How many backup products does your org actually run?
Only 7% of orgs run a single backup and recovery stack; the avg org runs 2.8 data protection solutions.
It’s not because IT teams enjoy tool sprawl; it’s because most need to supplement their primary solution to cover the breadth of their IT, especially due to endpoints and SaaS … and that has real ramifications for your cyber resilience strategy.
video transcript
The avg org uses 2.8 backup products, according to 440 IT decision makers that DPM surveyed in 2026. Here are three things that make this data really interesting:
- The survey covered midsize, enterprise, and large enterprise organizations, and the number doesn’t change as much as you might guess
- I’ve been in data protection for 35-plus years, nearly half of them as an analyst, and I’ve asked this question routinely; a decade ago, it was the same 2.8. It’s almost eerie how consistent that number is, but the real story is we’ve never had an era where most organizations ran on just one backup stack.
Dig a little deeper into the responses and the other headline is that only 7% of organizations use a single backup solution for everything in their environment; seven! There are actually as many organizations running five or more data protection solutions as there are running that single ring to rule them all. Depending on your cohort and your geography, I’ve seen that number reported as high as 9 to 11%; but it’s pretty consistent, when it isn’t a vendor doing the asking, to see single digits of organizations on one solution.
Most DPM research asks a question like this and then doubles down by asking why. Why don’t you run just a single backup solution?
Nearly half of organizations add an additional solution specifically for endpoints; that likely includes a lot of OT for manufacturing, retail, and healthcare, along with mainstream endpoint devices for remote users.
Nearly half of organizations add an additional solution specifically to protect their SaaS applications. This one matters: think back 20 years when most organizations had a solid solution for their physical servers in the data center. As virtualization first went mainstream, legacy solutions didn’t protect VMs well, so people supplemented with secondary solutions from PHD Virtual, Veeam, or vRanger; then, as virtualization became the mainstream production platform, that secondary backup tool became the primary solution by default. Fast forward 20 years: if your mainstream data protection solution doesn’t protect the breadth of SaaS’es (including identity platforms) that your organization relies on, then you’re probably supplementing (or ought to be) with something that does protect those SaaS’es. As your organization becomes more SaaSy, don’t be surprised if that SaaS solution becomes your primary going forward, or if you end up embracing a more modern data protection solution that covers both your data center and the breadth of your SaaS’es.
The reality is you’re going to change or add backup software; that’s exactly why some MSPs offer multiple stacks to cover the breadth of what you want to protect, which makes them really interesting for obfuscating the complexity of running multiple tools, and it’s why centralized protection storage becomes even more compelling, so you can maintain retention without creating a mess of isolated silos.
But those are future blogs … leave your thoughts below.
Leave your thoughts on the LinkedIn article.




Leave a Reply