IBM Storage Defender / Storage Protect: Enterprise Backup Ledger 2026
IBM is connecting established backup engines with recovery governance and threat scanning.
Part of the Enterprise Backup Ledger (edition 2026-10-03). How the scores work: methodology.
Snapshot
- Tier: Storage-vendor suite
- Owner: IBM; 2023 Cohesity OEM collaboration is a supply/portfolio partnership, not acquisition of IBM.
- Licence model: Storage Protect entitlements and Defender Resource Units/Essential subscriptions; Replica licensed separately.
- Products scored: Storage Protect, Protect for VE, Protect Plus and Defender Data Protect/DRS; component features remain separately attributed.
- Latest release: Defender 2.2.2 (2026-09-28); Data Protect 7.4.1 GA2026-07-27/bundle2026-08-17; Storage Protect 8.2.2 currency update 2026-08-04
- Next signal: No dated next milestone established in the accepted research.
- Archetype: Governed recovery portfolio
- Evidence grade: C. Overall grade uses all scored history/AI steps and lens criteria: 41 A, 1 B, 15 C of 57; the lowest grade covering more than 25% wins. Judgement itself does not demote a sourced fact; unresolved eligibility, baseline or contract estimates do.
Scope of the scores: Product capability cutoff 2026-10-01; scoring edition 2026-10-03. Combined portfolio scores do not imply one SKU or uniform feature parity. History is evidence-bounded; freezes and first-feature GA dates can be incomplete. AI services named in the AI section do not broaden the ten core domains.
Scorecard
| Dimension | Score | Direction |
|---|---|---|
| Capability today | 82.8 / 100 | higher is better |
| Momentum since end of 2022 | +6.2 points | higher is better |
| Credibility | 17.0 / 25 | higher is better |
| Commercial risk | 12.5 / 25 | lower is better |
| Technical lock-in | 15.0 / 25 | lower is better |
| Integrator fit | 13.5 / 20 | higher is better |
| AI leverage | 10.5 / 20 | higher is better |
| Ledger Index | 65.1 / 100 | balanced weights |
Capability by domain
Scores 0 to 5 against fixed anchors; total is weighted to 100.
| Domain (weight) | 2016 | 2019 | 2022 | Today |
|---|---|---|---|---|
| Virtual and physical servers (12) | 3.5 | 4.5 | 4.5 | 4.5 |
| Databases and applications (12) | 2 | 4 | 4.5 | 4.5 |
| Recovery (14) | 3 | 3.5 | 3.5 | 4 |
| Cyber resilience (14) | 0.5 | 2.5 | 3.5 | 4 |
| Storage efficiency and targets (10) | 3.5 | 4 | 4.5 | 4.5 |
| Long-term retention and tape (6) | 2.5 | 4 | 4.5 | 4.5 |
| Replication and DR (10) | 1.5 | 2.5 | 2.5 | 3.5 |
| Security and compliance (8) | 2.5 | 3.5 | 4 | 4.5 |
| New-platform support (VMware exit) (8) | 0 | 0 | 3 | 3 |
| Management at scale and automation (6) | 2.5 | 3.5 | 4 | 4.5 |
| Total / 100 | 43.0 | 64.8 | 76.6 | 82.8 |
Year by year: 2016: 43.0 · 2017: 43.0 · 2018: 51.2 · 2019: 64.8 · 2020: 64.8 · 2021: 69.6 · 2022: 76.6 · 2023: 76.6 · 2024: 76.6 · 2025: 78.6 · 2026: 82.8
What moved the score
| Year | Domain | Change | Points | Trigger |
|---|---|---|---|---|
| 2018 | Databases and applications | 2 → 4 | +4.8 | Spectrum/Storage Protect Plus 10.1.2 (2018-09-21 electronic-availability clock): Db2 point-in-time recovery; vSnap encryption; VADP load controls; catalog cloud copies. Evidence A. plusPrevious; plusDates |
| 2018 | Recovery | 3 → 3.5 | +1.4 | Spectrum/Storage Protect Plus 10.1.1 (2018-03-23 electronic-availability clock): SQL/Oracle instant access; log capture; vSnap replication; resource-scoped RBAC and scripts. Evidence A. plusPrevious; plusDates |
| 2018 | Replication and DR | 1.5 → 2.5 | +2.0 | Spectrum/Storage Protect Plus 10.1.1 (2018-03-23 electronic-availability clock): SQL/Oracle instant access; log capture; vSnap replication; resource-scoped RBAC and scripts. Evidence A. plusPrevious; plusDates |
| 2019 | Cyber resilience | 0.5 → 2.5 | +5.6 | Spectrum/Storage Protect Plus 10.1.3 (2019-02-22 electronic-availability clock): Immutable IBM COS/offload; Exchange granular restore; MongoDB protection; automated VADP deployment. Evidence A. plusPrevious; plusDates |
| 2019 | Long-term retention and tape | 2.5 → 4 | +1.8 | Storage/Spectrum Protect server 8.1.9 (Version-specific feature documentation; GA day separately unresolved): Second-administrator approval for restricted commands; indefinite retention-set holds. Both explicitly delivered in 8.1.9. Evidence A. server819 |
| 2019 | Management at scale and automation | 2.5 → 3.5 | +1.2 | Data Protection for VMware 8.1.8 (VE component GA day not established; do not substitute client availability day): Multiple backup servers in one vSphere plugin; per-datacenter server assignment; default server cannot be removed; fixed installation paths and automatic Linux library setup. Evidence A. veCumulative |
| 2019 | Security and compliance | 2.5 → 3.5 | +1.6 | Storage/Spectrum Protect server 8.1.9 (Version-specific feature documentation; GA day separately unresolved): Second-administrator approval for restricted commands; indefinite retention-set holds. Both explicitly delivered in 8.1.9. Evidence A. server819 |
| 2019 | Storage efficiency and targets | 3.5 → 4 | +1.0 | Storage/Spectrum Protect server 8.1.8 (Version-specific feature documentation; GA day separately unresolved): Directory-container disk-to-tape tiering; Protect Plus 10.1.4 S3/Glacier offload to tape/VTL; S3 Intelligent-Tiering; WORM file volumes. Evidence A. server818 |
| 2019 | Virtual and physical servers | 3.5 → 4.5 | +2.4 | Backup-archive client 8.1.9 (2019-11-22 available): Web file restore on AIX; signed-package verification on Linux x64/Z/Power. Evidence A. clientCumulative; clientclock |
| 2021 | New-platform support (VMware exit) | 0 → 3 | +4.8 | Plus 10.1.7.2/10.1.8.1/10.1.8.2 (Maintenance build dates unresolved; feature sections identify versions): 7.2 Oracle log-truncation/ad-hoc controls; 8.1 OpenShift Virtualization VM support; 8.2 diagnostic/log-SLA changes. Container ecosystem evidence is separate from core physical/VM scope. Plus 10.1.8.1 OpenShift Virtualization VM support is separately versioned; patch first day remains uncertain. Evidence C. plusPrevious |
| 2022 | Cyber resilience | 2.5 → 3.5 | +2.8 | Storage/Spectrum Protect server 8.1.15 (Version-specific feature documentation; GA day separately unresolved): S3 Object Lock cloud containers; Glacier Instant Retrieval; complex passwords/STRICT security default; OSSM gateway to Protect Plus is TECHNOLOGY PREVIEW. Evidence A. server8115 |
| 2022 | Databases and applications | 4 → 4.5 | +1.2 | Spectrum/Storage Protect Plus 10.1.12 (2022-09-16 electronic-availability clock): OSSM direct VMware-to-Protect 8.1.16; HANA recovery; cloud catalog backup; vCenter certificate validation. Evidence A. plusPrevious; plusDates |
| 2022 | Long-term retention and tape | 4 → 4.5 | +0.6 | Storage/Spectrum Protect server 8.1.14 (Version-specific feature documentation; GA day separately unresolved): Google Coldline/Archive targets; administrator TOTP MFA. Opening sentence incorrectly names 8.1.13; individual feature paragraphs explicitly name 8.1.14. Evidence A. server8114 |
| 2022 | Management at scale and automation | 3.5 → 4 | +0.6 | Spectrum/Storage Protect Plus 10.1.10 (2022-03-11 electronic-availability clock): REST global preferences and SLA assignment; cloned-Windows file backup fix; Windows2022 indexing. Evidence A. plusPrevious; plusDates |
| 2022 | Security and compliance | 3.5 → 4 | +0.8 | Storage/Spectrum Protect server 8.1.14 (Version-specific feature documentation; GA day separately unresolved): Google Coldline/Archive targets; administrator TOTP MFA. Opening sentence incorrectly names 8.1.13; individual feature paragraphs explicitly name 8.1.14. Evidence A. server8114 |
| 2022 | Storage efficiency and targets | 4 → 4.5 | +1.0 | Storage/Spectrum Protect server 8.1.15 (Version-specific feature documentation; GA day separately unresolved): S3 Object Lock cloud containers; Glacier Instant Retrieval; complex passwords/STRICT security default; OSSM gateway to Protect Plus is TECHNOLOGY PREVIEW. Evidence A. server8115 |
| 2025 | Replication and DR | 2.5 → 3.5 | +2.0 | Defender/DRS 2.0.17 (2025-09-29 release date): Application-level orchestration; RU calculator; IdP-group SSO; Docker connection agent for Protect on Windows/AIX. Evidence A. drs2017 |
| 2026 | Cyber resilience | 3.5 → 4 | +1.4 | Defender/DRS 2.1.2 (2026-03-23 release date): Recovery-plan point recommendations; isolated Sentinel 8.15 scan environment; YARA/AI Threat Scanner; Data Protect 7.3.2 bundle. Evidence A. drs212 |
| 2026 | Management at scale and automation | 4 → 4.5 | +0.6 | Defender/DRS 2.2.0 (2026-07-20 release date): Validated Slack/Teams/CrowdStrike/ServiceNow webhooks; general maintenance. Evidence A. drs220 |
| 2026 | Recovery | 3.5 → 4 | +1.4 | Defender/DRS 2.1.2 (2026-03-23 release date): Recovery-plan point recommendations; isolated Sentinel 8.15 scan environment; YARA/AI Threat Scanner; Data Protect 7.3.2 bundle. Evidence A. drs212 |
| 2026 | Security and compliance | 4 → 4.5 | +0.8 | Observed by 2026-10-01: Storage Protect official MCPv 1.1.0: scoped OIDC, module-specific least-privilege service identities, TLS, read-only mode; write attribution to each server ACTLOG via MCP_AUDIT. Two-person command approval is optional configuration, not default. Existing Protect MFA/command approval and Defender RBAC have separate scopes. MCP scoped OIDC and write attribution; optional two-person approval, not universal mandatory mode. Evidence A. mcpConfig110; mcpReleases; server8114; server819 |
Direction, 2023 to 2026
Each item carries one theme and one driver (V vision, C customer need, M market window, U upstream, P portfolio).
| Date | Item | Theme | Driver |
|---|---|---|---|
| 2023-03 | Cohesity DataProtect in Defender: partial; First OEM GA unresolved. Defender package/component download charts corroborate later integration; exact original deadline delivery not established. | D10 Scale and automation | C |
| 2023-03 | Defender unified recovery / AI threat monitoring: partial; Defender 2.0 package available 2023-12-11; initial GA unresolved. Do not use 2.0 as initial product GA: earlier OEM delivery/Defender release evidence incomplete. | D4 Cyber resilience | C |
| 2023-03 | Protect unified-management integration: partial; Original first GA unresolved. Existing Protect backup engine is separate from later DRS registration/governance integration documented 2.0.10. | D10 Scale and automation | C |
| 2024-02 | AI ransomware sensors: partial; First matching sensor GA unresolved. Research sensors; FlashCore hardware detection remains separate. | D4 Cyber resilience | C |
| 2024-02 | Automated Safeguarded Copy protection groups: shipped; 2024-05-21 release. DRS 2.0.4 FlashSystem recovery/governance supports later delivery. | D4 Cyber resilience | C |
| 2024-02 | VMware application recovery orchestration: partial; First matching GA unresolved. Later VM/application orchestration documented, not original deadline proof. | D3 Recovery | C |
| 2024-02 | Workload/storage inventory: partial; By2.0.0/2.0.4. Recovery groups documented; exact announcement-to-inventory clock unresolved. | D5 Storage efficiency | C |
| 2025-05 | AD/Db2 recovery-group generation: shipped; 2025-04-16 DRS 2.0.13 release. Automatic grouping for AD/Db2 data and FlashSystem/SVC metadata. Expanded source awareness is distinct from native backup support. | D2 Databases and applications | C |
| 2025-06 | Data Insights governance dashboards: shipped; 2025-06-23 DRS 2.0.14 release. Evaluates copy frequency/retention, immutability and encryption; recommends fixes, not proof of an autonomous AI executor. | D10 Scale and automation | C |
| 2025-06 | Oracle/SAP HANA Protect governance: shipped; 2025-06-23 DRS 2.0.14 release. Protect workload inventory/governance integrated with DRS; not the original database-agent support date. | D2 Databases and applications | C |
| 2025-06 | Pure FlashArray X/C integration: shipped; 2025-06-23 DRS 2.0.14 release. Registers Pure sources, governs snapshots and automatically creates recovery groups; array feature distinct from backup engine support. | D10 Scale and automation | C |
| 2025-06 | Windows2019/2025 sensors: shipped; 2025-06-23 DRS 2.0.14 release. Added sensor scan coverage; independent of backup-agent OS support. | D10 Scale and automation | C |
| 2026-03 | Application recovery plans: shipped; 2026-03-23 DRS 2.1.2. Ordered dependencies and clean/validated recovery-point recommendations; blog date differs from URL. | D3 Recovery | C |
| 2026-04 | Data Protect threat scanning: shipped; 2026-03-23 Defender 2.1.2. YARA/AV/IOC scanning; DMS on-demand/scheduled scans. Blog says Defender 2.1.2; package/RN corroborate. | D4 Cyber resilience | C |
| 2026-05 | Hyper-V connection manager deployment: shipped; 2026-05-18 DRS 2.1.4. Connection manager runs inside Hyper-V VM; not first native backup support. No invented earlier deadline; release-note evidence remains distinct from annual-event promise census. | D1 Virtual and physical servers | M |
- Centre of gravity: Scale and automation (5), Cyber resilience (4), Recovery (2)
- Driver mix: Vision 0%, Customer need 93%, Market window 7%, Upstream 0%, Portfolio 0%
Credibility: 17.0 / 25
| Criterion | Score | Basis |
|---|---|---|
| Cadence | 4.5 | 142 recorded release rows, including maintenance and component overlaps; rows are not distinct GA counts. Regularity judged from the dated tables, not an asserted promised cadence. Defender 2.0.0 /Data Protect 7.1.1 (2023-12-11): Platform/component package-release clocks; agent and cluster deployment Evidence A. def20 |
| Roadmap transparency | 3 | Public documentation access and versioned release evidence determine this score. Accepted roadmap finding: not found; dated release and vendor announcement pages used. No open-roadmap-tracker reference score is awarded. Defender 2.0.0 /Data Protect 7.1.1 (2023-12-11): Platform/component package-release clocks; agent and cluster deployment Evidence A. def20 |
| Say-do | 3 | Recorded ledger: 27 items; 18 shipped, 9 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 9; 1 documented within 12 calendar months, 0 later than 12 months, 8 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample. Evidence C for the rubric estimate: calibrated to the delivery record below, not a measured census percentage. See the vendor research section F. |
| Velocity | 4 | Substantive capabilities in the release tables determine velocity; maintenance-only rows do not become new features. Storage Protect 8.2.2 (GA day unresolved; currency index 2026-08-04 /documentation2026-09-04): Server DB backup stacking/reclamation on tape; Call Home support telemetry; object-agent multipart listing/restore optimization; official MCP interface documented. Same-host data TLS opt-out is optional, authentication encrypted; not a general encryption removal. Evidence A. server822; fix82 |
| Lifecycle stability | 2.5 | Accepted lifecycle finding: Data Protect support policy effective 2025-08-01: major releases generally 18 months; current minor/patch may be required for fixes. Release notes need IBMid linked to tenant.7.4.0 EOS2027-09-30; 7.4.1 EOS2027-10-27. Source: IBM support information.. Grade C where current contract/EOS boundaries remain unresolved. 2025-06-20: Plus 10.1.17 service packs become upgrade-only; fresh deployments need mod/base then iFix. Fix Central maintenance lacks licence enablement; obtain initial licence package via Passport Advantage. Evidence C. plus17Download |
Say-do record, 2023 to 2026: Recorded ledger: 27 items; 18 shipped, 9 partial, 0 slipped, 0 pending, 0 dropped. Mature dated prospective cohort: 9; 1 documented within 12 calendar months, 0 later than 12 months, 8 unresolved. Month-only/ambiguous clocks, same-day release notices and post-release blogs are excluded from that cohort. Pending is unverified, not failure; the ledger is a bounded sample.
Commercial risk: 12.5 / 25 (lower is better)
| Criterion | Score | Basis |
|---|---|---|
| Price and licence volatility | 2.5 | Defender RU consumption and paid Essential/trial models are documented; existing licences can continue or convert. 2023; exact original GA day not printed: Primary GA notice introduces consumption Resource Units (RU); existing licences continue or may convert to RUs. A GA assertion, not a reconstructed day. 2024-07-29: DRS 2.0.6 introduces 60-day Trial and paid Essential subscriptions. Evidence A. defgacredits; drs206 |
| Purchase constraints | 3 | Licence metrics, edition gates and purchase routes determine this estimate; undisclosed minimums are not assumed zero. Separate families: Defender Data Protect/Replica versus Storage Protect server and VE/SQL components; no unified licence or price inferred Evidence A. def21; ve; sql |
| Channel and access | 3.5 | Fix Central upgrade packages omit licence enablement; initial licences/packages require Passport Advantage. 2025-06-20: Plus 10.1.17 service packs become upgrade-only; fresh deployments need mod/base then iFix. Fix Central maintenance lacks licence enablement; obtain initial licence package via Passport Advantage. Evidence A. plus17Download |
| Owner stability | 0 | OEM partnership broadens portfolio; no recent controlling-owner change recorded. 2023-03-02: IBM/Cohesity OEM collaboration announced; planned 2Q2023 availability begins with Storage Protect and Cohesity DataProtect. Pricing/contract quantities not disclosed. Evidence A. oem |
| Cost of staying supported | 3.5 | Defender 1.x/2.0 EOS with no extended support; Plus chained/full-OS upgrade requirements. 2026-06-30 EOS: Defender1.x/2.0 support ends; no extended support available; supported 2.1 onward. Plus 10.1.17 /2025: Upgrade only from 10.1.16.4; vSnap update precedes appliance; pre-upgrade script and full OS replacement. Base plus iFix needed for new installs. Evidence A. drs215; plus17; plus17Download |
Security record of the product itself: No in-scope match located in the accepted security-record.md manual product-name filter of the CISA 2026-09-30 catalogue; no deduction. This is not an exhaustive advisory audit or a claim of no exploitation. Arcserve CVE-2015-4068 was added to KEV in 2022, outside the adjustment window. Adjacent array/infrastructure/hosting-plugin CVEs are excluded. Security record: CISA Known Exploited Vulnerabilities catalogue and vendor advisories.
Technical lock-in: 15.0 / 25 (lower is better)
| Criterion | Score | Basis |
|---|---|---|
| Formats | 4 | LZ4 archives written by 8.1.12 require an 8.1.12+ client: explicit vendor reader/version coupling. Client 8.1.12: LZ4-compressed backups created by 8.1.12 can only be restored by 8.1.12+ clients. This is an explicit reader-version compatibility boundary. Evidence A. clientCumulative |
| Export path | 2.5 | 2026-10-01 evidence boundary: Independent data extraction and post-licence restoration terms are incomplete. Provisional export estimate, not proof of no export or licence-required restore. Provisional rubric estimate; unknown terms are not evidence of either zero risk or the worst terms. Evidence C. |
| Stack coupling | 3 | The documented component/management stack is considered; cross-workload or cross-hypervisor recovery is not inferred from an API. Stack components: Defender installation files include Cohesity-named images/packages on qualified hardware and virtual/cloud editions; IBM product entitlement remains separate Evidence C. def21 |
| Hardware / cloud coupling | 2 | Deployment/service dependencies determine this score; missing offline/hardware terms are a provisional estimate. Stack components: Defender installation files include Cohesity-named images/packages on qualified hardware and virtual/cloud editions; IBM product entitlement remains separate Evidence C. def21 |
| Skills and tooling coupling | 3.5 | Named training and product-specific administration imply some skills coupling; no unsourced scarcity/headcount claim. Provider multitenancy: DRS 2.1.1 organization isolation, user assignment and Service Provider Access impersonation; accounts/roles govern access. Evidence A. drs211 |
Integrator fit: 13.5 / 20
| Criterion | Score | Basis |
|---|---|---|
| Partner programme openness | 3.5 | Published partner routes and entry/tier qualifications earn credit; undisclosed obligations limit the score. Provider multitenancy: DRS 2.1.1 organization isolation, user assignment and Service Provider Access impersonation; accounts/roles govern access. Evidence A. drs211 |
| Multi-tenancy and self-service | 4 | DRS 2.1.1 organization isolation and Service Provider Access; billing/self-service breadth incomplete. Provider multitenancy: DRS 2.1.1 organization isolation, user assignment and Service Provider Access impersonation; accounts/roles govern access. Evidence A. drs211 |
| API and infrastructure-as-code | 3.5 | Official governed MCP and validated webhook integrations; full vendor IaC coverage remains unresolved. First repository commit 2026-03-25; v1.0.0 2026-07-16; v1.1.0 2026-09-25; Official open-source MCP integration for commercial product: One MCP process per Protect server; stdio/SSH or HTTP-SSE. Production HTTP requires TLS and OIDC issuer/audience. Dynamic passwords memory-only with 15-minute inactivity lease; write identity/correlation recorded in each server ACTLOG. Audit retention not specified by guide. Integration is not a new OSS backup vendor and has as-is/support disclaimer. Threat/incident integrations: DRS 2.0.5 QRadar; 2.0.8 Splunk; 2.2.0 validated Slack/Teams/CrowdStrike/ServiceNow webhooks. Evidence A. mcpRepo; mcpReleases; mcpConfig110; drs205; drs208; drs220 |
| Skills and certification | 2.5 | Historical named Protect credentials exist; withdrawal is indexed and current Defender credential unresolved. Dated2017-11-16 training path: Spectrum Protect8 training path names Test511 IBM Certified Deployment Professional: Tivoli Storage ManagerV 7.1, plus 8.1.2 implementation/admin training TS616G. Evidence of an existing certification, not a2017 first-launch claim. Historical Spectrum Protect 8.1 credentials: Indexed IBM catalogue names Certified Administrator to Spectrum ProtectV 8.1, withdrawn 2020-05-31 and expiring 2020-09-30; Deployment ProfessionalV 8.1 badge also indexed. Opened pages returned empty bodies, soB; neither proves a current Defender credential. Evidence B. training17; admin81Cert; deploy81Badge |
AI leverage: 10.5 / 20
| Strand | Today | Latest step |
|---|---|---|
| AI for protection / protecting AI | 3.5 | 2026: 2026-03-23 /DRS 2.1.2; Released feature: Data Protect Threat Scanner: AI scanning, YARA/feed updates, automatic/on-demand scans and anomaly-triggered triage. Sentinel 8.15 isolated scanning is separately integrated. AI-labelled scanner plus YARA/feed integrations; not every scanner mechanism is ML. Evidence A. drs212 |
| AI platform stack | 0 | 2016: 2016 initial scoring observation: no affirmative released in-scope AI evidence is credited in this strand. Zero is an evidence-bounded score, not a claim that the capability was absent. Evidence C. |
| AI-assisted operations | 2 | 2024: 2024-12-18 blog /2024-12-17 DRS 2.0.10; Released: ML discovers VMware VMs and forms recovery groups/governance profiles; automatic restore consent not established. ML-generated recovery groups; recommendations are not a generative acting assistant. Evidence A. blog24Dec; drs2010 |
| Agent openness | 5 | 2026: First repository commit 2026-03-25; v1.0.0 2026-07-16; v1.1.0 2026-09-25; Official open-source MCP integration for commercial product: One MCP process per Protect server; stdio/SSH or HTTP-SSE. Production HTTP requires TLS and OIDC issuer/audience. Dynamic passwords memory-only with 15-minute inactivity lease; write identity/correlation recorded in each server ACTLOG. Audit retention not specified by guide. Integration is not a new OSS backup vendor and has as-is/support disclaimer. Released official MCP v1.0/v1.1 with OIDC scopes, least privilege, ACTLOG attribution and optional second-person approval; as-is support disclaimer preserved. Evidence A. mcpRepo; mcpReleases; mcpConfig110 |
AI say-do sample: 4 recorded announcement rows; 2 GA/shipped matches, 0 preview/early/limited at announcement, 2 partial, 0 pending, 0 slipped, 0 dropped. Preview-at-announcement overlaps outcome counts. These are promise-row counts, not unique announcements or counts of released AI features; omissions/overlaps in the AI research ledger are preserved. "Shipped" may be a vendor availability assertion rather than an independently verified first-GA day.
Reading
IBM is connecting established backup engines with recovery governance and threat scanning. Dated Defender notes and Protect documentation show immutable targets, recovery groups and a governed MCP interface. Component entitlements, reader compatibility and phased upgrades remain significant dependencies.
Open questions and evidence caveats
- Unchanged annual values carry the last scored release; they do not certify a frozen compatibility matrix or exact first-feature GA. Some checkpoint-derived jumps may lag the true first shipment.
- Unverified AI strands receive zero credited evidence; this is a conservative estimate rather than a vendor-wide absence claim. Preview/limited capabilities add at most half a point beyond the preceding established score.
- Say-do counts are a bounded research sample. Same-day/release-note announcements and post-release blogs are not promises delivered instantly. Missing outcome dates do not prove non-delivery.
- Commercial/exit terms not reconstructed use explicit provisional midpoint estimates; executed regional contracts may differ.
- apps: 2016 baseline is provisional; no frozen checkpoint fact.
- cyber: 2016 baseline is provisional; no frozen checkpoint fact.
- retention: 2016 baseline is provisional; no frozen checkpoint fact.
- dr: 2016 baseline is provisional; no frozen checkpoint fact.
- platforms: 2016 baseline is provisional; no frozen checkpoint fact.
- GCS 8.2.1 retention is governance-only with privileged IAM override, new bucket/new pool and workload exclusions. Protect package deployment images do not prove every hypervisor is protected. DRS 2.0.11 prints a conflicting year and is not used to date score gains.
Related reading
More from Enterprise Backup Ledger 2026
- Overview: all platforms side by side
- Enterprise Backup Ledger Methodology: How Every Score Is Built
- Acronis Cyber Protect: Enterprise Backup Ledger 2026
- Arcserve UDP: Enterprise Backup Ledger 2026
- Bacula Enterprise: Enterprise Backup Ledger 2026
- Cohesity DataProtect / NetBackup: Enterprise Backup Ledger 2026
- Commvault Cloud: Enterprise Backup Ledger 2026
- Dell: Enterprise Backup Ledger 2026
- Druva Enterprise Workloads: Enterprise Backup Ledger 2026
- HPE Zerto: Enterprise Backup Ledger 2026
- Huawei OceanProtect DataBackup: Enterprise Backup Ledger 2026
- HYCU R-Cloud: Enterprise Backup Ledger 2026
- NAKIVO Backup & Replication: Enterprise Backup Ledger 2026
- OpenText Data Protector: Enterprise Backup Ledger 2026
- Rubrik Security Cloud: Enterprise Backup Ledger 2026
- Sangfor backup / DR software candidate: Enterprise Backup Ledger 2026
- Storware Backup and Recovery: Enterprise Backup Ledger 2026
- Veeam Data Platform: Enterprise Backup Ledger 2026