Answer
The ransomware argument for tape is straightforward: a cartridge sitting in a vault or an offsite rotation is physically disconnected from the network the moment it is removed from the drive, which no cloud target can fully replicate unless it enforces true immutability with locked retention periods that even an administrator cannot override. Buyers should ask cloud vendors specifically whether their immutability is a configurable setting an attacker with stolen credentials could disable, or a hard retention lock enforced at the storage layer regardless of account compromise. That distinction matters more than the marketing language around either option.
Cloud earns its place for different reasons: automation, distance, and reduced dependence on someone physically rotating and transporting media correctly week after week, which is a common point of failure in smaller IT departments. The strongest evaluation approach is to treat media type as a design decision made per recovery scenario rather than a single platform-wide choice. A shop might keep tape for long-term archival and the ransomware-resistant offline copy, while relying on cloud for faster day-to-day offsite protection and easier restore access. Ask whether a candidate platform genuinely orchestrates both from one console and one policy set, or whether tape support is a legacy feature that receives less ongoing development attention.