Sound Networks IT Support
Sound Networks IT Services
IT Support
Managed IT Services
Cyber Security
AI
Insights
Networks

Request free IT audit

This site uses cookies for functionality and analytics Manage Close

Immutable backups

Do you maintain immutable, air-gapped or offline backups of your critical business data?

Insurers ask because modern ransomware attacks often target backups first. If attackers can delete your backups using stolen administrator credentials, they can encrypt your systems and leave you with little option but to pay the ransom.

This guide explains what immutable backups are

We also will cover which backup methods don't qualify, what to ask your IT provider before completing your renewal, and what to do if the answer is no.

What is an immutable backup?

An immutable backup cannot be altered or deleted for a fixed period, even by your IT provider or someone using stolen administrator credentials. This protection is enforced by the backup platform itself, often using technologies such as Object Lock or Write Once, Read Many (WORM) storage. While terminology varies between vendors, the principle is the same: once written, the backup cannot be changed until the retention period expires.

Backup solutions that don't qualify

Many businesses assume they're protected when they aren't.

A NAS or external hard drive

A NAS or permanently connected external drive can usually be accessed using the same network credentials as the rest of your environment. If ransomware reaches your network, it can often encrypt or delete these backups too.

Microsoft 365 retention

Microsoft 365 retention policies are not a replacement for a dedicated backup. An attacker with Global Administrator access may still be able to remove data or compromise your recovery options. If you rely solely on Microsoft's built-in retention features, the honest answer to the insurance question is usually no.

Cloud backups without immutability enabled

Many cloud backup platforms support immutability, but it isn't always enabled by default. Simply using a reputable backup provider doesn't mean your backups are immutable—you need to verify the feature has been configured correctly.

Three questions to ask your IT provider

Before completing your renewal, ask:

  • Are our backups immutable, and how long is the retention period? Most insurers now expect at least 14 days, with 30 days increasingly considered best practice.
  • If our Microsoft 365 Global Administrator or Domain Administrator account was compromised, could an attacker delete our backups? The answer should be no.
  • Can you provide evidence that immutability is enabled? A screenshot or vendor documentation should confirm the setting is active.

What does a compliant backup look like?

To satisfy most insurers, your backup solution should:

  • Have immutability enabled—not simply available.
  • Use separate credentials from your everyday administrator accounts.
  • Retain backups for an appropriate period.
  • Be regularly tested to confirm data can be restored successfully.

An untested backup should never be assumed to work when it's needed most.

What if the answer is no?

Answer honestly on your insurance application and use the renewal process as an opportunity to improve your backup strategy.

In many cases, immutability can be enabled on your existing backup platform without replacing the software. If your IT provider can't clearly explain how your backups are protected or answer the questions above, it's worth investigating before your next renewal. Whatever you do, don't tick Yes unless you're certain your backups meet the requirements. Cyber insurance applications form part of your policy, and inaccurate information could allow an insurer to reject or invalidate a future claim.

Paying a slightly higher premium is far less costly than discovering your policy won't pay out after a ransomware attack.

Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Need Help?