8 min

Tape backups versus object storage

Compare tape backups and object storage for 50 TB over five years, including equipment, facilities, recovery charges, speed, and operational risks.

Tape backups versus object storage

A comparison based on the price per gigabyte alone almost always gives the wrong answer. For 50 TB over five years, a cloud deep archive costs about $3,000 for storage alone, a new tape system costs roughly $15,000, and a local object store lands in the $20,000 to $30,000 range. Yet one complete cloud recovery over the internet can add about $5,400, while tape will restore nothing if nobody has tested the catalog and drive.

My short answer is this: deep object archive is cheaper for a copy that is rarely read and can wait a day or two; tape is cheaper when the drive and the operating discipline already exist; a local object repository earns its price when recovery must start immediately. With a strict RTO, the argument over tape or object storage usually ends with a hybrid.

Set equal terms before doing the math

You need to price 50 TB of average occupied backup capacity, not 50 TB of source data. If you have 50 TB of working data today, daily incrementals, monthly full backups, and five-year retention, the repository can easily become much larger. Deduplication does not provide a guaranteed ratio either: encrypted virtual machines, video, archives, and databases that have already been compressed may barely shrink.

In the model below, 50 TB remains unchanged for all 60 months. To keep the arithmetic transparent, I use 50,000 billable GB, US dollars, and prices before taxes, discounts, and exchange-rate changes. Backup software and administrator labor are excluded because those costs depend on licenses already purchased and local salaries. You still need to add them to your own calculation.

If the volume grows, you cannot price 50 TB for the whole five years. At 20 percent annual growth, the occupied volumes will be about 50, 60, 72, 86, and 104 TB. Across five yearly periods, that is 372 TB-years instead of 250, so the cloud line needs to be multiplied by roughly 1.49. Deep Archive rises from $2,970 to $4,420, while S3 Standard rises from $69,000 to about $102,800. Tape grows in steps: as soon as another full copy no longer fits on three cartridges, you must add a cartridge to each set and check whether writing still fits inside the backup window.

Another assumption concerns the number of copies. The cloud line pays for one logical copy, although the provider distributes it inside the stated service architecture. The tape line pays for two independent copies because one cartridge can be lost or damaged. These are not exactly the same topology. To compare the same risk, decide whether you need a cloud replica in another region or a second provider, then double the relevant capacity and replication requests. Do not treat the internal redundancy of one service as an independent backup.

For tape, the model keeps two complete copies on LTO-9. The LTO Program lists 18 TB of native cartridge capacity and 400 MB/s native speed for the LTO-9 generation. I do not count the advertised 45 TB with compression because backup data is often already compressed or encrypted. One copy needs three cartridges and two copies need six; I reserve two more for rotation and replacement.

For public object storage, I use two opposite Amazon S3 classes in the US East region as a verifiable price reference, not a provider recommendation. S3 Standard costs $0.023 per GB per month, while S3 Glacier Deep Archive starts at $0.00099. Another cloud will have different rates, regions, and data-transfer rules, so replace the four rates in the formula instead of rebuilding the whole model.

For local object storage, I count a repository with 50 TB of usable space, free-capacity headroom, disk fault tolerance, a server, networking, and support. A set of disks with an S3 logo on the screen does not become a backup. If a controller failure, account compromise, or room incident destroys both production data and the repository, you bought a convenient second file system.

Cloud is cheap until the first large recovery

Deep archive does win on the capacity charge alone. The calculations for 50,000 GB are as follows.

S3 Standard: 50,000 × 0.023 × 60 = $69,000 over five years.

S3 Glacier Deep Archive: 50,000 × 0.00099 × 60 = $2,970 over five years.

Tape with an existing drive: eight cartridges and rotation cost about $1,300 without off-site storage, or $7,310 with the rotation price assumed below.

Tape with a new drive: media, drive, connectivity, and rotation cost about $14,810.

Local object storage: server, disks, network, power, and support give a planning range of $20,000 to $30,000.

The two tape lines use explicit budget assumptions: $120 per cartridge, $150 for cleaning cartridges, $200 for cases and barcodes, $7,500 for the drive and connectivity, and $100 per month to move and store the second copy. That produces $7,310 with an existing drive and $14,810 when buying a new one. If you own the second site, subtract $6,000. If you need an autoloader, a support contract, or a second drive, add those complete quotes.

Local object storage cannot be priced honestly with one public rate. For a working budget, I set aside $15,000 to $20,000 for the server, disks, and 10-gigabit network, then $5,000 to $10,000 for electricity, cooling, disk replacement, and support over five years. Ask for usable capacity after erasure coding or mirroring, not the sum of the labels on the drives. Ask the supplier to show the expansion cost at 70 to 80 percent full.

With Deep Archive, the bill changes when you read. Standard retrieval costs $0.02 per GB in our example, so 50 TB adds $1,000. A temporary three-day copy in S3 Standard adds about $115. Sending 50 TB over the internet under the tiered US East rate adds about $4,300 after a small free allowance. One complete recovery therefore costs roughly $5,400 beyond storage, before request and compute charges.

Bulk retrieval has a lower read charge, about $0.0025 per GB in the published AWS example, but the wait grows to 48 hours. Three complete exports over five years turn the cheap archive into about $16,500 of recovery expenses plus $2,970 of storage. If the data stays in a service in the same region, there may be no internet transfer charge, but you will pay for target storage and compute. Price the route the bytes take, not the name of the storage class.

Object count also changes the bill. Deep Archive charges for transitions, restore requests, and 40 KB of metadata per object, of which 8 KB is billed at the Standard rate. Millions of tiny files are better packed into managed containers with an index and checksums. One enormous archive is also a poor choice because retrieving one document then requires restoring the whole container.

Currency risk needs its own line for a Kazakhstan organization. The cloud bill is usually tied to the dollar, while payroll, electricity, and some logistics are paid in tenge. I test the model at least at two exchange rates instead of guessing one "correct" rate for five years. With an imported drive, currency risk appears on purchase and replacement dates; with cloud storage, it returns every month. That distinction affects the budgeting process even when the discounted costs are equal.

Tape wins only with a working process

Tape provides a cheap physically disconnected copy, but manual work can easily consume the savings. A cartridge must leave the library, enter a labeled case, be logged, and travel to another room or site. If it sits beside the server for a month "until the next trip," there is no air gap for that month.

Five years is not a difficult media-retention period for LTO under proper conditions. The harder question is whether, after five years, you can find a compatible drive, the catalog, the encryption key, and the recovery instructions. The LTO-9 page confirms that an LTO-9 drive can read and write LTO-8, but compatibility rules change between generations. The migration plan must exist before support ends for the old drive, not after the first read error.

I use five checks for every batch:

  1. The software completed the job without omitted objects, rather than merely returning a green status.
  2. The catalog was exported separately and can be opened without the original backup server.
  3. The checksums of several large and small objects match after reading from tape.
  4. The encryption key is stored separately from the cartridge, but the on-call team knows how to retrieve it.
  5. The barcode in the log matches the physical cartridge and its storage location.

LTO hardware encryption is useful, especially during transport. It also creates an unrecoverable failure if you lose the key. A password stored in the same catalog encrypted by ransomware will not help. You need a separate key-recovery procedure with divided access, tested at least once a year.

An autoloader reduces manual work inside the library, but it does not transport a cartridge to the second site. A designated operator or a storage contract remains part of the system. For 50 TB, a standalone drive looks inexpensive while recoveries are rare; with daily rotation and hundreds of sets, a library quickly becomes a sensible purchase.

Local object storage pays for immediate access

Local object storage costs more than deep cloud archive and tape, but it does not require loading a cartridge or waiting hours for a thaw. The software sees objects continuously, can verify checksums on a schedule, and can return a needed virtual machine immediately. That availability, rather than the S3 protocol, provides most of the value.

Fault tolerance and backup solve different problems. Erasure coding survives the loss of a disk or node. It does not protect against an administrator with delete permission, a lifecycle-policy mistake, corruption of every version by an application, or a fire in one server room. The budget therefore needs a second object system in another zone, tape, or an immutable cloud copy.

A local system has a hidden growth boundary. You cannot fill disks to 100 percent because rebuilding after a failure and redistributing data need free space and network bandwidth. If a supplier promises 50 TB of usable capacity on 50 TB of installed drives, ask to see the protection scheme. A reasonable order for 50 TB of data often includes considerably more raw capacity, but the exact ratio depends on mirrors, erasure-coding layout, object size, and headroom.

Power cannot be dismissed with a single "the data center already has it" line. The server and disk shelves run all day, and their heat must be removed. For example, an average IT load of 350 watts consumes 15,330 kWh over five years. With a factor of 1.7 for cooling and losses, the meter records about 26,100 kWh. Multiply that by your rate, then add two power feeds, rack space, switches, and spare drives.

An object repository is easier to expand in smaller increments, but every new node must fit the compatibility matrix. Mixing disks, firmware, and network cards without checking turns expansion into a long risk window. For a five-year plan, request pricing for the first shipment, later expansion, support in the final year, and exporting the data when the platform changes.

The whole recovery chain sets the speed

Supply with a transparent chain
GSE's domestic production makes equipment origin easier to verify for the backup environment.
Approve the project

The LTO-9 rated speed gives a theoretical minimum of about 34.7 hours to read 50 TB with one drive: divide 50,000,000 MB by 400 MB/s. In practice, allow 40 to 70 hours for seeks, cartridge changes, small files, verification, and target-array limits. If the source feeds data below the drive's minimum sustained speed, tape begins stopping and repositioning, which lowers throughput and wears the media.

Two drives can nearly halve the time if copies are distributed across cartridges and the software can read in parallel. Buying a second drive for a rare emergency is not always economical. A contract for compatible equipment at another site can cost less, but you must test that arrangement with a real recovery instead of relying on a promise over the phone.

Local object storage on a dedicated 10-gigabit network has a theoretical minimum of 11.1 hours for 50 TB. At a sustained 700 to 900 MB/s, the result is about 15 to 20 hours. On a 1 Gbps network, the theoretical limit is already 111 hours, nearly five days. Disk performance is irrelevant if recovery crosses one overloaded port.

Deep archive adds two queues. AWS first prepares a temporary copy: its documentation states up to 12 hours for standard Deep Archive retrieval and up to 48 hours for bulk retrieval. The data then travels over your connection. At 1 Gbps, transferring 50 TB needs the same 111 hours in ideal conditions; with preparation time, RTO can easily exceed five days.

A complete recovery should rarely run as one alphabetical stream. Set the startup order: directory service and DNS, the backup system, databases, critical applications, and then file shares. If the first 2 TB brings the business back in four hours, the total time to read 50 TB no longer describes the useful RTO. The storage design must support that order in practice.

Measure RPO separately. A fast repository does not help when the latest usable restore point is a day old and the business can lose only fifteen minutes. Tape normally accepts larger periodic batches, while object storage is easier to use for frequent incrementals. Compare both the time to read the same 50 TB and the restore point that will actually be available after production is damaged. An RPO requirement can immediately leave tape in the role of a second or archival copy even when its RTO is acceptable.

A test with one file proves only that one file can be read. Once a quarter, recover a complete service into an isolated network and measure archive-preparation time, actual throughput, errors, and manual pauses. The CISA StopRansomware guide explicitly advises keeping critical backups offline, encrypting them, and regularly testing availability and integrity in a disaster-recovery scenario. I would add a measured application startup because a matching checksum still does not guarantee a working system.

Tape needs a storeroom, object storage needs a data center

Eight cartridges do not require a separate hall, but an ordinary drawer beside the rack is not suitable. IBM recommends storing LTO media at 16 to 25°C and 20 to 50 percent relative humidity without condensation. After a sharp temperature change, the manufacturer advises acclimating a cartridge for up to 24 hours to prevent condensation inside the drive.

The tape room must protect against dust, water, fire, direct sunlight, strong magnetic fields, and unrestricted access. It needs a checkout log, closed cases, labeling, and a separate fire zone. A second copy in the next cabinet survives a disk failure but not a fire, flood, or equipment seizure.

The drive belongs in a clean server room with suitable SAS or Fibre Channel connectivity. A standalone setup also needs operator space and a safe place for the cartridge during a change. A cleaning cartridge and the drive-warning log are part of operations. Do not clean the drive on a calendar against its indicator because unnecessary cleaning also wears the mechanism.

Local object storage requires rack space, cooling, backup power, network ports, temperature monitoring, and physical access control around the clock. Public cloud removes those requirements from your room, but it does not remove the network connection, accounts, logging, key management, or rules governing where data may reside. Kazakhstan organizations should approve the hosting region and data-transfer rules before uploading the first copy.

Tape also has a logistics RTO. If the safe is in another city, who can collect the cartridges at night, how long does authorization take, and how will they be transported? Add that time to the 35 hours of reading. For cloud, logistics is replaced by dependence on the telecom provider and access to the console. Both options need emergency contacts on paper.

Immutability is not an air gap

One integrator for the system
GSE combines computing equipment and data-center infrastructure for a specific storage scenario.
Contact GSE

An object protected by WORM locking is not physically disconnected. AWS Object Lock prevents a protected object version from being overwritten or deleted for a set period; in compliance mode, even the account's root user cannot do it. In governance mode, a user with special permission can bypass retention. AWS documentation also notes that locking applies to versions, while a simple DELETE can place a delete marker above a protected version.

This is strong protection against bulk deletion when permissions, retention periods, and logging are configured correctly. Yet the cloud administrator, encryption key, and billing account remain part of the same operating environment. A policy mistake can lock junk for years or leave required versions without retention. Test the setup by attempting deletion from the role an attacker would actually capture.

An ejected cartridge creates a true physical break. A remote command cannot erase it through an API. A person can still lose it, drop it, label it incorrectly, or leave it in the drive. An air gap shifts part of the cyber risk into a physical process rather than removing risk.

It is better to separate four properties: write inaccessibility, immutability for a defined term, geographic independence, and verified recoverability. Tape outside a drive provides the first and third properties, a WORM object provides the second well, and the fourth appears only after a test. One technology rarely covers all four.

Secrets also need separation. Tape keys, cloud encryption keys, administrative tokens, and the catalog should not depend on one identity domain. Otherwise, a catalog compromise can deprive the team of both the copies and the means to read them. Keep the emergency procedure and a minimal set of secrets in a controlled offline system.

You pay for risks after the purchase

A design for your RTO
GSE system integrators connect servers, data-center infrastructure, and recovery requirements in one configuration.
Request an estimate

The most expensive tape risk is a process that fails quietly. Jobs keep writing to the same set, cartridges do not leave the site, the log diverges from the shelf, and testing is postponed. A year later, the company owns an expensive air-gap prop. Assign an owner for rotation and a deputy, or one person's vacation will change your protection model.

The main object-storage risk comes from the shared control plane. Backup software often has permission to create and delete objects, and its credentials are available from the server. Ransomware that obtains those rights attacks the repository through its normal API. A separate account, minimum permissions, denial of retention bypass, and multifactor emergency access matter more than an impressive durability figure on a provider page.

The second group of risks is financial. Cloud services change rates by region and bill separately for requests, retrieval, and transfer. A local system needs disks, support, and expansion earlier than planned. Tape needs a drive from a compatible generation and transportation. Keep a reserve for one complete recovery and one migration, or your TCO describes only uneventful years.

The third group concerns integrity. Encryption protects confidentiality but does not prove that an application wrote a database consistently. Verifying an object hash does not replace a transaction log and a startup test. Create backups with methods that understand application state, and store the recovery report with the catalog.

Finally, there is dependence on one format. LTFS makes it easier to read files from tape, but backup sets may use a proprietary application format. An object API is portable at the command level, but metadata, locks, and policies do not match across systems. Before purchase, ask to see a catalog export and a recovery without the original management server.

Choose from RTO, not cartridge price

For an archive read less than once a year that can wait 24 to 48 hours, a deep cloud class has the lowest entry price. It is especially convenient when the team has no drive, suitable room, or rotation process. Put one standard full retrieval, outbound traffic, and object count into the estimate from the start. If the total remains acceptable, the low price is real.

For a regular offline copy in an existing tape environment, tape is usually cheaper. It fits an organization prepared to own the physical process, store keys separately, and migrate between generations. When buying the whole system for only 50 TB, the advantage shrinks; one standalone drive may still make sense, while a library without frequent rotation will sit idle.

For RTO under one day, choose a local object layer or fast disk repository. Keep recent restore points there and move long-term history to tape or deep cloud archive. This hybrid does not force a cheap archive to behave like fast disk.

Before placing an order, enter six of your own values in one table: usable volume including growth, retention term, number of full recoveries, required time to start the first services, measured network bandwidth, and the cost of a second site. Then ask suppliers for five unbundled lines: equipment, support, media or capacity, read operations, and data transfer. If a line cannot be named in advance, put its formula or ceiling in the contract.

As a system integrator and supplier of server and data-center infrastructure, GSE.kz can build this calculation without tying it to one manufacturer and include local support across Kazakhstan. The recovery owner must still approve the decision, knowing the allowed downtime and being ready to run a full test.

I would not confirm the choice after a write demonstration. Ask the finalists to recover the same dataset, limit them to the same network, disconnect the original management server, and measure time until the application starts. After that test, the argument over the price of 50 TB becomes short: you pay for the option that meets your deadline and survives failure of the primary environment.

FAQ

How many LTO-9 tapes are needed for a 50 TB backup?

Without compression, one complete 50 TB copy occupies three 18 TB LTO-9 cartridges. Two independent copies need at least six, while working rotation and reserve stock usually raise the number to eight or more.

Which is cheaper for 50 TB, LTO or S3 Glacier Deep Archive?

If you pay only for storage and almost never read the data, S3 Glacier Deep Archive is cheaper in this model at about $2,970 over five years. A new tape drive with media and off-site rotation costs about $14,800, but several complete cloud recoveries quickly narrow the gap.

How long does it take to recover 50 TB from LTO-9?

The theoretical minimum for one drive at 400 MB/s is about 35 hours. A realistic plan should allow 40 to 70 hours for cartridge changes, seeks, small files, verification, and target-array limits.

Can Object Lock replace offline tape?

No. Object Lock prevents changes to or deletion of a protected version, but the storage remains connected to an account and depends on its configuration and keys. An ejected tape creates a physical break, although it adds the risk of loss and operator error.

Does LTO require a special storage room?

It does not require a separate hall, but it needs a controlled, dry location with restricted access and protection from fire, water, dust, and magnetic fields. IBM recommends storing LTO at 16 to 25°C and 20 to 50 percent relative humidity without condensation.

Why can cloud recovery cost more than storage?

An archive class bills separately for retrieval, a temporary hot copy, requests, and sometimes internet transfer. For a complete 50 TB recovery, outbound data can be the largest line on the invoice.

Can local object storage be the only backup?

Only if it is independent from production in management, location, and authority, which is difficult to achieve in one data center. It is more practical to keep fast restore points there and place another immutable or offline copy in a different zone.

How often should backup recovery be tested?

Check individual files after every batch and recover a complete service into an isolated network at least once a quarter. Tie full-test frequency to RTO, application changes, and audit rules, but an annual test is usually too infrequent for a critical system.

Should LTO capacity be calculated with 2.5 to 1 compression?

Use native capacity for budgeting. The manufacturer lists 2.5 to 1 as a possible compression ratio, but video, archives, and encrypted backup sets may barely compress.

When is a tape and object hybrid cheaper than one repository?

A hybrid makes sense when recent copies must return within hours while long-term history can wait. Local object storage handles fast recovery, while tape or deep cloud archive lowers long-term retention cost and separates a copy from production.