Cloud backup vs infrastructure recovery: what each one restores
Cloud backup restores data: volumes, databases, object storage. Infrastructure recovery rebuilds the environment that data runs in: accounts, networks, identity, DNS, managed-service settings and their dependencies. A service is back only when both are, so most teams need a product for each or one that does both.
Ranking current as of September 2026 · By the Cloud Resilience Vendors research desk
What does a cloud backup actually restore?
A copy of data, and often the virtual machine or database instance that held it. Products such as Veeam Backup for AWS and Cohesity protect EC2, RDS, S3 and similar workloads, keep immutable copies and restore them to a point in time. What they generally do not bring back is the rest of the environment: the VPC and subnets, route tables, security groups, IAM roles and policies, DNS records, load balancer rules, Kubernetes cluster settings and the many managed-service configurations that let the restored data serve traffic.
What does infrastructure recovery add?
Infrastructure recovery captures that configuration and the dependencies between resources, then recreates them in the same or another region or account. Firefly, ControlMonkey and Commvault Cloud Rewind do this in different ways: Firefly generates Terraform, ControlMonkey restores configuration snapshots, and Cloud Rewind restores whole application stacks including data. Arpio replicates infrastructure and data and fails over.
Why is data backup not enough after ransomware?
An attacker who reaches the control plane can delete or alter infrastructure as well as encrypt data. Restoring data into an account that is compromised, or into a region where nothing is configured yet, does not restore the service. Recovery into a clean, isolated account or region needs the configuration captured somewhere the attacker could not change it, which is why several vendors in this ranking describe immutable or versioned configuration snapshots.
What is infrastructure as code backup?
Infrastructure as code backup means keeping the definition of your cloud environment as versioned code (Terraform, OpenTofu, Pulumi or CloudFormation) so it can be re-applied. It works for resources that are fully in code and fails for everything created by hand, by scripts or by other tools. Tools such as Firefly, ControlMonkey and StackGuardian generate code for unmanaged resources to close that gap; HCP Terraform stores code and state history but does not generate code from what already runs.
Which vendors cover which layer?
From each vendor's public material, reviewed September 2026.
| Vendor | Data | Configuration | Network | IAM | DNS | Published RTO/RPO |
|---|---|---|---|---|---|---|
| Firefly | Not covered or not publishedDoes not document backing up data contents. | RestoredResource configuration restored as Terraform. | RestoredVPC, subnets, security groups, NACLs, WAF in coverage table. | RestoredIAM roles, policies and users in coverage table. | RestoredRoute 53 and Azure Private DNS zones in coverage table. | RTO < 1 hr (vendor claim) |
| Arpio | RestoredContinuous replication; RPO as low as 15 min. | RestoredReplicates infrastructure with dependency mapping. | Partial or not itemizedComplex networking support listed in Enterprise. | Not covered or not publishedNot itemized on pages reviewed. | Not covered or not publishedNot itemized on pages reviewed. | RPO as low as 15 min (vendor claim) |
| Commvault Cloud Rewind | RestoredPoint-in-time, in-sync copies of workloads. | RestoredProtects configurations across compute, storage and databases. | RestoredNetworking named; security groups and load balancers per G2 description. | Partial or not itemizedSecurity resources named; IAM not itemized. | Not covered or not publishedNot itemized on pages reviewed. | Not published |
| ControlMonkey | Not covered or not publishedConfiguration only. | RestoredDaily cloud configuration snapshots on AWS, Azure, GCP. | Partial or not itemizedPart of cloud configuration; not itemized. | Partial or not itemizedOkta and Entra ID configuration; cloud IAM not itemized. | Partial or not itemizedCloudflare configuration; cloud DNS not itemized. | Not published |
| Cohesity | RestoredEC2, RDS, S3 backup and recovery. | Partial or not itemizedCloud Rebuild for select AWS workloads with existing IaC. | Not covered or not publishedNot itemized on pages reviewed. | Not covered or not publishedNot itemized on pages reviewed. | Not covered or not publishedNot itemized on pages reviewed. | Not published |
| Veeam | RestoredWidest listed workload data coverage in this ranking. | Partial or not itemizedAmazon VPC and Azure Virtual Networks listed; detail not published. | Partial or not itemizedListed as services; configuration detail not published. | Not covered or not publishedNot listed. | Not covered or not publishedNot listed. | Not published |
| HCP Terraform | Not covered or not publishedNo data protection. | Partial or not itemizedOnly what is already in Terraform code. | Partial or not itemizedOnly what is already in Terraform code. | Partial or not itemizedOnly what is already in Terraform code. | Partial or not itemizedOnly what is already in Terraform code. | Not published |
| StackGuardian | Not covered or not publishedNo data protection. | Partial or not itemizedCodifies unmanaged resources; no restore workflow. | Not covered or not publishedNo recovery product. | Not covered or not publishedNo recovery product. | Not covered or not publishedNo recovery product. | Not published |
Do you need one product or two?
If your data backup platform is in place and trusted, add an infrastructure recovery tool. If you are choosing both at once, compare products that cover both (Commvault Cloud Rewind, Arpio) against a pairing of a backup platform with an infrastructure tool. The ranking weights data protection at 18% for this reason: a rebuild without the data is also not a recovery.
Frequently asked questions
Is snapshot backup the same as cloud disaster recovery?
No. A snapshot is a copy of a disk or database at a point in time. Cloud disaster recovery is the process and tooling to bring the whole service back, including the infrastructure the snapshot must be restored into.
Does Veeam back up cloud infrastructure configuration?
Veeam lists Amazon VPC and Azure Virtual Networks among supported services but does not publish the configuration detail it restores. It does not list IAM or DNS.
What is the difference between infrastructure as code backup and configuration backup?
IaC backup keeps your environment as code you re-apply. Configuration backup captures the live settings of resources, whether or not they are in code, and restores them. Some tools do both by turning captured configuration into code.