Welcome, everybody. Thanks for joining us today, and thanks to Carahsoft for hosting this webinar.
Today’s session is called “One Platform, Every Industry,” and that title is a direct claim about what Bacula Enterprise does across the full spectrum of government environments.
Whether you are managing infrastructure for a federal agency, a DoD component, the intelligence community, or state and local government, the data protection challenges you face are very different from those of commercial enterprises. They are also very different from what many commercial tools were designed to handle.
Over the next 50 minutes, we will walk through four areas in depth. We are going to talk about HPC and national laboratories, government at the federal, state, and local levels, defense and the intelligence community, as well as healthcare.
For each one, we will examine what makes the environment genuinely difficult, how Bacula addresses those specific requirements, and who is already relying on Bacula to protect their most critical data.
Let’s start with a quick agenda of what we are going to do today.
We will talk about how legacy platforms can fail in very complex environments. I am not here to criticize any specific vendors. This just gives you a baseline for everything that follows.
Then we will walk through each vertical, including HPC research, government and federal organizations, defense and the intelligence community, healthcare and life sciences, and some cross-vertical themes.
Each section will generally follow the same structure: the specific challenge, Bacula’s answer, and our real-world proof.
Most backup tools on the market were built for generic enterprises. They assume a relatively homogeneous environment, reasonable data volumes, and reasonable compliance requirements.
However, the organizations represented here today and the ones we generally work with—national laboratories, federal agencies, state and local governments, defense organizations, and hospitals—do not really have reasonable requirements. They have extreme ones.
There are four areas where legacy platforms consistently fail to meet these demands.
The first is platform coverage.
Government agencies are heterogeneous by nature. They have mixed operating systems, mixed hypervisors, physical and virtual infrastructure, on-premises and cloud environments, databases, and specialized systems.
A lot of legacy tools force you to choose between coverage and complexity. You often do not find out that you have a gap until you need to recover a file and discover that the file is not there.
The second issue is licensing economics.
Capacity-based licensing, whether it is per gigabyte, terabyte, or petabyte, punishes you for protecting more data.
The purpose of backup is to protect all your data. We do not want to punish you for protecting it.
As your data volumes grow, the bill grows. This creates an incentive not to back up data. You back up less because you do not want to pay more.
That is exactly the opposite of what your security posture should look like.
The third issue is hidden external dependencies.
A lot of platforms have phone-home capabilities, whether they connect to a cloud licensing server, a SaaS control system, telemetry endpoints, or something similar.
In a sensitive or classified environment, that is not merely a nuisance. It is a non-starter.
The fourth issue is ransomware.
If your backup is reachable and mutable, it is not a recovery plan. It is just another attack surface.
Adversaries actively target backups first because they know that destroying the backups is what will make an organization pay.
If they compromise your backup and leave you with no way to recover, they have achieved what they wanted.
Each of these four failures appears in a different form within each vertical, and we will walk through them.
Let’s talk about what this looks like at the HPC, research, and national laboratory scale.

High-performance computing is where scale stops being just a figure of speech and becomes one of the most important considerations.
These environments run massive parallel I/O operations against petabyte-scale file systems. The backup layer cannot become a bottleneck.
Bacula’s architecture is built to handle that parallelism. It protects enormous datasets without stealing cycles from the compute jobs that justify having the cluster in the first place.
The economics matter just as much as throughput.
If you are being charged per petabyte, gigabyte, or another capacity metric, data protection can become financially unsustainable.
The more science you conduct, the more data you generate, and the more you are penalized.
Bacula licenses an HPC cluster per compute core. That matches the growth curve that research computing runs on and keeps the cost model completely predictable.
You can grow your data from one petabyte to one million petabytes. Your cost remains the same.
HPC environments also require long-term archival, parallel streams, storage tiering, and similar capabilities.
Bacula treats all of these as core parts of the system. They are not bolt-ons or add-ons. They are part of the core product.
As you will see in the healthcare segment, the same characteristics carry forward into genomic research, healthcare research, medicine, and related areas.
The proof is not hypothetical.
Bacula is in production at Los Alamos National Laboratory, Idaho National Laboratory, Sandia National Laboratories, other government laboratories, federal research agencies, and academic HPC centers.
The national laboratory story leads directly into our next area: government and federal organizations.
Governments typically have a requirement that no other vertical necessarily has: a true air gap.

This does not simply mean storing backups in a separate location or using an isolated network segment.
True air-gapping means a backup system that has no outbound dependencies.
There are no calls to licensing servers, no SaaS cloud components, no telemetry, and nothing else. It is completely isolated from everything outside the environment.
We anchor this claim in CNSSI 4009-2015.
This is not marketing language. We do not claim that we have a logical air gap because we do not believe there is such a thing. This is a true air gap.
This matters because many other vendors require their software to communicate with a licensing server or send telemetry.
In a classified or sensitive network, you cannot do that. It is a non-starter.
We have never had those capabilities in our product. It is not something we previously had and later turned off. It has never been there.
The entire licensing and management stack can operate while fully disconnected. We never have to communicate with it.
It is not simply a feature. It is how we built the system.
From the compliance side, we have done the work to align with FedRAMP, FISMA, NIST SP 800-53, CNSSI 4009, DOE Order 205.1D, and other frameworks.
These are deployment frameworks, not simply things we claim we can support.
We can walk through these frameworks with security and compliance staff and demonstrate how Bacula maps to the relevant security components.
For procurement, we have GSA schedules and subcontracts through Carahsoft, as well as options for state and local organizations through Carahsoft.
We are already well established to handle acquisition.
Let’s move on to the next point.
When your architecture must operate inside a Sensitive Compartmented Information Facility on a classified network, the backup platform must have zero external dependencies or it cannot be deployed.

It does not meet the CNSSI definition otherwise.
There is no middle ground. Any product that must connect to an external system for any reason is out.
Here is a statement worth remembering from today:
Bacula is one of the only enterprise backup platforms that can be deployed inside a SCIF on a classified network with zero external dependencies.
We are currently deployed with the U.S. Air Force, the U.S. Navy, and many government contracting agencies.
We support many air-gapped environments. We are also closing out another 13 air-gapped environments for the federal government, hopefully this month.
For compliance, we map to CMMC Levels 2 and 3 across the control families that matter most for data protection.
These include access control, audit and accountability, system and communications protection, and configuration management.
We also handle Controlled Unclassified Information, ITAR data, and government data with encryption, immutability, and full audit logging.
These capabilities are already built in at no additional cost.
We also deploy in DoD Impact Level 4 and Impact Level 5 cloud environments.
When cross-domain solutions are involved, Bacula’s clean, dependency-free architecture makes it straightforward for a component to be accredited instead of becoming a source of additional risk.
The proof is operational.
NASA is probably one of our largest data consumers, with several deployments. We also work with the U.S. Army, the U.S. Navy, and other organizations.
Now let’s examine one of the environments with the greatest security risks: healthcare.
This is where the issue stops being only an IT problem and becomes a patient safety problem.
Healthcare has the highest average data breach cost of any sector, at more than $10 million per breach.
When systems are down, patient care is at risk.
When you cannot access patient data, you cannot see their allergies, sensitivities, which medications are due, or which medications are not due. This creates a major issue.
The question for every healthcare organization is simple:
Is your backup architecture part of your ransomware defense, or is it just another target?
Bacula’s immutable, air-gapped backups create a recovery layer that attackers cannot alter, delete, or access.
This is combined with encryption for data in transit and at rest.
When systems are down, you can recover quickly and demonstrate recoverability. The audit logging required by HIPAA is also available.
When your primary environment is compromised, your recovery point remains intact.
That is the entire point of backups.
The second story here connects with the earlier HPC section.
Research hospitals and genomic facilities generate enormous petabyte-scale datasets.
They need the same types of backup capabilities that we discussed for HPC, including long-term archival, parallel processing streams, and tiered storage.
The same platform handles both clinical and research environments.
That is a real advantage, especially for academic medical centers that operate across both worlds.
We have a large national cancer center that is moving approximately 60 petabytes onto the back end.
We also have two large medical schools conducting genomic data modeling and biomedical statistical analysis, as well as several other large research institutions doing similar work.
Again, the pricing and licensing model does not punish you for the amount of data you generate. It remains highly predictable.
Now let’s examine the four themes that these environments have in common.
When you look across HPC, federal organizations, state and local government, defense, and healthcare, four recurring themes consistently emerge.
The first is complexity.
Every one of these environments is heterogeneous.
They have mixed operating systems, storage systems, workloads, database structures, and ancillary platforms.
Most generic backup tools force you to choose between coverage and complexity.
With Bacula’s plug-in architecture, you do not have to make that trade-off.
You do not have to purchase the capability to back up every hypervisor on the market.
You select the plug-in that covers the hypervisor you use, whether it is VMware, Nutanix, Proxmox, OpenStack, or another platform.
Everything is licensed individually, so you are not buying anything you do not need.
The next theme is compliance.
The standards differ, including FedRAMP, CMMC, HIPAA, and DOE 205.1D.
However, the underlying components are generally the same: encryption, immutability, audit logging, and demonstrable recoverability.
Those capabilities are all built into Bacula.
They serve every framework and help you demonstrate the compliance and auditing requirements relevant to your vertical.
The next theme is cost pressure.
Bacula’s HPC licensing is based on cores. Everything else is licensed per agent.
Every budget is under strain.
Backup is often treated as a commodity until something goes wrong. Then everybody asks why the backup was not there to take care of the problem.
Our pricing gives you the capability and predictability to understand what your licensing costs will be every year.
It removes the perverse incentive to protect less data to keep your budget intact.
We do not care how much data you back up. We want you to back up all of it.
The other theme is cyber resilience.
Ransomware does not discriminate. Attackers will target almost anything.
Healthcare is popular. Retail is popular. Everything is popular nowadays.
Every organization on this call is a target.
The only real question is whether your backup is part of your defense or part of your attack surface.
I am also going to briefly discuss financial services.
We did not examine the sector in depth today, but it is another significant vertical for us.
Its requirements map directly to what we have already discussed, including encryption and key management, as well as extremely low recovery point and recovery time objectives.
If that is your world, let’s talk.
We do have some questions, so we can go ahead and get into those.
The first question is: What are the hardware requirements, if any?
Hardware requirements? Everybody always asks this question.
I would say it depends.
It depends on your environment and what you want to back up.
Bacula itself is very lightweight.
There are four essential components to Bacula.
There is the Director, which does what its name suggests: it directs the backups.
You have a File Daemon, a Storage Daemon, and the Catalog.
The Catalog is simply a PostgreSQL database.
Again, it is very lightweight. Each individual record is not large at all.
If your Catalog gets remotely close to a terabyte, it is already massive.
The requirements depend on what you are backing up, the volume, the file sets, the number of files, and the number of Storage Daemons you need.
The Storage Daemons connect directly to the storage and handle the movement of data.
The File Daemons collect the files and pass them to the Storage Daemons.
Determining your requirements involves a conversation with one of our pre-sales engineers so that they can understand what you need based on what you are backing up.
However, you do not need a supercomputer to run Bacula.
The next question is: What is the estimated pricing per core?
Estimated pricing per core is also something we would need to discuss directly.
The pricing is tiered.
There are tiers covering zero to 5,000 cores, 5,000 to approximately 25,000 cores, 25,000 to 100,000 cores, 100,000 to one million cores, and one million cores and above.
The next question is: Do you have a data sheet available? If so, where would it be located, or would you be able to email me a copy?
Absolutely. We would be happy to email you a copy of anything you are looking for.
You can visit baculasystems.com. Everything is available there.
You can also email me directly or communicate through Carahsoft.
We have data sheets, white papers, and other resources.
The next question is: What is Bacula’s FedRAMP and ATO status?
That is a very good question.
For FedRAMP, the customer deploys Bacula within their own authorization boundary.
It is an in-boundary component, not a hosted service. Therefore, we do not require a separate FedRAMP Marketplace listing.
It also inherits and supports the customer’s Authorization to Operate.
We have ATOs at some of the national laboratories.
Based on recent guidance from the Office of the Director of National Intelligence, these are inheritable across both the intelligence community and the DoD.
The next question is: What exactly do you mean by no cloud callback?
When we deploy Bacula, the entire stack is installed in your environment, including the licensing and management components.
There are no outbound calls to a licensing server or anything similar.
Once the software is installed in your environment, we have no way to communicate with it.
There is no licensing checkout to a cloud server, no SaaS control plane, and no telemetry.
We never need to access your environment, and we do not.
The only thing we may ask you to do is send us a system report if you are experiencing a problem and need troubleshooting assistance.
That report contains no information other than the Bacula system configuration.
That is the only thing we ever see.
We do not even remotely connect to your environments.
In a worst-case scenario, we will use screen sharing, and you will type the commands that our support engineers instruct you to enter.
This keeps us consistent with CNSSI 4009 and air-gapping requirements.
Our licensing model does not need to connect anywhere.
You purchase the license, receive it, and use it. That is how it works.
How does Bacula map to CMMC Level 2?
We map to the control families most relevant to data protection.
These include access control, audit and accountability, system and communications protection, and configuration management.
You have role-based access controls, audit logging, encryption in transit and at rest, system hardening, and version control for configurations.
We can also provide a control-by-control crosswalk that assessors can use.
The next question is: Is Bacula hardware-agnostic?
Yes.
We do not run on z/OS if you want to use it on a mainframe. Almost everything else is within scope.
We do not care whether you are running Dell, HPE, or another hardware platform.
We do not care which tape drives or storage systems you use.
We can run on almost anything.
We have not really encountered many systems that we cannot support.
Whether you have Spectra Logic tape systems, Quantum drives, or something similar, there is no problem. We are certified for both.
We are also certified for many different storage platforms from vendors such as HPE, Dell, and NetApp.
Can Bacula deploy in DoD Impact Level 4 and Impact Level 5 environments?
Yes. We can operate in Impact Level 4 and Impact Level 5 cloud environments.
The same dependency-free architecture is important there.
It makes the accreditation process cleaner.
Procurement through the Solutions for Enterprise-Wide Procurement program, GSA, and Carahsoft also makes the process easier.
What does a proof of concept look like in a classified environment?
A proof of concept works in essentially the same way in any environment.
You have a call with one of our sales representatives and one of our systems engineers.
You discuss your environment and what you are looking to back up.
We then create a proof-of-concept quote with a cost of zero because we do not charge for the 30-day proof of concept.
Once we receive the signed agreement, you receive a link to download the software from a repository.
We schedule a call, walk you through the installation, and help you with the initial configuration.
We also provide demonstrations showing how the web and graphical interfaces work, how to configure file sets, and other relevant functions.
The proof of concept then runs entirely within your environment.
It does not matter whether it is a classified environment inside a SCIF. The proof of concept runs in your environment with no external connectivity.
Our engineers help with setup and validation.
For sensitive environments, we work through your integrator or cleared staff.
The deliverable is a functioning system running verified, immutable, and air-gapped backups against your own data.
It is relatively straightforward.
Another question is: How does per-core licensing save us money at scale?
That is easy. Imagine you build an HPC cluster with 50,000 cores and have one petabyte of data.
That data may grow by 500 terabytes per month, one petabyte per month, or at another rate.
When you pay based on capacity, your bill grows every month.
You do not frequently change the CPU core count of an HPC cluster, if you change it at all.
If you are going to change the core count, you are probably building a new cluster anyway.
With Bacula, your pricing remains flat and static because it is tied to your computing capacity.
That makes it predictable.
If you decide to build a new 100,000-core HPC cluster, your price will increase, but you will know that well in advance.
You can call us and say, “I am going to build this new cluster. How much will it cost?”
You will know the cost in advance, include it in your budget, and be prepared.
We are not going to penalize you because you are conducting valuable research or generating large amounts of data.
You will generally have the same bill year after year, with the exception of occasional price increases.
It is easy to calculate your savings based on that model.