If ransomware hits, attackers often delete your backups first, then lock up everything else. That is why cyber insurance applications now ask, “Do you maintain immutable, air gapped, or offline backups of your critical data?” If backups can be changed or deleted with normal admin credentials, the real answer is no. That answer can affect your renewal, your premium, and your ability to collect on a claim.
What “immutable backup” means
An immutable backup is a copy of your data that nobody can change or delete for a set amount of time. Not you. Not your IT provider. Not an attacker using stolen admin credentials. The storage system enforces the lock. Vendors may call it Object Lock, WORM, or immutable storage. Different names, same idea.
CISA, the FBI, and the Internet Crime Complaint Center (IC3) document that ransomware actors frequently wipe backups first, then encrypt everything else. If a thief can use the same admin account you use every day to delete your backups, you have no clean way to recover.
Setups that do not count as immutable
A NAS or external drive in your office
A NAS on your network or a drive that stays plugged in is reachable by ransomware. If attackers get domain admin, they can erase it. These devices can be useful for quick restores, but they are not immutable.
Treating Microsoft 365 retention as a backup
Microsoft 365 has retention features, but a global admin, or anyone who steals that login, can purge data and retention holds. Under Microsoft’s shared responsibility model, backing up your data is still your job.
Cloud backups with immutability turned off
Many good backup tools offer immutability, but it is not always on by default. You have to enable it and verify it. Do not assume it is active.
Three questions to email your IT provider today
- Are our backups immutable, and what is the immutability window? Insurers often want at least 14 days. Thirty days is becoming the norm because attackers can sit in a network for weeks.
- If our domain admin or Microsoft 365 global admin account were stolen tomorrow, could that account delete our backups? The only acceptable answer is no.
- Can you send a screenshot or vendor documentation showing immutability is enabled on our account? Verbal assurances are not enough. Ask for proof.
What a passing setup looks like
Immutability is actually turned on for the data you care about. The feature must be enabled, not just available in the product. Common vendors that support this include Veeam, Datto, Rubrik, Acronis, and S3 compatible storage with Object Lock.
Backup credentials are isolated from your day to day admin accounts. The logins that control backups should be separate from Microsoft 365 and domain admin logins. If one set is stolen, attackers still cannot touch your backups.
The retention window is long enough. Aim for at least 14 days. Thirty days is safer and often requested by carriers. Longer windows increase your odds of having a clean restore point.
Restores are tested. Run a restore test at least once a year and record the date. Many insurers ask for it.
What to do if your honest answer is no
Tell the truth on the application, then use the renewal to fix gaps.
Start with your current platform. Ask your IT provider if immutability can be enabled where you already back up. Often it is a configuration change, not a new purchase.
Watch for red flags. If your provider cannot clearly answer the three questions above, or will not provide proof, treat that as a priority issue to resolve before your next renewal.
Do not check yes if it is not true. If a post incident investigation shows your backups were not immutable, the carrier can rescind the policy and claw back payouts. That mistake is costly for small businesses.
Why Columbus and Central Ohio businesses should act now
From the Arena District to Dublin, Hilliard, Worthington, and New Albany, local businesses are regular targets. Immutable backups are now basic table stakes for cybersecurity and insurance readiness in Central Ohio. If you work with a Columbus IT company or MSP, ask for immutable, tested backups to be part of your standard service, not an optional add on.
Quick checklist
- Immutability is enabled and documented with a screenshot or vendor proof
- Retention window is at least 14 days, 30 days preferred
- Backup admin credentials are isolated from everyday admin accounts
- A restore test was completed and logged in the last 12 months
- Insurance application answers match reality
FAQs
What does immutable backup mean?
A backup that cannot be changed or deleted for a set time, even by administrators. The storage system blocks it.
Is Microsoft 365 retention a backup?
No. A global admin can still purge data. You need separate, immutable backups.
How long should the immutability window be?
At least 14 days. Thirty days is becoming standard. Some insurers ask for longer.
Can my IT provider just turn immutability on?
Often yes, if your platform supports it. Ask for written confirmation or a screenshot.
What happens if I say yes on the form when I should not?
The insurer can void the policy after a claim and claw back payouts. Misrepresentation is a common reason claims get denied.
Article heavily inspired by The Technology Press