
Replication keeps a near-live copy of a server or database on separate hardware, ready to take over within minutes, but it copies every change, including an accidental deletion or a ransomware encryption. A backup keeps dated restore points stored apart from the system, so you can roll back to the hour before the damage. In the backup vs replication decision, most businesses need backups for every system and replication only for the few that cannot be down for hours.
This guide compares backup, replication and snapshots, shows how Veeam handles each, and covers what each costs. If you are still on the first questions, such as whether cloud sync counts as a backup, start with our backup and disaster recovery FAQ. For the two targets that decide between these methods, see RTO vs RPO.
What is the difference between backup and replication?
Microsoft's reliability guidance defines the terms the way an engineer would. Replication maintains multiple copies of live data, called replicas, kept in sync in real time or close to it. A backup is a timestamped copy of data that can be used to restore data that has been lost. Microsoft then draws the line that matters: replication is not the same as backup, because replication synchronizes every change and keeps no old copies. Delete a folder by accident and the deletion reaches every replica.
| Backup | Replication | Snapshot | |
|---|---|---|---|
| What it keeps | Dated restore points, kept for days to years on storage separate from the system | A near-live copy of a server or database on other hardware or at another site | A point-in-time view of a disk or virtual machine, on the same storage or host |
| Recovers from | Deletion, corruption, ransomware and hardware loss; with an offsite copy, loss of the building | Hardware, host or site failure | A bad update or change you want to undo soon after |
| Weak spot | Restoring a large system takes time | Copies mistakes and encryption to the replica | Lost with the disk, host or array it depends on |
| Typical data loss (RPO) | Back to the last backup, often an hour to a day | Seconds to hours, set by the replication interval | Back to the last snapshot |
| Typical recovery time (RTO) | Hours for a full restore; minutes for some systems with instant recovery | Minutes, because the replica is ready to start | Minutes, if the host and storage survive |
| Main cost | Storage for retention, plus offsite and immutable copies | A second set of storage and compute that sits mostly idle, plus bandwidth | Space and performance on production storage |
| Use it for | Every system, including Microsoft 365 | The few systems the business stops without | A short-lived safety net before a change |
The two time rows are the recovery point objective and the recovery time objective. Microsoft's guidance is that backups used for disaster recovery typically support targets measured in hours, while failing over to a passive replica is commonly measured in minutes.
Why isn't replication a backup?
Replication is built to make the copy match the original as quickly as possible. That is what you want when a server dies and what you do not want when the original has been damaged. NIST's contingency planning guide, SP 800-34 Rev. 1, says the same about high-availability systems: corrupted data can propagate through them, and without a backup kept separate from the system, recovery may not be possible.
Ransomware raises the stakes. CISA's #StopRansomware guide tells organizations to keep offline, encrypted backups because many ransomware variants search for reachable backups to delete or encrypt them. A replica on the same network, run with the same administrator accounts, is reachable by design.
Some replication tools keep a short chain of restore points on the replica; Veeam, for example, rolls a replica back to the restore point you choose when you fail over. That helps after a bad patch last night. It does not replace a backup kept offline or in immutable storage for weeks or months.
Where do snapshots fit?
A snapshot freezes a virtual machine or volume at a moment and writes later changes to a separate file. It is fast to take and fast to roll back, which makes it the right tool before a risky upgrade and the wrong tool for protection. Broadcom's guidance for VMware is direct: do not use VMware snapshots as backups, and do not keep a single snapshot longer than 72 hours. Because a snapshot depends on the original disk, losing the disk or the storage array loses the snapshot too.
Backup and replication software use snapshots as a starting point rather than as the copy. Veeam asks the hypervisor for a snapshot, reads the data from that frozen state, then commits the snapshot back into the virtual machine, so the copy is consistent without stopping the server.
Veeam backup vs replication: how does Veeam treat each?
The product name, Veeam Backup & Replication, covers both, and the two jobs produce different things.
- Backup jobs write compressed, deduplicated backup files to a repository and keep restore points under your retention policy. Instant Recovery can run a virtual machine straight from a backup file, which Veeam says brings workloads back in a matter of minutes, with limited disk performance until the machine is moved back to production storage.
- Replication jobs keep an exact copy of a virtual machine in its native format on a target host, in a ready-to-start state. Unlike backup files, replica disks are stored decompressed, so a replica takes more space than a compressed backup of the same machine.
- Recovery point: Veeam's replication documentation recommends replication for virtual machines that need a recovery point of hours, and its continuous data protection feature where you need seconds.
- Location sets the purpose: Veeam describes on-site replication for high availability and off-site replication for disaster recovery.
Cloud backup vs local backup: do you need both?
Usually, yes, because they fail in different ways. A local copy on an appliance or backup server restores fastest, and it is the copy you reach for after a deleted folder or a failed disk. An offsite cloud copy survives fire, flood and theft, and an immutable one survives an attacker who has your administrator password. NIST lists the criteria for choosing offsite storage: distance from the main site, how long retrieval takes, security, environmental protection and cost.
Two cautions. Cloud sync is not cloud backup: OneDrive or Dropbox sync copies deletions and encrypted files just as replication does. And a cloud copy has its own recovery time, set by your internet bandwidth, so restoring a whole server from the cloud can take far longer than restoring it from a local appliance. Test both.
Which fits a small team: backup, replication or both?
Start with backup for everything and add replication only where the recovery time demands it. For a typical small office:
- Back up every server, database and cloud service on a schedule that matches its recovery point, with at least one copy offline or immutable and offsite.
- Back up Microsoft 365 separately. Microsoft keeps the service running; restoring your deleted or encrypted mail and files is your job.
- Replicate only the systems the business stops without, such as an ERP, an order system or a line-of-business database, and only if a restore would take longer than you can wait.
- Use snapshots as a short-lived undo before upgrades, and delete them within days.
- Test restores and failovers on a calendar and write down the measured times.
If no system needs to be back in under a few hours, backups with instant recovery may be all you need, and you skip paying for standby hardware.
What affects cost, implementation and support?
- Backup storage grows with data volume, change rate and retention. As one published example, Veeam lists Veeam Vault immutable cloud storage at $14 per TB per month for its Foundation edition, including API calls and egress within a fair-use allowance for restores, as of October 2026; prices may vary by region.
- Replication pays for a second copy that mostly sits idle: storage the size of the protected machines, compute during tests and failovers, licenses and enough bandwidth to keep up with changes. Microsoft lists Azure Site Recovery at $25 per protected instance per month for replication to Azure, free for each instance's first 31 days, with storage, transactions, outbound data and failover compute billed separately, as of October 2026.
- Implementation is lighter for backup: agents, a repository, retention rules and an offsite target. Replication adds network design at the recovery site and a runbook for failover and failback.
- Support is mostly labor: checking jobs every day, fixing failures, and testing restores and failovers. That work is what turns either method into a recovery you can count on.
How does NetSys set up backup and replication?
Our IT disaster recovery services start with a recovery time and a recovery point for each system, agreed with the person who owns the process. Systems get backups to offline and immutable copies, including Microsoft 365; replication with failover is added for the systems where downtime costs most. Backup jobs are checked daily, and restore and failover tests run on a schedule with the date, scope and measured time recorded. One published result: a tested failover recovery time of 15 minutes for an importer's ERP and SQL core, down from multi-day rebuilds. A time measured in one test is evidence for that system, not a promise for every outage. Disaster recovery planning is included in every managed agreement, and agreements run month to month.
Book a call with an engineer and bring your list of servers and applications; we will go through which ones need replication and which are well covered by backup.
Frequently asked questions
Is replication the same as backup?
No. Replication keeps a second copy that matches the original as closely as possible, so it recovers quickly from a hardware or site failure. A backup keeps older, dated copies, so it recovers from deletion, corruption and ransomware. Microsoft's guidance is that replication keeps no old copies, so a deletion reaches every replica.
Does replication protect against ransomware?
Not on its own. If ransomware encrypts the source before the next replication cycle, the encrypted data is copied to the replica. Replica restore points may let you roll back a short way, but reliable protection is an offline or immutable backup the attacker cannot reach, tested before you need it.
Is a snapshot a backup?
No. A snapshot depends on the original disk and storage, so it is lost if they are lost. Broadcom tells VMware users not to use snapshots as backups and not to keep one longer than 72 hours. Use a snapshot as a quick undo before a change, then delete it.
Does Veeam do both backup and replication?
Yes. Veeam Backup & Replication runs backup jobs, which keep compressed restore points in a repository, and replication jobs, which keep a ready-to-start copy of a virtual machine on another host. Many designs use both: replication for the most critical machines, and backups with an immutable copy for everything.
Is cloud backup better than local backup?
Neither is better alone. Local backups restore fastest; offsite cloud copies survive a fire, flood or break-in, and immutable ones survive an attacker with administrator rights. Keep both, and test a full restore from the cloud copy so you know how long your internet connection makes it take.
Which option fits a small team?
Backups for every system, with an offsite immutable copy and Microsoft 365 covered separately. Add replication only for the one to three systems that must be back within an hour or two, because replication keeps a second full copy of every system it protects.
What affects the cost of backup and replication?
For backup: data volume, change rate, retention and immutable offsite storage. For replication: standby storage and compute, bandwidth, licenses and failover testing. Both need someone to check jobs daily and test restores. Price each system against its recovery targets instead of buying the fastest option everywhere.
Related reading
ComparisonsDatto vs Veeam for Small Business Backup
Read Article
ComparisonVeeam vs Acronis (and Datto): Small Business Backup Compared
Read Article
Disaster RecoveryHurricane Season IT Checklist for NY, NJ & Florida Businesses
Read ArticleAlso on this topic: RTO vs RPO: The Difference, a Worked Example and Typical Tiers
Discuss disaster recovery for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
