When criminals deploy ransomware, they do not only encrypt your files. Many groups first search for backup systems, then delete or encrypt them so there is nothing to restore from. A firm with a clean backup can recover without paying. A firm whose backups were destroyed faces a much worse choice. Immutable backups exist to prevent that outcome, and they have become a common requirement in cyber-insurance applications.
This post explains the concept without jargon, so administrators and partners can ask the right questions.
What immutable means
An immutable backup is a copy that cannot be changed or deleted for a set period, even by someone with administrator rights. Once written, it is locked. If an attacker takes over your domain administrator account, or even the backup console, they cannot erase the immutable copies until the retention period ends.
The idea is sometimes called WORM, for write once, read many. It is applied through storage settings, such as object lock features offered by cloud storage platforms, or special modes in backup appliances.
Immutable versus offline versus air-gapped
These terms are related but not identical.
- Immutable: connected and reachable but protected from modification or deletion for a retention window.
- Offline or air-gapped: physically or logically disconnected from the network, such as tapes or drives that are removed and stored elsewhere. They cannot be reached remotely, but they require manual handling.
- Logical separation: stored in a different account with separate credentials, which helps but is not equivalent to immutability if the same attacker can reach those credentials.
CISA's ransomware guidance recommends maintaining offline, encrypted backups and testing them. Immutable cloud copies can serve a similar purpose for many firms, with less manual work.
Why standard backups fail
Consider a hypothetical firm whose backup server is joined to the same domain as everything else, managed with the same administrator password. An attacker who steals that password in a phishing attack can log in to the backup server, delete the repository and then launch the ransomware. The firm had backups on paper and nothing in practice.
What to ask your vendor
- Is immutability enforced at the storage level, not just by software settings that an administrator can reverse?
- How long is the immutability window, and can it be shortened by anyone?
- Which data is covered: servers, endpoints, Microsoft 365, databases?
- Are backup credentials separate from your domain, and protected by MFA?
- What happens when the retention period ends, and how are older copies expired?
- How is data encrypted, and who holds the keys?
- How quickly can you restore from the immutable copy, including large volumes over a realistic internet connection?
- Can the vendor's own staff delete the data, and what safeguards apply?
Design considerations
Retention length
Attackers sometimes wait weeks before activating ransomware, so recent backups may already contain malware. A longer retention window, with multiple restore points, gives you somewhere clean to return to. Balance this against storage cost and your records policies.
Recovery speed
Immutability protects the data but does not speed up recovery. Pair it with a local copy for fast restores, and keep the immutable offsite copy for worst-case events. This matches the idea behind the 3-2-1-1 approach, with at least one copy that is immutable or offline.
Separate identity
Create dedicated accounts for backup administration, with MFA, and do not reuse credentials that exist anywhere else.
Protect the keys
If backups are encrypted and the key is lost or stored only on a compromised server, the data is unusable. Store recovery keys securely outside the primary environment.
Test it
An immutable backup that has never been restored is an assumption. Include the immutable copy in your restore testing and time the result. Confirm that you can reach the recovery console from outside your network if your environment is down.
Budget and perspective
Immutable storage typically adds modest cost compared with the total backup spend, and it addresses a risk that can threaten the survival of a firm. When balancing budgets, treat it as a priority control.
Wrap-up
Ask your IT provider whether you have a truly immutable copy, where it lives and when it was last restored. If the answer is unclear, that is the first thing to fix.
Counsel Cyber designs backup systems for law firms that include immutable copies, separate credentials and regular restore tests. We are glad to review what you have in place.