Immutable Backup: What Your Cyber Insurance Form Really Wants

Free Close-up of hands analyzing insurance policy paperwork with pen on table. Stock Photo

Most cyber insurance renewals now include one question that stops small business owners cold: “Do you maintain immutable, air-gapped, or offline backups of your critical business data?” We sit with clients filling out these forms regularly, and this is the line that produces the longest pause.

It’s on the form for a specific reason. Ransomware crews worked out that the fastest way to force a payment is to destroy the backups first, then encrypt everything else. CISA, the FBI, and the Internet Crime Complaint Center all document this as a standard move in current ransomware playbooks. If your backup copies can be deleted with the same admin login an attacker just stole, you have no way back other than paying.

So the real question isn’t “do you have backups.” It’s whether your backups can survive an attacker who already holds the keys to your network. Those are two different things, and plenty of setups that feel safe fail the second test.

Here’s what immutable actually means, three common setups that don’t qualify even though owners assume they do, the exact questions to send your IT provider before you sign, and what to do if your honest answer is no.

What immutable backup actually means

An immutable backup is one that can’t be changed or deleted for a fixed period of time. Not by you, not by your IT provider, and not by anyone using stolen admin credentials.

That last part is what carriers care about. Most backup systems can be wiped by anyone with admin access. Immutability means the backup platform itself enforces the lock down at the storage layer, so no login, however privileged, can override it during the retention window. Some vendors call this object lock, write-once-read-many, or WORM storage. The names differ, but the control underneath is the same: for a set number of days, the data is frozen.

Three backup setups that don’t count

Three setups come up again and again that don’t satisfy the immutability question, even though business owners often assume they do.

A NAS or external drive in your office

A network-attached storage device (a NAS, the shared box that often lives in the server room) is reachable from your network by design. If ransomware spreads across your environment, it can reach the NAS too. Anyone holding domain admin credentials can wipe what’s on it. An external drive that someone plugs in once a week and leaves connected carries the same exposure.

These devices have a place in a broader backup and recovery plan. On their own, they don’t answer the immutability question.

Microsoft 365 retention used as a backup

Microsoft 365 includes retention features, and some businesses lean on them as their backup. They aren’t a backup in the sense the form means. Anyone with global admin access to your tenant (your company’s Microsoft 365 environment) can delete data and clear the retention holds along with it.

Under Microsoft’s shared responsibility model, backing up and protecting your own data stays with you, separate from what Microsoft handles at the platform level. If the only thing standing behind your Microsoft 365 data is what Microsoft provides natively, the honest answer to the immutability question is no.

A cloud backup with immutability switched off

This is the most common gap we find. Plenty of reputable backup platforms include immutability as a feature, but the setting isn’t always on by default. The capability is there. Someone still has to turn it on. You may be paying for a backup that looks solid on paper while the immutability toggle sits in the off position, and you can’t tell from the outside without checking.

Three questions to send your IT provider before you sign

Copy these into an email and send them before you check the box.

1. Are our backups immutable, and how long is the immutability window?

Carrier expectations have tightened over the past two years. Most insurers now want a window of at least 14 days, and 30 days is increasingly cited as the preferred floor. Attackers often sit quietly in a network for weeks before triggering the ransomware, so a backup from yesterday may already be compromised. The window has to reach back far enough to give you clean restore points from before the attacker arrived.

2. If our admin account were stolen tomorrow, could it be used to delete our backups?

This applies to both your domain admin account and your Microsoft 365 global admin account. The right answer is no. If the answer is yes, or your provider isn’t sure, your backups aren’t immutable in the way the form means.

3. Can you send me proof that immutability is enabled on our account?

A screenshot or vendor documentation showing the setting is on. A provider who can send something concrete has done the work. If they come back with verbal reassurance and nothing to show, treat that as a no until they can prove otherwise.

What a qualifying setup looks like

For your backup to honestly satisfy the question, a few things need to be true at the same time.

Immutability has to be turned on, not just available as a feature. Several major platforms offer it, including Veeam, Datto, Rubrik, and Acronis, along with the cloud storage providers that support S3-compatible object lock (a storage setting that makes files unchangeable for a set time). A vendor name on the invoice doesn’t answer the question by itself. The setting has to be switched on, scoped to the right data, and tied to credentials that aren’t shared with the rest of your environment.

The backup credentials need to sit outside your everyday admin accounts. If the same login that runs your Microsoft 365 environment also controls your backup platform, one compromised account reaches both. A qualifying setup keeps the backup behind separate credentials, away from your day-to-day identity system.

The retention window has to be long enough. A 24-hour backup that overwrites itself every day won’t help if an attacker has been inside for a week. CISA’s #StopRansomware Guide lists immutable, tested backups as a baseline control, and most insurers now line up with that position.

And restores have to be tested. A backup nobody has tried to restore in the past year isn’t something you can count on when it matters. Most carriers now ask for the date of your last successful restore test, and they expect to see one.

What to do if your honest answer is no

Declare what you actually have, and use the renewal as the push to fix what’s missing.

Start by asking your IT provider whether immutability can be turned on with your current platform. Often it already supports it, and switching it on is a configuration change rather than a new purchase. When that’s the case, the whole thing can usually be sorted in a few days.

If your provider doesn’t understand what you’re asking, or can’t give a clear answer to the three questions above, that response tells you something on its own. This is the kind of gap we close as part of a client’s cybersecurity setup, and it’s worth handling before your next renewal even if the rest of your IT is in good shape.

One thing to avoid: don’t check yes on the form to dodge a premium hike. Cyber insurance applications work as warranty documents. If a forensic investigation after a claim finds your backups didn’t match what you declared, the carrier can rescind the policy. Coverage is then treated as if it never existed, and prior payouts under the same policy term can be clawed back. Misrepresentation found after a claim is one of the most expensive mistakes a small business can make on an insurance form.

Checking no will probably cost you something at renewal, in premium or in coverage terms. That’s a known, manageable cost. Take the hit on the application, and use the months before your next renewal to close the gap.

Frequently asked questions

What does immutable backup mean in plain English?

A backup nobody can change or delete for a set period of time, even with administrator credentials. The storage platform enforces the lock at the system level, so user permissions can’t override it.

Is Microsoft 365’s built-in retention a backup?

No. Native retention can be bypassed by a global admin, or by anyone who steals one. Microsoft’s shared responsibility model puts backup of your data on you, separate from retention.

How long should the immutability window be?

Most insurers and security frameworks point to a minimum of 14 days. 30 days is increasingly the preferred floor, and some carriers want longer. A longer window gives you more confident recovery if an attacker has been inside your environment for a while.

Can my IT provider just turn immutability on?

Often, yes. If your backup platform supports the feature and it hasn’t been enabled, this is a configuration change rather than a new purchase. Ask for written confirmation once it’s done.

What happens if I check yes when I shouldn’t?

The carrier can rescind the policy after a claim, which voids your coverage retroactively. Prior payouts under the same policy term can be clawed back too. Misrepresentation is one of the most common reasons cyber claims get denied.

Sources and further reading

If you’re not sure where your backups stand, raise it with your IT provider before your next renewal date. They should be able to walk you through the configuration and give you a clear answer to the three questions above. If you don’t have an IT provider, reach out to us and we’ll help you sort it out.

Featured Image Credit