Ransomware crews know the easiest way to make you pay is to delete your backups first, then lock up everything else. That is why cyber insurance renewal forms now ask if you have immutable, air gapped, or offline backups. If your backups live on the same network you use every day and can be deleted with regular admin logins, the honest answer is no.
What “immutable backups” means in plain English
Think of an immutable backup like a time capsule. You put your data in, seal it for a set period, and during that window nobody can change it or throw it away. Not you. Not your IT provider. Not a criminal who stole an administrator password. The storage system itself enforces that seal so even top level logins cannot switch it off until the timer runs out.
Why insurers care
Attackers often spend days or weeks in a network before they strike. One of their first moves is to wipe out backups. If your backups can be deleted using the same credentials the attacker just stole, you do not have a safe copy to restore from. That leaves you with two bad choices: pay the ransom or rebuild from scratch.
Common setups that feel safe but do not qualify
- A NAS box or an external drive in your office: These devices are connected to your network by design. If ransomware spreads, it can hit them too. An admin with broad access can also delete what is on them. They can be part of a bigger plan, but they are not immutable on their own.
- Relying on Microsoft 365 retention as your backup: Microsoft’s retention features help with day to day issues like accidental deletes. They are not a true backup that is locked from admin changes. A global admin, or someone who steals those credentials, can still purge data and retention holds.
- Cloud backups with immutability turned off: Many reputable backup tools offer an immutability setting, but it is not always enabled by default. You cannot tell from an invoice. Someone has to look and make sure the setting is on.
Three quick questions to email your IT provider
These are worth sending before you check the “yes” box on your insurance form:
- Are our backups immutable, and what is the length of that lock window?
- Most insurers expect at least 14 days. Thirty days is becoming the common minimum.
- If a domain admin or Microsoft 365 global admin account were stolen, could that account delete our backups?
- The correct answer is no.
- Can you send a screenshot or vendor documentation that shows immutability is enabled on our account?
- Verbal promises are not enough. Ask for proof.
What a passing setup looks like
First, immutability is actually enabled on your backup platform, not just listed as a feature. Big names like Veeam, Datto, Rubrik, Acronis, and many S3 compatible storage services can do this, but the switch has to be turned on and scoped correctly.
Second, the logins that control backups are separate from your everyday admin accounts. If the same username that manages Microsoft 365 can also control backups, then a stolen account can reach both.
Third, your retention window is long enough to cover the time an attacker may have been inside your systems without you noticing. A day or two is not enough. Two to four weeks is the current baseline most carriers want to see.
Finally, you test restores. A backup you have never tried to restore is a gamble. Many insurers now ask for the date of your last successful restore test.
What to do if your honest answer is no
Tell the truth on the form. Then use the renewal as a reason to fix the gap. Start by asking your IT provider whether your current platform supports immutability and whether they can enable it. In many cases it is a configuration change, not a new purchase.
If your provider cannot clearly answer the three questions above or cannot show proof, that is useful information. It means this area needs attention soon. What you should not do is check “yes” to avoid a price increase. If a claim investigation finds that your setup did not match what you declared, the carrier can void coverage and even claw back prior payouts.
Why this matters right now in Birmingham
Local small and midsize businesses often run Microsoft 365 and a basic cloud backup. That is a solid start, but many of these setups are not immutable out of the box. Attackers target SMBs because stolen admin logins are easier to get and backup practices vary. Insurers, auditors, and even customers now expect immutable backups and proof that you can restore.
Simple next steps
- Ask your IT company to confirm four things: immutability is on, backup credentials are isolated, the retention window meets insurer expectations, and the date of your last successful restore test.
- Save proof. Keep screenshots and vendor links in a “Cyber Insurance” folder so you can produce them quickly.
- Put a recurring restore test on the calendar. Quarterly is a good rhythm.
Quick Q&A you can share with your team
What is an immutable backup? A copy of your data that cannot be changed or deleted for a set period, even by administrators. The storage system locks it.
Is Microsoft 365 retention enough? No. It helps with routine issues, but an admin or attacker with those rights can still purge data. You still need a separate, immutable backup.
How long should the lock last? At least 14 days, with 30 days increasingly preferred. Longer windows give you cleaner restore points if attackers were present for a while.
Can my IT provider just turn this on? Often yes. Many platforms already support it. Ask them to enable it and send proof.
What happens if I say yes when it is really no? The carrier can void coverage after a claim and recover any payouts. Misrepresentation is a common reason claims get denied.
Need help getting this in place in Birmingham?
If you want a fast, practical path, ask for an audit of your current backups, turn on immutability where supported, separate the credentials, set a 30 day retention window, and run a restore test with screenshots. That gives you real protection and the documentation insurers expect.