A successful backup is not cyber resilience: What Veeam’s Omdia result says about the MSP market

Veeam was recently named a Champion in Omdia’s 2026 Global Managed Backup and Disaster Recovery Leadership Matrix. Omdia is a respected global technology research and advisory firm. Its Leadership Matrix carries weight because it is meant to look beyond a vendor’s own marketing claims. Only four other companies made the cut this year, which makes this an enviable list. 

Source: Omdia

But the more important story is not the accolade. It is the direction of travel for Managed Service Providers (MSPs).

The real test is recovery

A successful backup is not necessarily indicative of cyber resilience.

It used to be, but isn’t lately. For years, backup was judged through straightforward measures such as: Was the data copied? Was it retained for the agreed period? Was there enough storage capacity? Those questions obviously still matter, but you can blame ransomware, cloud outages, and compromised credentials for making them insufficient.

The true test of whether an organization is cyber resilient is whether it can recover clean data, restore critical applications, and resume operations within an acceptable timeframe.

Sounds obvious? Maybe, but in practice it is where many recovery strategies break down. A backup job can show green on a dashboard while the business remains unable to recover its identity systems, core applications, or customer data. It is a bit like owning a lifeboat that nobody has checked, stocked or practised launching.

This is why cyber resilience is becoming a much more important proposition for MSPs. Customers no longer want a provider to simply store data somewhere else. They want proof that their business can withstand disruption.

From backup capacity to recovery confidence

Omdia’s assessment covered vendors that support managed backup and disaster recovery across the MSP ecosystem. They considered analyst assessment, ecosystem feedback, and performance metrics. Veeam says its result reflects, in part, the scale of its Veeam Cloud & Service Provider programme, which includes more than 12,000 partners.

That ecosystem is important because MSPs sit between increasingly complex cyber threats and customers that often lack the skills, budget or time to manage recovery properly themselves.

The opportunity is to move from selling backup capacity to selling recovery confidence. That translates to building services around immutable backups, isolated recovery environments, recovery-time objectives and, crucially, regular recovery testing.

As our interview with Veeam UK & Ireland vice-president Dan Middleton noted, the 3-2-1-1-0 rule adds an offline, air-gapped or immutable copy and requires zero errors after backup verification. Cyber resilience depends on that final step: proving that the data can actually be restored.

A changing MSP proposition

Veeam’s recognition should not be read as a simple vendor victory lap. Rather, it reflects a wider shift in the managed backup market.

Providers are being judged less by the volume of data they protect and more by the quality of the recovery outcomes they can deliver. This includes cost and compliance considerations too, as Veeam’s Data Cloud Vault Archive strategy shows. Retained data may appear dormant, but it can become vital during an attack, audit, or legal investigation.

The MSPs that win will be those that can answer the hardest question in cyber resilience: “Can you prove we will recover?”

About The Author

Kihara Kimachia
Kihara Kimachia

Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.