Acronis Cyber Protect Cloud is a subscription-based cloud management platform that unifies backup, disaster recovery and endpoint security in a single agent. The management server runs not on the organization's own network but in one of the Acronis data centers; the protection agent is deployed to the workloads and consumption is measured by the number of protected workloads and by storage. Capabilities such as EDR, patch management, email security and disaster recovery are enabled on the platform as add-on packs.
Threat data explains why this model has spread so widely. According to the Acronis H2 2025 Cyberthreats Report, more than 7,600 ransomware victims were publicly disclosed worldwide in the second half of 2025; the most active groups were Qilin (962 victims), Akira (726) and Cl0p (517), and phishing accounted for 83% of email threats (Acronis Cyberthreats Report H2 2025). The Verizon 2025 Data Breach Investigations Report, meanwhile, examined 22,052 security incidents and 12,195 confirmed data breaches across 139 countries: ransomware was seen in 44% of breaches (32% the previous year), and that share climbed to 88% in SMB breaches while remaining at 39% in large organizations (Verizon DBIR, 2025).
What sets Acronis Cyber Protect Cloud apart is that both fronts — data loss and attack — are managed in the same agent and the same console. At Sora Yazılım we license the platform within the Acronis solution family, build the tenant architecture, design the protection plans and, on request, operate it under a managed service model. In scenarios where the management server has to stay inside the organization's boundaries, the equivalent is Acronis Cyber Protect 16; the official feature differences between the two models are set out as a table below.
What does Acronis Cyber Protect Cloud cover and which workloads does it protect?
Short answer: with a single agent it backs up a broad set of workloads, from physical servers and workstations to virtual machines, and from databases to SaaS mailboxes; the same agent also takes on security functions such as behavioral ransomware prevention, vulnerability assessment and device control. The current Acronis product page describes the platform as a solution supporting more than 30 platform and workload types (Acronis Cyber Protect Cloud product page, 2026).
The capabilities specific to the cloud deployment are set out as a separate list in the official documentation: Microsoft 365 and Google Workspace cloud-to-cloud backup, backup to public cloud, EDR, Virtuozzo / oVirt / Virtuozzo Hybrid Infrastructure / Nutanix hypervisor-level agents, disaster recovery as a cloud service, Cyber Scripting, remote desktop, machine learning-based workload monitoring and hardware inventory (Acronis Cyber Protect 16 Web Help). This list is the technical answer to the question "why the cloud model".
The technical limits we take into account during the scoping exercise are as follows:
- Backup destinations: cloud storage, local folder, network folder (SMB/CIFS/DFS), NFS folder (Linux/macOS) and Secure Zone. The SFTP, tape device, Acronis Storage Node and Acronis Cyber Infrastructure destinations, along with deduplication, exist only in the on-premises deployment.
- Direct backup to public cloud: backups can be written to public cloud compatible storage without installing an additional gateway component; this method does, however, require a Local backup storage quota.
- Virtualization: Microsoft Azure virtual machines can be backed up agentlessly only in the cloud deployment mode; Amazon EC2 instances are not supported agentlessly and are backed up only with an agent inside the guest OS.
- Continuous data protection (CDP): in the current documentation this is part of standard protection; it works only on the NTFS file system, on Windows 7 / Windows Server 2008 R2 and later, and only for local folders, and it cannot be used together with the Application backup option.
- Agent autonomy: once a protection plan has been deployed to a machine, the agent continues protection operations for 30 days even if communication with the management server is lost.
Every one of these lines is taken from the official Acronis product documentation (backup destinations, supported virtualization platforms, continuous data protection, deployment models). Verifying these items one by one against your own environment before purchase prevents the surprises that otherwise surface during rollout; we run the scoping exercise with exactly this checklist.
How does the subscription and multi-tenant (MSP) model work?
Short answer: the platform is built on a tenant hierarchy. Customer tenants are created beneath a partner tenant; each customer operates in isolation with its own users, quotas and protection plans, and service items can be switched on and off per customer. Because billing follows protected workloads and consumed storage, opening a branch, a seasonal capacity increase or a change in the customer base does not force the license structure to be redesigned.
This flexibility is a direct business model advantage for managed service providers: backup and security are delivered under a single contract, protection plans are replicated as templates and reporting is standardized per customer. On the enterprise side, the same structure naturally accommodates a split by department, subsidiary or branch. In these scenarios Sora Yazılım designs the tenant tree, the quota policies and the alert channels as part of the rollout project; our DevOps and infrastructure services step in for needs on the infrastructure, automation and monitoring side.
One point deserves emphasis: add-ons do not have to be enabled across the entire fleet at once. For example, the official Acronis licensing knowledge base states that the disaster recovery add-on is licensed per workload and requires an active Acronis Cyber Protect subscription and a cloud deployment; a 1-year subscription includes 2,000 compute points, a 3-year subscription 6,000 and a 5-year subscription 10,000, and 2,000 points correspond roughly to two weeks of failover/test usage per year (Acronis Support KB 73387, 2026). For scoping and a quote, you can reach us through our contact page.
What is in the standard subscription, and what do the Advanced add-on packs add?
Short answer: the standard Acronis Cyber Protect Cloud subscription already includes file, disk, image and application backup, flexible recovery, backup encryption, vulnerability assessment, Microsoft 365 and Google Workspace protection, and monitoring and reporting. The Advanced packs add specific areas of depth on top of that base. The table below follows the "what the pack adds" lists in Acronis's own data sheets.
| Add-on pack | Main capabilities added by the pack | Typical rationale |
|---|
| Advanced Backup | Microsoft SQL cluster, Microsoft Exchange cluster, Oracle DBMS Real Application cluster and SAP HANA backup; full or granular recovery for MariaDB and MySQL databases; data protection map and compliance reporting; off-host data processing (source: Acronis Advanced Backup data sheet, 2021-12) | Cluster configurations and large databases; an obligation to produce reports for audit |
| Advanced Security + EDR | Full-stack anti-malware, URL filtering, exploit prevention, anti-malware scanning of backups in the Acronis Cloud, forensic data collection in backups, CPOC threat feed, automatic allowlisting, AV definition updates during recovery, remote device wipe | Detection and response at the endpoint; being able to select a clean restore point |
| Advanced Management (Acronis RMM) | Software inventory collection, automated patch management, fail-safe patching (automatic system backup before patching), ready-made Cyber Scripting scripts, disk health monitoring, remote desktop and remote assistance (Windows, Mac, Linux) | Moving patch and inventory management into the same console |
| Advanced Disaster Recovery | Production and test failover to the Acronis Cloud, VPN-less deployment option, IPsec multi-site VPN and L2 site-to-site OpenVPN, multiple runbook templates, custom DNS configuration, DR for DHCP servers, failover to a malware-free recovery point | Critical workloads with RTO/RPO targets in the order of minutes |
| Advanced Email Security | Spam filter, anti-evasion (recursive unpacking), six-source threat intelligence, static signature analysis, anti-phishing with four URL reputation engines and image recognition, anti-spoofing with SPF/DKIM/DMARC, Perception Point CPU-level dynamic detection, incident response service, outbound email scanning for M365 | Stopping phishing before it reaches the mailbox |
| Advanced File Sync and Share | Remote file notarization, embedded eSigning, notarization and signature certificates — End of Life as of December 31, 2025 | Not positioned in new projects; a transition is planned for existing users |
The rows in the table are taken from Acronis's own data sheets: Advanced Backup data sheet (2021), Advanced Security data sheet, Advanced Management data sheet (2023), Advanced Disaster Recovery data sheet (2022) and Advanced Email Security data sheet (2023). On the file synchronization side, the Files Sync and Share and Advanced Files Sync and Share (Notarization and eSignature) functions reached End of Life as of December 31, 2025; mainstream support ended on that date and extended support ends on December 31, 2026 (Acronis Support KB, 2026). For that reason we do not meet file sharing requirements with this pack in new projects.
We maintain a separate detailed page for each pack: Acronis Advanced Security + EDR, Acronis Advanced Management, Acronis Advanced Email Security and Acronis Disaster Recovery. The most common mistake in add-on selection is buying a pack without noticing that the required capability is already in the standard subscription. Continuous data protection (CDP), for instance, is listed as a feature added by the pack in the 2021 Advanced Backup data sheet, while the current Cyber Protect Cloud documentation defines it as part of standard protection (Acronis Cyber Protect Cloud user guide). We verify differences of this kind against the current documentation at the quotation stage.
What is the difference between Cyber Protect Cloud and Cyber Protect 16?
Short answer: the difference does not lie in the question "am I backing up to the cloud" but in where the management server runs and, consequently, which capabilities are switched on. In both models, backups can be written to a local disk, a network folder or the cloud. The distinction is the location of the console and the capability differences listed in the official Acronis feature matrix.
| Topic | Cyber Protect Cloud (cloud deployment) | Cyber Protect 16 (on-premises deployment) |
|---|
| Location of the management server | Acronis data center | The organization's own network |
| Endpoint Detection and Response (EDR) | Yes (Advanced edition required) | No |
| DLP Device Control / DLP Advanced Limited | Yes (Advanced edition required) | No |
| Microsoft 365 and Google Workspace cloud-to-cloud backup | Yes | No |
| Direct backup to public cloud (Azure, Amazon S3, S3-compatible) | Yes (Advanced edition required) | No |
| Anti-malware scanning of Microsoft 365 backups | Yes | No |
| Mobile device backup | Yes | No |
| Agent uninstall protection | Yes | No |
| Immutable storage for cloud storage | Yes | No |
| Immutable storage based on Acronis Cyber Infrastructure | No | Yes (Advanced edition required) |
| Tape destination and tape management | No | Yes (Advanced edition required) |
| Acronis Storage Node destination, ASN management and deduplication | No | Yes (Advanced edition required) |
| PXE server | No | Yes (Advanced edition required) |
| Forensic Mode | No | Yes (Advanced edition required) |
| Rejoining the domain after recovery | No | Yes |
| Centralized dashboard for multiple management servers | No | Yes |
| VMware vSphere Web Client plug-in | No | Yes |
| One-click recovery, Notary, eSign, Advanced Reports, shared backup policy | Yes (Advanced edition required) | Yes (Advanced edition required) |
The table is compiled from Acronis's official feature comparison knowledge base and product documentation (Acronis Support KB 73376, October 23, 2025, Acronis Cyber Protect 16 Web Help). The practical decision rule is this: if keeping the management plane inside the organization's boundaries is mandated by contract or internal policy, choose Acronis Cyber Protect 16; if detection and response, SaaS data protection and disaster recovery as a service take priority, choose Acronis Cyber Protect Cloud. For organizations that need backup only and source the security layer from another vendor, the licensing distinction on the Acronis backup editions side is what to examine.
Keeping endpoint security on a different platform is also a legitimate design; in that case Acronis is positioned as the backup and recovery layer. Organizations looking for a single console and broad policy control in endpoint protection can build the design together with Bitdefender GravityZone Business Security, while those who want to collect email, cloud and identity signals as well as endpoint signals on one platform can do so with Trend Vision One. These products do not rule Acronis out; the choice is about which layer is managed on which platform, and in two-sided architectures the recovery responsibility stays with Acronis.
How is the integrity of backups protected against ransomware?
Short answer: three mechanisms work together — immutable storage, strong encryption and the ability to select a clean restore point after an attack. Since September 2024, Governance mode immutable storage with a 14-day retention period has been enabled by default on all Acronis-hosted storage, across all Partner and Customer tenants (Acronis Cyber Protect 16 Web Help).
Immutable storage has two modes, and the difference between them involves an irreversible decision. In Governance mode, immutability can be turned off and on again and the retention period can be changed. Compliance mode, once selected, cannot be turned off, its retention period cannot be changed and there is no way back to Governance mode. The technical prerequisites are equally clear: in the cloud deployment, Acronis-hosted or partner-hosted cloud storage running Acronis Cyber Infrastructure 6.0.1 or later and a protection agent of at least version 24.01 (build 24.1.37195) are required; only backups in the TIBX (Version 12) format are supported (Acronis Cyber Protect 16 Web Help).
On the encryption side, Acronis runs the AES algorithm in Galois/Counter (GCM) mode with a randomly generated 256-bit key; that key is encrypted with AES-256, using the SHA-2 (256-bit) hash of the password as the key, and the password is stored nowhere — neither on disk nor in the backups (Acronis Cyber Protect 16 Web Help). The operational consequence matters: losing the password means losing the ability to recover the backup. We treat key storage and handover as a separate line item in the rollout project.
On top of these two mechanisms, the 3-2-1 approach — at least three copies of the data, two different media, one copy off-site — is embedded as a design principle in the protection plans. The Personal Data Security Guide issued under KVKK (Turkey's data protection law) points in the same direction, requiring that data set backups be kept strictly off the network (KVKK Personal Data Security Guide).
Recovery speed is itself a security parameter. According to the IBM Cost of a Data Breach Report 2025, 65% of organizations have still not fully recovered from a breach; among those that say they have fully recovered, 76% took more than 100 days and 26% more than 150 days, and only 2% recovered in under 50 days. The same report puts the global average cost of a data breach at USD 4.44 million (USD 4.88 million in 2024) and notes that 63% of organizations refused to pay a ransom (IBM & Ponemon, 2025).
On the Acronis side, two mechanisms stand out for shortening recovery time. Instant Restore starts a virtual machine directly from a disk-level backup that contains the operating system; while the machine runs, its disks are emulated from the backup and storage space is needed only for the changes that occur. Acronis recommends keeping the temporary machine for no more than three days and then deleting it or converting it into a permanent virtual machine (Acronis Cyber Protect Cloud user guide). For tighter targets the Acronis Disaster Recovery add-on comes into play: the official data sheet explicitly states an RPO and RTO target of under 15 minutes thanks to the Acronis RunVM engine (Acronis Advanced Disaster Recovery data sheet, 2022), and with the add-on up to 23 local networks can be extended to the cloud over a secure VPN tunnel (Acronis Cyber Protect Cloud user guide).
Why should Microsoft 365 and Google Workspace data be backed up separately?
Short answer: the SaaS provider is responsible for the continuity of the infrastructure, not for the data itself. When a deleted mailbox, OneDrive content encrypted by ransomware or a mistaken administrator action exceeds the provider's retention windows, there is no way back. Acronis Cyber Protect Cloud backs this data up in a cloud-to-cloud model, independently of the organization's endpoints; the official documentation lists this capability among those available only in the cloud deployment (Acronis Cyber Protect 16 Web Help).
The risk is not abstract. According to the Acronis H1 2025 Cyberthreats Report, malware was found in 1.47% of the Microsoft 365 email backups examined; the same report draws on signals from more than 1,000,000 unique endpoints and states that the number of publicly disclosed ransomware victims between January and June 2025 rose by close to 70% compared with the same period in 2023 and 2024, with manufacturing the most targeted sector at 15% of all cases in the first quarter of 2025 (Acronis Cyberthreats Report H1 2025). ENISA Threat Landscape 2025, in turn, examined 4,875 incidents between July 1, 2024 and June 30, 2025; it identified the leading initial access routes as phishing (60%) and vulnerability exploitation (21.3%), and reported that 53.7% of the incidents involved essential entities in scope of the NIS2 Directive (ENISA, 2025).
On the Google Workspace side, protection covers Gmail mailboxes, Calendars, Contacts, Google Drive and Shared drive data; the official documentation states that up to 5,000 items per company (mailboxes, Drive and Shared drive) can be protected without performance loss (Acronis Cyber Protect Cloud user guide). On the Microsoft 365 side, two capabilities specific to the cloud deployment stand out: anti-malware scanning of backups, and the ability to search encrypted Microsoft 365 / Google Workspace archives (Acronis Support KB 73376).
For Microsoft 365 licensing, tenant configuration and migrations, see our Microsoft 365 solutions. In organizations that aim to stop threats before they reach the mailbox, the Acronis Advanced Email Security add-on is positioned as a complementary layer alongside backup; backup does not replace email security, it takes over in the scenario where email security fails.
KVKK, data residency and rollout: how do you plan this in Turkey?
Short answer: KVKK (Turkey's data protection law) counts backup directly as a technical measure. The "Backing Up Personal Data" section of the Personal Data Security Guide published by the Personal Data Protection Authority states that, if data is damaged, destroyed or stolen, the data controller must resume operations as quickly as possible using the backed-up data; that developing data backup strategies against ransomware is recommended; that only the system administrator should be able to access backed-up personal data; and that data set backups must be kept strictly off the network (KVKK Personal Data Security Guide).
The platform equivalents of these items are concrete: the off-network requirement is met by a cloud destination and immutable storage, access restriction by the tenant and role model, and the phrase "resume operations as quickly as possible" by measurable RPO/RTO targets and regular recovery drills. As for data residency: Istanbul also appears under the "Acronis Cloud DC" heading in the official Acronis data center list; on the same page Acronis lists Google Cloud Platform and Microsoft Azure locations as well, and the product page describes this network as more than 50 locations (Acronis Cyber Cloud Data Centers). Choosing the right storage region when the tenant is created is far easier than moving it later; we settle this decision at the start of the project.
There is an independent reference on protection quality as well. In the AV-TEST Windows 11 business user test for the January–February 2026 period, Acronis Cyber Protect 25.11 scored Protection 6.0/6.0, Performance 6.0/6.0 and Usability 6.0/6.0, winning the "TOP PRODUCT" award with 18.0/18.0 points; the threshold for that award is 17.5 points (AV-TEST, 2026). We always report independent test results together with the test period, because these results change from period to period and are misleading when quoted without a date.
Sora Yazılım's rollout approach consists of the following steps: producing the workload inventory and the recovery targets (RPO/RTO); determining the tenant structure and the storage region; designing backup destinations in line with the 3-2-1 approach; templating protection plans by workload group; defining the immutable storage, retention period and encryption policy; setting the scope of Microsoft 365 and Google Workspace protection; assigning add-on packs only to the workloads that need them; putting recovery drills on the calendar; and establishing the reporting and alerting channels. If detection and response are needed at the endpoint, Advanced Security + EDR is placed inside the same plan; if patch and inventory management are needed, Advanced Management is.
Let us assess together whether Acronis Cyber Protect Cloud is the right fit for your organization, taking your existing backup infrastructure and recovery targets into account. Share the number of your workloads, your retention periods and your data residency requirements, and we will prepare a proposal covering the tenant structure, storage sizing, add-on scope and rollout plan. Reach us through our contact page — Turkish-language technical support, deployment and post-deployment operational support are included in how we work.