← All articles

Immutable backups: the one control ransomware cannot work around

·2 min read·By Adrian

Also available in ES, RO

Ransomware operators learned years ago that encrypting data is pointless if the victim can simply restore. So the backups are attacked first.

How the attack actually runs

The pattern is consistent:

  1. Initial access, usually through a stolen password or an unpatched service
  2. Weeks of quiet reconnaissance
  3. Escalation to domain administrator
  4. Backup jobs disabled, repositories deleted, snapshots removed
  5. Only then, encryption

By the time anything is visible, the recovery path has already been dismantled — using valid credentials, which is why nothing raised an alarm.

What immutable means

An immutable backup cannot be modified or deleted for a defined retention period, by anyone, including an administrator. The prohibition is enforced by the storage layer rather than by permissions, so stolen credentials do not lift it.

Common implementations:

  • Object storage with object lock in compliance mode
  • Purpose-built backup appliances with hardened repositories
  • Tape, which is immutable by virtue of being in a drawer
  • Cloud backup services offering a locked retention tier

Getting the retention right

Retention has to exceed your detection time. Attackers commonly sit in a network for weeks before triggering encryption, and a seven-day lock is no help if the intrusion began four weeks ago.

Thirty days is a sensible floor. Ninety is better if the volume allows.

The rest of the picture

Immutability protects the copy. It does not protect the credentials:

  • A separate account for backups, not the domain administrator
  • Multi-factor authentication on the backup console itself
  • Alerts when jobs are disabled or retention is changed
  • The backup system outside the domain, so compromising the domain does not compromise it

Test it deliberately

Try to delete a locked backup. It should fail. If it succeeds, the configuration is not what you believe it is — and finding that out now costs nothing.

Our backup and recovery designs assume the attacker will reach the backup system.

← Blog