovery time on the business is a measurable cost. According to the IBM Cost of a Data Breach Report 2025, 65% of organizations have still not fully recovered from a breach; among those that say they have fully recovered, 76% took more than 100 days and 26% more than 150 days, and only 2% recovered in under 50 days. The same report puts the global average cost of a data breach at USD 4.44 million (USD 4.88 million in 2024) (IBM & Ponemon, 2025). That is why we schedule the recovery drill at least once a year, preferably including the bare-metal scenario.
What does the on-premises model provide in terms of KVKK and data residency?
Short answer: full control over the physical location of the data, and direct demonstrability of the backup obligations. The "Backing Up Personal Data" section of the Personal Data Security Guide published by the Personal Data Protection Authority under KVKK (Turkey's data protection law) states that, if data is damaged, destroyed or stolen, the data controller must resume operations as quickly as possible using the backed-up data; that developing data backup strategies against ransomware is recommended; that only the system administrator should be able to access backed-up personal data; and that data set backups must be kept strictly off the network (KVKK Personal Data Security Guide).
Cyber Protect 16 produces an answer to each of these items: the off-network requirement can be met with tape or with an Acronis Storage Node in a separate storage segment, access restriction is built with role-based management, and the phrase "resume operations as quickly as possible" is evidenced with measurable RPO/RTO targets and regular recovery tests. In organizations that process card data, backups of systems in PCI DSS scope are expected to be kept under a separate retention policy and in encrypted form, while in finance and the public sector audit trails are expected to be reportable; the advanced reporting (Advanced Reports) and shared protection plans offered in the Advanced editions meet that need.
On independent test results the scope has to be kept precise. In the AV-TEST Windows 11 business user test for the January–February 2026 period, Acronis Cyber Protect 25.11 scored Protection 6.0/6.0, Performance 6.0/6.0 and Usability 6.0/6.0, winning the "TOP PRODUCT" award with 18.0/18.0 points; the threshold for that award is 17.5 points (AV-TEST, 2026). The version tested, however, is 25.11; that is the version number of the cloud-managed agent line, and it is not the same as the 16.0.x agent line of the on-premises Cyber Protect 16. For that reason we do not present the result as proof of the protection quality of Acronis Cyber Protect 16; we report it, together with the test period, as a reference showing that the Acronis malware engine achieved a perfect score in an independent business test. If you are looking for an independent test result on a per-product basis, we check together which version was tested.
Sora Yazılım's approach to rolling out Acronis Cyber Protect 16 consists of the following steps: producing the workload inventory and the hypervisor mix; determining the recovery targets (RPO/RTO) together with the business units; selecting the right license edition and license type; installing and backing up the management server; sizing the backup repository and the tape/Storage Node architecture; tying the immutable storage mode and retention period to a written policy; establishing a procedure for storing the encryption password; running a bare-metal recovery test with bootable media and Universal Restore; and setting up the reporting and alerting channels. In environments where a backup-only scope is sufficient, we also assess at this stage the differences between the Acronis backup editions.
Let us assess together whether Acronis Cyber Protect 16 is the right fit for your organization, taking your data residency requirements and your existing virtualization infrastructure into account. Share your server and virtual machine inventory, your retention periods and your recovery targets, and we will prepare a proposal covering the license edition, storage design, management server architecture and rollout plan. Reach us through our contact page — Turkish-language technical support, deployment and post-deployment operational support are included in how we work.