ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Why Ransomware Crews Hunt Backups First: Immutability Explained

Ransomware targets backups first. Learn what immutable backups are, how they differ from offline copies and what to ask your vendor before relying on them.

3 min readBy Counsel Cyber Team

When criminals deploy ransomware, they do not only encrypt your files. Many groups first search for backup systems, then delete or encrypt them so there is nothing to restore from. A firm with a clean backup can recover without paying. A firm whose backups were destroyed faces a much worse choice. Immutable backups exist to prevent that outcome, and they have become a common requirement in cyber-insurance applications.

This post explains the concept without jargon, so administrators and partners can ask the right questions.

What immutable means

An immutable backup is a copy that cannot be changed or deleted for a set period, even by someone with administrator rights. Once written, it is locked. If an attacker takes over your domain administrator account, or even the backup console, they cannot erase the immutable copies until the retention period ends.

The idea is sometimes called WORM, for write once, read many. It is applied through storage settings, such as object lock features offered by cloud storage platforms, or special modes in backup appliances.

Immutable versus offline versus air-gapped

These terms are related but not identical.

  • Immutable: connected and reachable but protected from modification or deletion for a retention window.
  • Offline or air-gapped: physically or logically disconnected from the network, such as tapes or drives that are removed and stored elsewhere. They cannot be reached remotely, but they require manual handling.
  • Logical separation: stored in a different account with separate credentials, which helps but is not equivalent to immutability if the same attacker can reach those credentials.

CISA's ransomware guidance recommends maintaining offline, encrypted backups and testing them. Immutable cloud copies can serve a similar purpose for many firms, with less manual work.

Why standard backups fail

Consider a hypothetical firm whose backup server is joined to the same domain as everything else, managed with the same administrator password. An attacker who steals that password in a phishing attack can log in to the backup server, delete the repository and then launch the ransomware. The firm had backups on paper and nothing in practice.

What to ask your vendor

  1. Is immutability enforced at the storage level, not just by software settings that an administrator can reverse?
  2. How long is the immutability window, and can it be shortened by anyone?
  3. Which data is covered: servers, endpoints, Microsoft 365, databases?
  4. Are backup credentials separate from your domain, and protected by MFA?
  5. What happens when the retention period ends, and how are older copies expired?
  6. How is data encrypted, and who holds the keys?
  7. How quickly can you restore from the immutable copy, including large volumes over a realistic internet connection?
  8. Can the vendor's own staff delete the data, and what safeguards apply?

Design considerations

Retention length

Attackers sometimes wait weeks before activating ransomware, so recent backups may already contain malware. A longer retention window, with multiple restore points, gives you somewhere clean to return to. Balance this against storage cost and your records policies.

Recovery speed

Immutability protects the data but does not speed up recovery. Pair it with a local copy for fast restores, and keep the immutable offsite copy for worst-case events. This matches the idea behind the 3-2-1-1 approach, with at least one copy that is immutable or offline.

Separate identity

Create dedicated accounts for backup administration, with MFA, and do not reuse credentials that exist anywhere else.

Protect the keys

If backups are encrypted and the key is lost or stored only on a compromised server, the data is unusable. Store recovery keys securely outside the primary environment.

Test it

An immutable backup that has never been restored is an assumption. Include the immutable copy in your restore testing and time the result. Confirm that you can reach the recovery console from outside your network if your environment is down.

Budget and perspective

Immutable storage typically adds modest cost compared with the total backup spend, and it addresses a risk that can threaten the survival of a firm. When balancing budgets, treat it as a priority control.

Wrap-up

Ask your IT provider whether you have a truly immutable copy, where it lives and when it was last restored. If the answer is unclear, that is the first thing to fix.

Counsel Cyber designs backup systems for law firms that include immutable copies, separate credentials and regular restore tests. We are glad to review what you have in place.