Continuous Resilience Enforcement — every backup vendor and cloud

Prove recoverability. Keep it true as the estate changes.

A completed backup job is not recoverability. Forttic continuously checks 3-2-1-1-0 and policy across every vendor and cloud, remediates inside your guardrails, and proves the restore. Not another backup. Not posture-only.

Three reasons recovery plans expire
The estate changed. Attackers went for the backups. “We think” stopped counting.
96%
of ransomware attacks target backup repositories (Veeam)
2.3×
median ransom demand when backups are compromised (Sophos)
DORA
Article 11 enforcement live since Jan 17, 2025
Governs every major backup tool — vendor-agnostic by design
VeeamCommvaultDruvaClumioAWS BackupAzure BackupGoogle Cloud BackupAWS Elastic Disaster RecoveryCommvault Air Gap Protect VeeamCommvaultDruvaClumioAWS BackupAzure BackupGoogle Cloud BackupAWS Elastic Disaster RecoveryCommvault Air Gap Protect
Why recovery plans expire

The estate changed. The attestation did not. That gap is the risk.

New accounts, new volumes, new vendors — then ransomware, insurers, and regulators ask what is actually true today. None of them accept quarterly theater.

01 · Change

The estate moved since the last review.

Deployments, migrations, and new accounts open coverage gaps between quarterly checks. Forttic discovers what is running, what is protected, and what should be — then keeps that view current.

02 · Attackers

Ransomware now goes for backups first.

Backups went from the recovery plan to the primary objective. 96% of attacks target backups; 76% succeed. When they do, the median ransom doubles to $2.3M. A job-success screenshot is not a clean restore point.

03 · Proof

Boards, regulators, and insurers do not accept “we think.”

DORA Article 11 is in force. NIS2 and SOC 2 Type II want operating effectiveness over time. 25–40%+ of cyber claims are rejected for control drift between application and incident.

→
A completed backup job is not recoverability. Copies, media, offsite, immutability, and a proven restore have to be true together — after every change.
What Forttic does

Posture tools show the gap. Forttic closes it and proves it.

Four outcomes from one enforcement loop — across the backup tools you already run. Observation leaves the work on your team. Forttic discovers, remediates inside your guardrails, verifies the restore, and keeps the evidence current.

01 / CHANGE

Stay current through change

Agentless inventory of backup assets and cloud configuration — compute, databases, storage, network, IAM. Coverage gaps surface when the estate moves, not at the next audit.

02 / RECOVER

Restore from a copy you can trust

Isolated restore tests prove RTO, RPO, and immutability. Clean recovery points for tier-1 workloads — not a job-success screenshot.

03 / SPEND

Spend on recovery that works

Duplicate coverage, over-retention, and orphaned snapshots get named with a dollar figure. Align spend to verified recovery, not silent sprawl.

04 / PROVE

Prove the claim

Timestamped Verify-stage records for DORA, NIS2, SOC 2, and cyber insurance. Board-ready when they ask — generated by running, not by audit-prep.

CRE Framework

Five stages. One loop that keeps recoverability true.

Discover, assess, enforce, verify, report. Every cloud, every vendor — closing the gap between configured policy and live recoverability in minutes, not quarters.

01
Discover

Inventory everything that affects recoverability.

02
Assess

Score drift by impact and urgency.

03
Enforce

Remediate within approval guardrails.

04
Verify

Prove RTO/RPO and restoration outcomes.

05
Report

Generate compliance and board evidence.

The Backup Standard

3-2-1-1-0 is the rule everyone configures. Forttic checks it continuously.

Every layer eliminates a specific class of data loss. Forttic makes continuous, auditable adherence provable across multi-cloud and hybrid environments.
3
Layer 01
Copies

Three distinct copies, with co-location detection. Copy-count drift detected the moment retention or replication fails.

2
Layer 02
Media types

Storage diversity enforced. Three buckets in one region won't pass. Cross-vendor concentration risk flagged before incidents reveal it.

1
Layer 03
Offsite

Geographic separation validated against cloud-provider metadata — not self-reported config. AZs don't count. Regions do.

1
Layer 04
Immutable

Object Lock continuously verified. Governance-mode tampering detected. The layer ransomware hunts for is the one we watch hardest.

0
Layer 05
Errors

Tiered verification — clean-room restores on tier-1 workloads. The only layer that determines whether your backup actually saves you.

Vendor Coverage

Keep your stack. Forttic governs recoverability across it.

Forttic sits across the backup tools you already run so 3-2-1-1-0 and policy stay consistent on every vendor and cloud. When change is required, Forttic can coordinate approved actions through Commvault, Clumio, and other protection systems.

Veeam
Enterprise backup platform
Vault config Replication Immutability
Commvault
Includes Air Gap Protect & Threatwise
Cleanroom Air gap WORM
Druva
SaaS-delivered data resilience
SaaS Multi-cloud
Clumio
Cloud-native backup & archive
Snapshot discovery Archive
AWS Backup
Including Elastic Disaster Recovery
Vault Lock Cross-region
Azure / GCP Backup
Native Microsoft & Google services
Soft delete Geo-redundant
How Forttic Decides

Agentic architecture built for resilience decisions.

Knowledge supplies the rules. Memory supplies context. Triggers fire on real events. Skills act. Tools execute — every decision auditable and mapped to the regulation it satisfies.

01

Knowledge

Control standards and regulations codified into decision logic.

02

Memory

Operational context retained across incidents and team changes.

03

Skills

Prebuilt actions execute remediation and verification workflows.

04

Triggers

Event-driven responses to drift, tampering, and risk signals.

05

Tools

Native integrations across backup vendors and cloud platforms.

Ask Forttic

Resilience decisions you can finally delegate.

A backup console answers "did the job run?" Forttic answers the questions from your CISO, CFO, auditor, and incident commander — in plain English, from live data.

Incident Mode
"Ransomware suspected at 2 AM. Show me clean recovery options ranked by RTO for affected workloads."
→ Sub-minute response · verified clean recovery points
Regulatory
"Generate the DORA Article 11 evidence package for our EU regulator visit on Tuesday."
→ Mapped controls · time-stamped audit trail · examiner-ready PDF
Board-Level
"CFO is asking before the board call: are we ransomware-safe? Generate the defensible one-page answer."
→ Executive synthesis · dollarized exposure · top risks

See all example decisions →

Where Forttic fits

Forttic doesn't replace any tool you own. It proves recoverability across them.

Backup vendors protect. Posture tools observe. Forttic is the enforcement layer: it checks whether recoverability still holds, closes drift inside your guardrails, and keeps the evidence current.

What each layer does (observation)

Backup posture tools — scan, map, report. See the drift; the doing is left to you.
Backup vendors — protect the enterprise inside their own stack. Forttic governs recoverability across them.
CSPM / DSPM — security and data lens, not recovery. Not built for backup proof.
+

What Forttic adds (enforcement)

Closes the gap observation surfaces — bounded autonomy, audited every step
Vendor-neutral by structure — one recoverability surface across every backup vendor
Continuous evidence mapped to DORA, NIS2, SOC 2, ISO 27001, HIPAA
Security and platform, same recoverability question

Two rooms. One enforcement layer.

Security and platform walk in together. One team gets quantified recovery risk. The other gets governed action instead of ticket chasing.

Security · CISO · GRC

Risk you can stand behind

Quantified ransomware exposure, denial-defense evidence, and board-ready scores from live restore records — not inherited assumptions from last quarter's attestation.

  • Timestamped Verify-stage records for insurers and examiners
  • DORA, NIS2, SOC 2 evidence generated by running
  • Cross-vendor visibility without another backup contract
Platform · ResOps · Backup

Speed without the blind spots

Coverage gaps after change, silent job failures, and retention drift get a governed response. Low-risk fixes auto-remediate. High-impact actions escalate with an audit trail.

  • One recoverability surface across Veeam, Commvault, Druva, Clumio, and cloud-native backup
  • Less ticket chasing; more verified closure
  • Ask Forttic answers incident, board, and examiner questions from live data
Free CRE assessment · ~3 minutes

See where recoverability is already drifting.

Eight questions across the CRE loop — Discover, Assess, Enforce, Verify, Report. Leave with a gap map and a concrete next step. This is a maturity snapshot — not a connected-estate scan.

Start the free assessment →
Pricing

Per-account economics. No surprise overages.

Priced by cloud account. Not by resource, not by API call, not by backup copy. Predictable.

Professional
Discover
Platform teams getting a baseline
Per account
Custom pricing — contact us for quote
Get a quote
  • Continuous Discover + Assess loop
  • 3-2-1-1-0 estate scoring
  • Multi-cloud (AWS, Azure, GCP) discovery
  • Up to 3 backup vendor integrations
  • Drift detection & alerting
  • Quarterly compliance reports
Enterprise / Sovereign
Sovereign
Regulated, public sector, multi-region
Custom
Annual commitment, SLA-backed
Talk to us
  • Everything in Enforce, plus:
  • Single-tenant / sovereign deployment options
  • Custom data residency (EU, UK, US, APAC)
  • Dedicated technical account manager
  • Custom regulatory framework mappings
  • API and SIEM integration
  • Executive readiness reviews
  • 24×7 support

Not sure where you sit? Run the free resilience assessment — we'll map your maturity and recommend a starting tier.

Talk to us

See recoverability on your own stack.

Renewal coming? DORA examination ahead? Briefing in 30 minutes — on the estate you already run.

Send us your questions

Go deeper

Full guides for every part of the platform

Everything above is the snapshot. These pages go deeper on why recoverability expires, the CRE loop, agentic decisions, vendor coverage, and the readiness assessment.

Frequently asked questions

Everything most teams ask in the first 30 minutes.

What is Continuous Resilience Enforcement (CRE)?

Continuous Resilience Enforcement is how Forttic keeps recoverability true after the estate changes: discover what is protected, score drift against 3-2-1-1-0 and policy, remediate inside your guardrails, verify the restore, and report timestamped evidence — across every cloud and backup vendor.

How is this different from CBPM tools like Eon?

Observation vs. enforcement. Posture and CBPM tools scan, map, score, and report. Forttic closes the gap those tools surface: it remediates inside your guardrails, verifies the restore, and keeps evidence current. Vendor-neutral by structure — not another backup console.

I already pay for backup. Why also Forttic?

Protection systems protect the enterprise inside their own stack. Forttic proves recoverability across them, produces unified evidence, and remediates silent failures inside guardrails. When change is required, Forttic can coordinate approved actions through Commvault, Clumio, and other protection systems.

Our enterprise is consolidating backup vendors. Does Forttic still apply?

Yes. Consolidation takes years. Most enterprises run two to four vendors at once. Forttic governs all of them — and enforces the survivors when consolidation finishes.

How does Forttic help with cyber insurance?

Denial defense. 25-40%+ of cyber claims are now rejected for control drift. Forttic's Verify-stage record is the timestamped artifact that defeats a misrepresentation denial.

What does Forttic do about ransomware?

Three things: verifies immutability in real time, enforces backup-credential isolation, runs clean-room restore tests for tier-1 workloads. 96% of attacks target backups; when they fall, the ransom doubles. Forttic removes the lever.

We're in the US, not the EU. Does Forttic still apply?

Yes. DORA and NIS2 are EU-only — but SOC 2 Type II demands operating effectiveness over time, US insurers audit drift forensically, and ransomware doesn't care about geography. Same evidence artifact satisfies all of them.

Does Forttic make decisions without human approval?

Only ones you authorize. Low-risk drift auto-remediates. Higher-impact decisions escalate. Every action is logged with before/after state.

How does the architecture work in practice?

Knowledge supplies the rules. Memory supplies context. Triggers fire on real events. Skills act. Tools execute. Every decision is auditable, reversible where possible, mapped to the regulation it satisfies.

Do I need to replace my existing backup vendor?

No. Keep Veeam, Commvault, Druva, Clumio, or whatever you run today. Forttic uses their APIs to connect requirements, check them continuously, and coordinate approved actions.

What kinds of decisions can I actually delegate to Forttic?

Cross-vendor recovery exposure. Clean-room test gaps. Object Lock changes by user. DORA Article 11 evidence on demand. Region-failure RTO simulation. Duplicate-coverage cost analysis. Forttic connects those questions to the protection systems you already run.

What does recovery verification actually look like?

Tiered. Lightweight checks continuously. Clean-room restores for tier-1 workloads (typically quarterly). On-demand full drills when needed. Credible — not theater.

How is Forttic different from Veeam, Commvault, or Druva?

Those platforms protect workloads inside their own consoles. Forttic is the enforcement layer across them: it checks 3-2-1-1-0 continuously, proves the restore, and coordinates approved actions when change is required.

Does Forttic need CSPM or DSPM to work?

No. Forttic discovers cloud configurations natively — compute, databases, storage, network, IAM — alongside every backup asset. CSPM/DSPM findings can be ingested as context, but optional.

How is CRE different from CSPM or DSPM?

CSPM observes cloud from a security lens. DSPM observes data from a sensitivity lens. Forttic observes the same cloud plus the backup estate from a recovery lens — then acts.

How does Forttic save money if it's an added layer?

Three payback paths: (1) duplicate backup coverage you're paying twice for; (2) retention right-sizing beyond compliance minimums; (3) eliminated audit-prep cycles.

Does Forttic require agents or production access?

No. Read-only IAM role into cloud-provider and backup-vendor APIs. No agents on production. Decision execution limited to the backup estate.

What regulations does Forttic help with?

DORA Article 11, NIS2, SOC 2 Type II, ISO 27001 A.12.3, HIPAA. Continuous, time-stamped evidence mapped to specific controls.

What does week one look like?

Read-only IAM connection, automatic asset discovery, initial posture scoring within 24–48 hours. First isolated-recovery records typically inside the first week. Skills activate once decision guardrails are defined with your team.

Stop hoping backups recover.
Prove it — and keep proving it.

Book a 30-minute briefing to walk recoverability on your estate — or start with the free assessment if you want a maturity snapshot first.