What’s Next from Veeam?
This segment takes a look into the Veeam roadmap from a security perspective, highlighting the fan favorite from VeeamON 2025 – the Veeam Software Appliance. A major upcoming innovation from Veeam is the new Veeam Software Appliance, a fan favorite from VeeamON 2025. This appliance runs the core Veeam platform on Rocky Linux, hardened with DISA STIG security standards, and is designed to be a purpose-built, highly secure backup infrastructure. It aims to significantly enhance the protection of the backup environment itself, moving towards a “secure by default” delivery model. Veeam will manage all security patching for these appliances, offering forced updates with scheduled timelines, thereby reducing the burden on customers for maintaining server security.
Another key future innovation is the introduction of universal continuous data protection (CDP), extending beyond current VMware capabilities to support physical systems and various hypervisors, with future targets including hyperscalers. This aims to provide near-instant recovery point objectives (RPOs) down to two seconds across diverse environments. While Veeam already supports CDP via VMware’s VAIO Filter Driver, this new universal CDP will broaden its applicability across the entire ecosystem.
Finally, Veeam is exploring the integration of AI into its data fabric to unlock deeper insights from customer data, particularly for eDiscovery scenarios. This involves leveraging Veeam’s extensive backup data to enable rapid querying and analysis that would otherwise take significantly longer. While still in early stages and requiring a public statement on responsible AI, this initiative promises attractive future capabilities in data intelligence. Veeam offers flexible licensing through its universal license (VUL) model, which simplifies pricing across various workloads, and their top-tier Veeam CyberSecure offering includes comprehensive capabilities and a ransomware recovery warranty.
Presented by Rick Vanover, VP of Product Strategy, and Emilee Tellez, Field CTO, Strategy and Community. Recorded live at Security Field Day 13 in Santa Clara, CA on May 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/veeam-presents-at-security-field-day-13/ or visit https://techfieldday.com/event/xfd13/ or https://Veeam.com for more information.
Transcript
Welcome to Security Field Day 13. I'm Rick Vanover from Veeam. And I'm Emily Tes.
And We are gonna talk about some future innovations coming from Veeam. We've got some time permitting about security and more, uh, let's, let's get into it. We only have one slide for the future.
It's more of a dialogue. Yeah. Um, I think, yes.
Yes, exactly. So, um, it's hard to pick a favorite here, but I will tell you, coming off of Veeam on recently, the fan favorite is the new Veeam Software appliance. So if you're just tuning in, we walk through a number of different capabilities of some Veeam Innovations and some ecosystem integrations, as well as the Veeam difference of Covert by Veeam.
One of the biggest technology undertakings we've ever gone into is what's coming later this year of a Veeam software appliance. And, uh, we started this journey in 2023 with the first preview, I think maybe 24. And it's really running the core of our platform on Linux.
Okay. So that's a big change. You know, it's a Windows app right now, but what I really like is that we really have reimagined the delivery process of that.
So yes, it's nice that T net services can be ported to Linux and run on new platforms, but what would you do in 2025 for something like this? So what we are doing is we're making a Veeam software appliance that's running on Rocky Linux, DISA, STIG hardened, and oh, we gotta, we got, we gotta head nod without one. And all it does is run the Veeam app or the, the storage all in one or split separate.
And we're really excited for this capability because this will really provide the backup infrastructure and additional fortitude of itself being protected. Now again, we have best Practice Analyzer, now we have all these other things, but if the delivery model is truly secure, by default, we're taking a major step forward. And when we had our Veeam on event, we did some previews of that.
It was by far the fan favorite. Oh, absolutely. Yeah.
And I think the biggest piece in here right, is for all of our customers that are truly, they love the fact that Veeam is always flexible. 'cause we were always delivering as a software model, but having that additional opportunity to now have that be installed on Linux, something that they can manage, they could still choose their own hardware, they could choose to deploy it as a virtual machine, right? We're still giving 'em that freedom of choice, uh, but from the other side of things, security patching.
Right. Well, that's the last thing I wanna do, is now I have to go and I have to patch a whole nother server. Well, the benefit with the new Veeam software appliance is that veeam's gonna handle all those security patching for customers themself.
So it'll be a forced update that they will see. They'll be able to choose the date and time in which they want it to take place, but it'll be a set timeline for them for those updates to have to happen. So something that can, they can kind of take off their plate, not have to worry about, but then also still have the benefit of it being fully secure and managed.
And organizations can pull that off the internet or set up a local distribution server for that. Because current best practice is not connecting the Veeam server to the internet. But what I'll say about the updates part is it's gonna be both.
Um, you know, think about the surface area of this, what we're calling a Veeam software appliance as well is, you know, version updates. And, you know, currency is so important. You know, I'll be the first to say we're a software company, we've had vulnerabilities and we've fixed them, but I've also talked to organizations that haven't fixed them.
And, you know, people just throw things in and walk away, and that's the worst practice. Mm-hmm. So we're trying to prevent users from being users in a way in this regard, and having this hardened surface area automated updates.
And I'll also say that a lot of Veeam's Alliance partners, specifically compute and storage, are really interested in this because they're gonna look into some bundled systems. We already have launched what we call the Veeam Ready Appliance qualification. So we already have five server platforms that are qualified to run Veeam as a physical appliance.
I see a lot of orgs probably gonna look at a virtual appliance as well. Um, I'm absent of a recommendation. Of course, the actual answer is, it depends on what is the best mode.
But the fact that this is hardened by default, the fact that this is purpose built to be that Veeam server in those associated roles, and it's, you know, on Linux, it's a lighter footprint, one less thing to have to update, um, the market is super, super excited for that one. So Rick, uh, yeah, Jack, Jack Poller with, uh, paradigm Technica. Um, uh, I love the, uh, concept of a hardened appliance that you can use.
Um, although feels maybe a little bit dated in that a lot of organizations are moving beyond appliances and virtual machines towards containers. You gimme a thought process about containerization and where you are and thought process of Yeah. First containers Kubernetes.
Great. So Jack, great question. Um, number one, the Windows consumption model doesn't go away.
Okay. So what, what has gotten us to mm-hmm. 7 billion?
Well, not, that's not the only product, but it's gotten us here stay in market. This is an option. So that's point number one.
Number two, um, it is reasonable to expect in the future that additional consumption models of this product hosted as a service would use Kubernetes. Okay. Now, what I'm going with that is a important part of our portfolio is the Veeam Data Cloud.
And the, the tech business leader of that actually built our Kubernetes backup product, Veeam casting for Kubernetes. Mm-hmm. Trust me, it's come up internally, but on scale with the ephemeral nature of it, it feels like in the, as a service model is the way in place to do it.
Um, but for on-prem, roll your own, I don't know if the market's there yet. We're looking for, uh, what is it? Yes.
Password an okay. I think those a that's, that's the test to do this right now, you know, two okays and a password. That's how low tech, low barrier of entry.
We're making this option for people. But you know, that's, that's no for now, but not know forever and not know everywhere, if that makes any sense. Yep.
So if you look down the roadmap, will the windows be discontinued or have to parallel? The plan is parallel, yeah. But there will be, at this time, we're aware of one capability that will only be available in the Veeam software appliance model.
And it is due really to technical limitations of, it's a high availability capability. com just for a little bit more and you can watch the replays just until May 30th. Mm-hmm.
But, uh, the thought is we could have two backup servers ha to each other with background Postgres synchronization that gets ugly in windows. So, um, right now there's capability that was planned only for the Veeam software appliance. I don't think there's any others that are planned.
That's, that's the only one that I, yeah. But, uh, generally parody is planned. Um, any other questions on that appliance tour?
Especially, I got the chat up if, uh, uh, Andre or, or Tyler as well have any comments. Um, so we'll talk about the, the next innovation coming from Veeam. And we showed this at VM O as well.
Mm-hmm. And it's a unit, it's is a, a future integration, um, probably beyond 2025, but we're gonna introduce a universal continuous data protection. So the thought is this Veeam data platform that protects data, great.
Continuous data protection is kind of that holy grail in, in my world, of protecting data down to two seconds. Um, I showcase the preview of this technology at Veeam on replicating a system from my desk in Ohio to the, to our data center in Prague on our own Veeam corporate network. And I was able to do that with a one minute RPO with zero misses for a week.
And that's on the early build beta. So that's really exciting. Uh, physical systems, any hypervisor can, can replicate to another system that way.
Uh, the current first target will be for VMware environments and also server environments, but we also have active projects going right now to target other systems, including hyperscalers. So it will be, uh, a game changer for some continuous data protection use cases. So we're pretty excited about that.
Uh, we'll say we support CDP today though. Correct. So we do support that through VMware VAIO filter drivers.
So help majority of everybody else supports CDP that is currently supported today. This is just taking it one step outside of mm-hmm. VMware scope, right.
And looking at a way that we could, could utilize it across the ecosystem. Yeah. Goodchild, existing VMware capabilities, been in the market for a good four or five years, so, uh, or more actually.
So it's really exciting there. And then, um, the last innovation is around ai. And I think I wanna just kind of get the world thinking.
We have a really interesting data fabric that we're working with. If we're backing up most of the organizations of state, it's really interesting what we could potentially do with that. But there's also a lot of concerns.
Mm-hmm. You know, um, and I'll, I'll tell you the first, the first hole in our AI story, which this isn't AI field day, but stay tuned. Um, we don't really, we have not really gone public with our responsible AI statement.
That's what's missing right now. I'll be the first to say that, um, our leadership team's working on that. But when we start getting in and analyzing customer data in the cloud, that changes the game.
So we're, we're on the edge of some really important stuff here for Veeam Guardian. But I will say that, uh, Ben, a colleague on our team did a preview of an innovation here. Uh, the scenario was, it was SharePoint data hosted in Microsoft 365 backed up by Veeam Data Cloud.
And he basically was talking to the data and generating output that, you know, I know how to use Veeam, but if I was trying to answer, these are basically e-discovery is what, what this walks into. I was trying to answer questions about this data, it would've taken me a week to do that and I know how to use Veeam. But he was able to make short work of that and truly talk to the data.
So I think that, you know, as a backup provider, balancing the, you know, the responsibility that comes with providing deep insights to customer data and then the power of ai, we're really on the edge of some, some pretty attractive, uh, future capabilities. Uh, you know, you'll also see across our portfolio, every product is moving fast. You know, we just released our Kubernetes product at, uh, red Hat Summit, uh, last week or two.
Mm-hmm. And, you know, when you think about keeping that data safe, that data resilience story, we're trying to bring it in all these different places. The portfolio is the biggest it's ever been.
And, um, it's a wild time. So, uh, any questions on any of the future innovations and really anything we've talked about here? We do have a little bit of time left, but Yeah.
Um, yeah. Laura, do, Do you have, uh, orchestrator integration for all these new products? We, we've have an orchestrator integration for all these products.
Yeah. So, so part of the Veeam data platform is a product called Veeam Recovery Orchestrator. Um, so Orchestrator helps, uh, you to be able to build customized playbooks.
So if we need to be able to recover specific applications or a stack of applications, we can go ahead and we can do that. And you can actually set up different types of plan steps and you can issue, uh, things like YA rules to be able to scan across multiple iterations of those recovery points. And then it'll build out documentation on the backend so that way a customer will have all of that documentation, plus they could see a good audit trail of what things have changed.
Are we gonna be able to meet SLAs? Are we gonna be able to meet RTOs or RPOs or are those missing? So, um, the Veeam Recovery Orchestrator is part of the Veeam data platform and we see customers utilizing that.
The other pieces also working with just those third party security partnerships of them building out their own playbooks as well. Lars, one other comment on the orchestrator is it solves some of the fundamental basic problems that are out there. Like this product for a good six or seven years has had automated daily recovery point objective and recovery time objective validation.
We've all been there, we implement something day one, Hey, it's good, we'll go home. Let's check day 93. Yeah.
You know, with like 10% growth every day and things like that. This will catch when the, the two hour RTOs now two hours in one minute. The good news is Veeam can scale and we can bring that number down, but this product will catch that, um, and make sure it's free with malware.
So it's, it's good stuff. Any other, uh, questions, comments, observations? And I, I, I, I personally wanna ask specific question.
Um, you know, and Karen, I've known you for a while. Um, Fernando, I've known you, you're different 'cause I talk to you often. But, um, my hope is that the first question I started with, have you seen Veeam lately?
My hope is that this is a different Veeam or maybe more than what you would expect from a backup product. That's the goal of what we wanted to bring here today. So, um, and same goes for the, the audience online.
That's our goal. You know, for this security world, we're a credible, I wouldn't say player, we're not a security platform, but what we are is a very important signal to a security process. Whether it's the integrations, the innovations, or the Veeam difference with Covo by Veeam, I mean we're, we're definitely, uh, that secret weapon.
I think that's part of the solution. Yep. So, uh, so let me eat up your last few.
Go for It. Tony, Bring, and I'm sure, and I'm sure this is a very subjective sort of question, but you guys seem like you have a ton of awesome capabilities and it, you're right. I'm in, I'm, I had no idea Veeam was doing so much, right?
I know Veeam is doing VMware backups. That's what I'm trying To fix, but, you know. Yeah.
But I don't deal with Veeam, so I I'm not plugged in. So my, my question is, uh, licensing and pricing model, I mean, you guys showcased a lot of different features and integrations and things. Does each of those come with an add-on SKU or is it, you know, we, we pay an annual and we get everything in the box or, or What?
There's two top shelf offerings. Okay. Um, the first one is Veeam Cyber Secure.
And you might have noticed I kind of caught when she had that slide up that says that's a package, it includes the warranty. That one is high sh top shelf offering. Okay.
And then there's this other thing called premium, right? And I'll tell you, we are really, um, smart on this pricing. We made this thing called the Universal license.
Um, this is a Windows workstation. Okay? This is one third of a Windows or one third of a Veeam Universal license.
An EC2 instance in the cloud is one universal license. A physical Oracle database is one, a VM is one, everything else is one. 500 terabytes of data is one, uh, from NAS standpoint.
So it becomes really easy to say, I don't know how many systems I have, I don't know, 20,000. Mm-hmm. I'll buy 20,000 VUL.
And then there's even built in Grace and I get that premium, which has the orchestration has immutability. Um, I think if the customer goes in informed with the goal of being resilient, the price is not an issue. It's not a nickel and dime, I'll tell you that.
And, and, and with that in mind, you know, what should, what should an organization, uh, what should their spending target be to be able to, you know, from their IT budget to be able to meet, you know, what is you guys', what do you call it? Premium? No, what was above premium?
Veeam Cyber secure. Yeah. The white glove stuff.
Well, I mean, I'd say it's, it, you know, it depends. I mean, Of course it depends, but I mean, here's the thing is like, you know, there's only so much budget and we have security, we have infrastructure, there's storage, there's all the field days stuff, you know, usually data protection and now, and now there's backups. Mm-hmm.
Right? So if we're doing more than just backups, you know, how much of the budget should we be spending in case we get hit by ransomware and we need to back up? Uh, that's actually a good question from a, let's just call it a predictive fi, predictive finops from a resiliency perspective, I don't have an answer, but I can tell you that usually our, and Emily has a sales background, maybe you can help me here, but I'd say that our spend, our cost, I should say, usually sits in the very high single digit to very low double digit percentage of when a customer says, I'm gonna do all of this.
Okay, forget their staffing cost uhhuh. But when you go out, the, the backup TAM is high single to low double digit. Mm-hmm.
Quote unquote that percentage of a deal. You know, okay. Because we go in, we're talking to people buying servers and storage and applications and all That.
I have multiple conversations now with the ciso, right? They're spending their budget and that's what's what's funding their data protection, data resilience strategy and versus it coming directly out of IT operations. So now it becomes an even, you know, bigger conversation of, okay, well, do we wanna make sure that we could actually perform a recovery?
'cause that's gonna impact, you know, what we do from an incident response play, and then the other portions of it with CO and the retainer services. So, so a lot of that information all comes into consideration, but for the most part, yeah, from what Rick said, the, the universal licensing is very unique. But then on top of that, we could also help customers if they decide to change or move, right?
We're on-prem today. We go into AWS guess what, that universal license. You don't have to go and buy a whole new thing to protect all your AWS workloads.
We can help you with that migration. And those licenses can stay with those workloads or be repurposed. Thank you.