Modern ransomware doesn't just encrypt your live systems - it actively hunts for and destroys backups first, specifically to remove the option of recovering without paying. Immutable backups are the direct answer to that tactic: a backup copy that literally cannot be altered or deleted, even by someone with full admin credentials.
Why This Matters Now
Earlier ransomware attacks mainly encrypted live data and hoped victims had no backup to fall back on. Attackers have adapted - many now specifically seek out and delete or encrypt backup files and snapshots as one of their first moves, before triggering the main encryption event. If your backup can be deleted using the same credentials an attacker has already compromised, it's not a reliable fallback.
What "Immutable" Actually Means
An immutable backup is written once and locked for a defined period - during that window, the data cannot be modified, encrypted, or deleted by anyone, including an administrator with full credentials, and including the backup software itself. This is typically enforced at the storage layer (write-once storage, or "object lock" features on cloud storage), not just through software permissions that a compromised account could override.
Why This Is Different From Standard Access Controls
Standard backup permissions rely on account access being properly restricted - useful, but not foolproof, since an attacker who compromises an admin account inherits whatever that account is allowed to do, including deleting backups. Immutability removes that pathway entirely: even a fully compromised admin account cannot delete or alter a backup during its locked period, because the restriction exists at the infrastructure level, not the account permission level.
How It Fits Into a Broader Backup Strategy
Immutability isn't a replacement for good backup fundamentals - it's an additional layer on top of them. See our guide on the 3-2-1 backup rule for the underlying structure (multiple copies, multiple media types, an offsite copy) that immutable backup should sit alongside, not instead of.
Setting the Immutability Window
The locked period needs to be long enough to cover realistic detection time - the gap between an attacker first gaining access and the business actually noticing something is wrong, which industry data increasingly shows can be weeks rather than days. A common approach is a 30-day minimum immutability window, with some businesses in higher-risk categories extending to 60-90 days for additional margin.
Is This Only for Large Enterprises?
It used to require expensive specialist infrastructure, but immutable backup is now a standard feature offered by most major cloud backup platforms at a modest cost premium over standard storage - genuinely accessible to small and medium businesses, not just large enterprises with dedicated infrastructure budgets.
What to Ask Your Backup Provider
- Is immutability enabled on our backups, and for how long?
- Is the immutability enforced at the storage layer, or only through account permissions?
- Would a compromised admin account be able to delete our backups today?
Frequently Asked Questions
Does immutability replace the need for offsite backup copies?
No, they solve different problems - immutability protects a copy from being altered or deleted, while offsite storage protects against physical disasters affecting your primary location. A properly designed backup strategy uses both together, not one instead of the other.
Can immutable backups still be affected by ransomware at all?
The backup data itself can't be encrypted or deleted during the immutability period, but ransomware can still encrypt your live production data before backup - immutability protects the backup copy specifically, not your live systems. It ensures you have something clean to restore from, not that the attack never happens.
How long should the immutability period be set for?
Long enough to cover realistic dwell time - the gap between when an attacker gains access and when the attack is actually detected, which industry data increasingly shows can be weeks. 30 days is a common minimum; some businesses set 60-90 days for added margin.
Is immutable backup significantly more expensive than standard backup?
It typically adds a modest premium over standard backup storage, since the underlying technology (write-once storage, object lock) is not dramatically more expensive to provide - the differential is far smaller than the potential cost of a ransomware incident with no clean recovery point.
We configure immutable backup for Perth businesses as standard, so a compromised admin account can't take your recovery option away too.
Backup & DR Services →Not sure if your current backups are actually immutable?
Call 0433 087 091 - we'll check your current backup configuration, no obligation.
Get a Free Backup ReviewFor related reading, see our guides to how to protect your business from ransomware and how much business backup costs.