Write-Only Spokes. Zero Lateral Risk.
Consolidate multi-site Veeam backups across isolated plants and remote facilities without site-to-site VPNs, open firewall ports, or ransomware propagation risks.
Air-gap resilience with automated central hub consolidation.
Ransomware-Proof Hub and Spoke Backup for Veeam
Multi-Site Centralization Without VPN Vulnerabilities
Protect distributed industrial facilities from catastrophic data loss. Agilicus AnyX enables remote sites to push Veeam backup archives over write-only shares, while your central backup server ingests data in read-only mode, completely eliminating lateral attack vectors.
No Site-to-Site VPN
Write-Only Push Immutability
Outbound-only HTTPS
PROBLEM / SOLUTION
Organizations managing multiple industrial plants, water utilities, or distributed substations need to consolidate backups to a central Veeam server. However, traditional replication methods introduce dangerous lateral attack surfaces. Agilicus AnyX delivers a resilient, isolated architecture:
The Operational Challenge
❌ Ransomware Lateral Traversal: Site-to-site VPNs create broad network visibility. If malware infects one facility or the central backup server, it spreads across the VPN to corrupt repositories and peer plants.
❌ Costly On-Site Silos: Purchasing, maintaining, and licensing dedicated backup storage appliances at every remote plant creates massive capital expenditure and administrative overhead.
❌ NAT and Firewall Complexity: Remote sites connected via Starlink, cellular SIMs, or double-NAT lack public IPs, making inbound replication and port forwarding impossible without fragile tunnels.
The Customer Outcome
✅ Write-Only Push Security: Remote plants mount the central repository as write-only over outbound HTTPS. Spokes cannot read other sites’ data and cannot pull files back, stopping malware reflection.
✅ Read-Only Veeam Ingestion: The central Veeam Backup Server mounts deposited data read-only. It processes and archives backups without the ability to modify or overwrite pushed immutable files.
✅ Zero-Footprint Deployment: Operates entirely over outbound HTTPS, traversing Starlink, cellular CGNAT, and restrictive firewalls with zero on-site hardware silos required.
Why Enterprises Choose Agilicus for Multi-Site Backup
Zero Trust architecture engineered to satisfy industrial reliability requirements and strict enterprise cybersecurity standards.
Write-Only Push Isolation
Spokes contribute data to dedicated incoming directories without read permissions, preventing malicious reverse-injection even if a central storage repository is compromised.
Zero Lateral Network Exposure
Eliminate complex site-to-site VPN meshes entirely. Branch locations remain completely invisible to each other, stopping the propagation of ransomware across facilities.
Air-Gap & Cellular Traversal
Replicate backups reliably over Starlink, cellular LTE/5G, and double-NAT environments using outbound-only TLS without public IP addresses or firewall port forwarding.
HOW IT WORKS
1
Deploy Connector
Run the lightweight Agilicus connector at each remote spoke facility and the central Veeam backup hub.
2
Configure Write-Only Spokes
Assign remote plant agents write-only deposit paths for local backup dumps over outbound HTTPS.
3
Mount Read-Only on Veeam Hub
The central Veeam Backup Server mounts the consolidated repository in read-only mode for ingestion.
4
Automate & Protect
Automate scheduled backups across all remote facilities with complete audit logging and zero lateral risk.
Resilient Multi-Site Backups. Absolute Isolation.
“Agilicus AnyX enables us to centralize Veeam backups from dozens of remote plant facilities into our core datacenter seamlessly, eliminating site-to-site VPNs and completely removing ransomware lateral traversal risks.”