Immutable Backups and Cyber Insurance: What You Need to Know

Getting your Trinity Audio player ready...

If you’ve renewed your cyber insurance recently, you’ve probably noticed a question that wasn’t on applications a few years ago:

“Do you maintain immutable, air-gapped, or offline backups of your critical business data?”

For many business owners, it’s an unexpected question. But insurers have good reason for asking it.

Modern ransomware attacks don’t just encrypt your files, they often target your backups first. The Cybersecurity and Infrastructure Security Agency (CISA) recommends maintaining immutable, offline, and tested backups as one of the most effective defenses against ransomware attacks. Cybercriminals know that if they can delete or corrupt your backup copies before launching ransomware, businesses are left with one difficult choice: pay the ransom or lose their data.

That’s why insurance carriers now place so much emphasis on backup security. If an attacker can erase your backups using stolen administrator credentials, your organization may have no reliable way to recover.

In this guide, we’ll explain what immutable backups are, highlight backup strategies that don’t meet insurance requirements, share the questions you should ask your IT provider before completing your renewal, and explain what to do if your current backup solution falls short.

What Is an Immutable Backup?

An immutable backup is a backup that cannot be altered, overwritten, or deleted for a predetermined period of time, even by administrators, your IT provider, or someone using stolen administrator credentials. That last point is what matters most to insurance companies.

Traditional backup systems often allow administrators to delete backup files. If cybercriminals gain access to those administrative accounts, they can erase your backups before deploying ransomware.

Immutable storage prevents that from happening. Once backup data is written, it remains locked until the retention period expires. No administrator can override that protection.

Depending on the vendor, you may see this feature referred to as:

  • Object Lock
  • Write Once Read Many (WORM)
  • Immutable Storage

While the terminology varies, the goal is always the same: protect your backup data from being modified or deleted.

Three Backup Setups That Aren’t Immutable Backups

Many businesses believe their backups are protected when, in reality, they wouldn’t satisfy an insurer’s definition of immutable storage.

1. A NAS Device or External Hard Drive

A network-attached storage (NAS) device or external hard drive still plays an important role in many backup strategies, but by itself, it isn’t enough.

Because a NAS is connected to your network, ransomware can often reach it. Likewise, if an external drive remains plugged into your computer after backups run, it can also become encrypted or deleted during an attack.

These devices can certainly be part of a layered backup strategy, but they do not qualify as immutable backups on their own.

2. Relying Only on Microsoft 365 Retention Policies

Microsoft 365 includes retention and recovery features, leading some organizations to assume they already have a complete backup solution. Unfortunately, retention policies are not the same as independent backups.

If an attacker compromises your Microsoft 365 Global Administrator account, they may still be able to delete data or remove retention protections. Under Microsoft’s shared responsibility model, customers remain responsible for protecting and backing up their own data.

If Microsoft’s native retention tools are your only safeguard, the truthful answer to the insurance question is typically no.

3. Cloud Backups Without Immutability Enabled

This is one of the most common gaps organizations discover during insurance renewals. Many cloud backup platforms support immutable storage, but the feature isn’t always enabled by default.

In other words, you may already own a capable backup solution, but unless immutability has been turned on and configured correctly, your backups may still be vulnerable. The only way to know is to verify the settings with your IT provider.

Three Questions to Ask Your IT Provider Before Renewing

Before checking the box on your cyber insurance application, ask your IT provider these three questions.

Question 1: Are our backups immutable, and how long is the retention period?

Today’s cyber insurance carriers typically expect immutable backups to remain protected for at least 14 days, while 30 days is increasingly becoming the preferred minimum.

Since attackers often spend days or even weeks inside a network before launching ransomware, longer retention windows provide a much better chance of restoring clean data.

Question 2: If our Microsoft 365 Global Administrator account or domain administrator account were compromised, could those credentials delete our backups?

The answer should be no. If stolen administrator credentials can erase your backups, they aren’t truly immutable in the way insurers expect.

Question 3: Can you provide documentation showing immutability is enabled?

Ask for screenshots or vendor documentation rather than verbal confirmation. A provider who has properly configured immutable storage should be able to demonstrate it. If they can’t, assume the feature isn’t fully implemented until proven otherwise.

What Qualifying Immutable Backups Look Like

Meeting cyber insurance expectations involves more than simply purchasing backup software.

A qualifying backup strategy typically includes several key components:

  • Immutability is actively enabled, not simply available as an optional feature.
  • Backup administrator accounts are separate from your everyday Microsoft 365 or domain administrator accounts.
  • Retention periods are long enough to recover data from before an attacker entered your environment.
  • Backups are tested regularly through successful restore exercises.

Many leading backup providers, including Veeam, Datto, Rubrik, and Acronis, offer immutable backup capabilities.

However, using one of these vendors doesn’t automatically mean your backups meet insurance requirements. Proper configuration is just as important as the software itself.

Just as importantly, backups should be restored and tested on a regular basis. A backup that has never been tested shouldn’t be trusted during a real disaster.

What If You Don’t Have Immutable Backups?

If your organization doesn’t currently have immutable backups, answer your insurance application honestly and use the renewal process as motivation to strengthen your backup strategy.

Start by asking your IT provider whether immutable storage can be enabled within your existing backup platform. In many cases, it’s simply a configuration change rather than a costly replacement.

If your provider cannot clearly explain how your backups are protected, or cannot answer the three questions above, that should be viewed as a warning sign. It’s worth addressing long before your next renewal.

One mistake to avoid is checking “Yes” simply to receive a lower premium.

Cyber insurance applications are legal documents. If a future investigation determines your backup environment didn’t match what you declared, the insurance carrier may deny or even rescind coverage.

While answering “No” may increase your premium or result in stricter policy terms, those costs are far less expensive than discovering your claim has been denied after a ransomware attack.

Closing the backup gap now is one of the smartest investments you can make in both your cybersecurity strategy and your cyber insurance coverage. To learn more, contact Twintel today.

Twintel Logo
+ posts

Twintel has grown into an expansive, full team of IT services professionals, acting as the outsourced IT department of non-profits, small to mid-size businesses, and enterprise-level corporations in Orange County, across California, and nationally.

Today, it’s the strength and deep expertise of the Twintel team that drives positive outcomes for clients. Each of the support staff, technicians, and engineers works diligently each day to make sure that the companies served have the seamless, secure, and stable IT environments needed to allow them to pursue their organizational objectives.

Learn more...