What “Immutable Backup” Means on Your Cyber Insurance Form
If you have filled out a cyber insurance application recently, you may have seen a question like “Are your backups immutable or offline?” Many business owners tick yes because they have backups. But having backups and having immutable backups are different things, and the difference is exactly what ransomware attackers look for.
Immutable backup, defined
An immutable backup is a copy of your data that cannot be changed or deleted for a set period of time, by anyone, including someone who has stolen an administrator password. Once written, it is locked. If ransomware encrypts your files and tries to erase your backups, the locked copies survive and you can restore.
This is usually done with storage that supports “write once, read many” behavior, such as object lock in cloud storage, a hardened repository on a backup server, or a backup service that offers immutability as a built-in setting. An “offline” backup reaches the same goal differently: the copy is physically disconnected or stored somewhere your systems cannot reach.
Why insurers ask
Modern ransomware attackers do not just encrypt your files. They look for your backups first and try to delete or encrypt them, so you have no choice but to pay. Insurers have seen this enough to ask directly whether your backups can be tampered with. A “no” can affect your premium, your coverage or whether you are offered a policy.
Setups that often do not qualify
These are common, reasonable-looking arrangements that may not meet the definition:
A network drive or external drive in the office. If it is plugged into your computer or reachable on the network, ransomware can reach it too. A drive that is sometimes unplugged is better, but only if it is truly disconnected when an attack happens.
Microsoft 365 retention treated as a backup. Recycle bins and retention settings help you recover from deleted files for a limited time. They are not a separate, locked copy, and an attacker with administrator access, or a sync of encrypted files, can still cause permanent loss. A separate backup of your Microsoft 365 data is the safer approach.
A cloud backup with immutability switched off. Many backup services include the feature but do not enable it by default, and a deletion with a stolen administrator login goes through. Check the setting, and confirm it with your provider.
Backups sharing the same login as everything else. If the account that manages backups is the same one an attacker steals, locks do not matter. Backup administration should have its own credentials and multi-factor authentication.
What qualifying immutable backups look like
The details vary, but a solid setup usually has these parts:
- Several copies, at least one stored away from your main systems. The common rule is three copies, on two kinds of storage, with one off-site.
- At least one immutable or offline copy, with a retention period long enough to outlast the time an attacker can sit unnoticed in your network. Weeks, not days, is a reasonable aim.
- Separate, protected credentials for backup administration, with multi-factor authentication.
- Regular restore tests, because a backup you have never restored is a hope, not a plan.
- Monitoring and alerts so that a failed or missing backup is noticed the same day.
See our backup and disaster recovery page for what a good backup plan includes, and our post on how ransomware attacks work for why attackers go after backups.
Three questions to ask your IT provider before you sign
- Is at least one copy of our data immutable or offline, and how long is it locked for?
- Who can delete or change our backups, and what does it take to do it?
- When did we last restore from backup, and how long did it take?
If your honest answer is no
Answer the form accurately. An incorrect answer on an application can cause serious trouble at claim time. A “no” today is something you can fix: ask your IT provider for a plan and a date, and talk with your insurance broker about how to describe a project that is in progress. Many fixes, such as turning on immutability in a service you already pay for, are quick and inexpensive. Our cyber insurance readiness service helps you review your answers before you submit.
Frequently asked questions
What does immutable backup mean in plain English?
A backup copy that is locked so it cannot be altered or deleted for a set time, even by someone with administrator access. If ransomware hits, that copy is still intact.
Is Microsoft 365’s built-in retention a backup?
Not in the sense insurers mean. Retention and recycle bins help with deleted items for a limited time, but they are not a separate locked copy of your data. A dedicated backup of Microsoft 365 is the safer answer.
How long should the immutability window be?
Long enough that an attacker lurking in your network cannot wait it out. Many providers use periods of several weeks or more. Ask your IT provider and insurer what is appropriate for your situation.
Can my IT provider just turn immutability on?
Often yes, if your backup service supports it, though some setups need a change in storage or settings and sometimes a higher price. Ask what it will involve and what it will cost.
What happens if I answer yes on the form when it should be no?
A wrong answer can give the insurer grounds to dispute a claim or, in some cases, to cancel the policy. Policies differ, so talk with your broker, and when in doubt, check the facts with your IT provider before you submit.
