How Immutable Backup works
Three-step view of how it operates in practice.
- Write. A backup copy is created using WORM (Write Once, Read Many) storage or object lock technology.
- Lock. The copy is marked immutable for a retention window — days, weeks, or years, during which it cannot be changed.
- Restore. If production data is encrypted or corrupted, the immutable copy remains usable for recovery. The attacker cannot delete it.
Why Immutable Backup matters
Modern ransomware crews hunt for backups first, because a business that can restore has no reason to pay. One immutable copy is the difference between a negotiation with criminals and a restore procedure, and tested, attacker-proof backups have become a standard question on cyber insurance applications for exactly that reason.
Ways to make a backup immutable
- Cloud object lock. Cloud storage with a lock flag that prevents deletion or modification until a retention date passes — enforced by the storage platform itself, not by anything an attacker can log into on your network.
- Hardened backup repository. A purpose-built on-premises backup server, stripped down and disconnected from the domain, that refuses deletion requests during the retention window even from its own administrators.
- Air-gapped media. Tape or removable drives physically disconnected after each backup. Truly unreachable from the network, at the cost of slower restores and manual handling discipline.
- Vendor-native snapshot locks. Immutability features built into backup appliances and SaaS backup products. Convenient, but verify the lock cannot be shortened or removed through the vendor's own admin console — that's the loophole attackers look for.
Common Immutable Backup mistakes
- A lock window shorter than your detection time. Attackers routinely sit in networks for weeks before encrypting, so a seven-day immutability window can expire before you even know you're breached. Size retention to realistic dwell time — think 30 days or more, not a long weekend.
- Backup access tied to domain admin. If the same credentials that run your network can also manage backups, ransomware that captures an admin captures both. Give backup infrastructure its own accounts, its own strong sign-in protections, and no domain membership.
- Confusing offsite with immutable. A replicated copy faithfully replicates the encryption too — offsite answers 'what if the building burns,' not 'what if an attacker holds the keys.' You need at least one copy that no credential in your environment can erase.