Home›Guides›IT backup

IT backup

What is an immutable backup?

An immutable backup is a copy that nobody can modify or delete before a fixed period ends: not the user, not the administrator, and not an attacker who has stolen their credentials. When the period ends, the copy can expire or be renewed; until then, it remains read-only.

Updated October 20263 min read4 sources cited

Key points

  • Immutability is enforced by the storage itself, not by a setting that the administrator could untick.
  • It protects copies against deletion by ransomware or a stolen account, but replaces neither encryption, nor antivirus software, nor restore tests.
  • Against ransomware, 30 to 90 days is a common target; for a legal obligation, the period set by the law, applied only to the documents concerned.
  • The ANSSI, France’s national cybersecurity agency, recommends keeping at least one offline copy: immutability is its logical equivalent for a copy that stays online.

Why immutability exists

Conventional backups remain files that the backup software is able to delete. This is useful to avoid filling up storage. It is also exactly what ransomware does when it takes control of the console: delete the copies before encrypting production, leaving no choice but to pay. Immutability moves the decision: deletion is refused by the storage itself for N days, not by a checkbox the administrator can untick.

It also serves as evidence. An accounting document or a record that must be presented unaltered cannot live on a volume where any operator can rewrite the history.

Immutable, offline, conventional: three levels of protection

The ANSSI reiterates the “3-2-1” rule: three copies of the data, on two different media, one of which is offline. The offline copy remains the safest defence against ransomware, because no connected account can reach it. The immutable copy plays the same role for a backup that must stay online, and therefore be quick to restore.

Conventional backupImmutable backupOffline copy
Deletion by an administratorPossibleRefused until expiryImpossible without physical access
Resistance to a stolen accountLowHighHigh
Restore speedHighHighSlower (medium must be brought back)
Discipline requiredLowLowRegular media rotation

What immutability is not

  • It is not encryption. Encryption prevents reading without the key. It does not prevent deletion.
  • It is not retention. Retention says “we keep 30 days”. If the administrator can shorten that period or purge, it is not immutable.
  • It is not antivirus software. Production can still be encrypted. Immutability lets you recover an earlier version.
  • It is not instantaneous. The immutable copy is as old as the last successful backup. If the last clean copy is from the day before, you lose a day of work.

How to implement it

The most widespread mechanism is called WORM: write once, read many. You write once, read as often as you like, and never overwrite. Cloud object storage and some NAS devices offer object locking. The lock must still not be liftable by the same account as production, and the period must exceed the time needed to discover the attack.

Three points to check before choosing a solution:

  1. Who can lift the lock? In “compliance” mode, nobody before expiry. In “governance” mode, a privileged account can: that account must then be protected like the rest of the backup infrastructure.
  2. Are actions logged? A refused deletion request is a valuable warning sign.
  3. Is the backup console isolated from production? The ANSSI recommends dedicated, named administration accounts, and backup servers that do not join the production directory.

A tape removed from the drive and stored offsite is a physical form of immutability, provided someone really does the rotation.

Useful period

Against ransomware: often 30 to 90 days, sometimes more if detection is slow, as an intrusion can remain unnoticed for several weeks before encryption. For a legal retention obligation: the period set by the law of your country (accounting, tax, health), to be checked with your accountant or the competent authority, applied only to the documents concerned, not to the full server image every night. Example: in France, ten years for accounting documents (Article L123-22 of the French Commercial Code). The details are in Immutable backup: how long should data be retained?.

At WeDoBack

The IMMUTABLE offer is based on WORM storage. For the chosen period, up to ten years, data can be neither modified nor deleted, even if access to the console were stolen. Every action, including an attempted deletion by an administrator, is logged in a history that cannot be erased. The public price is €20 excl. VAT per 100 GB block per month, plus one agent per machine. The offer can be taken on its own or in addition to a SMART or INTEGRAL backup. When the period ends, simply subscribe again to start a new protection period. The encryption key stays with the client: immutability guarantees that the copy is not altered, but it does not remove the need to keep the key in order to read it.

Frequently asked questions

Can ransomware encrypt an immutable backup?

No, as long as the lock period is running: the storage refuses any overwrite. However, if the ransomware encrypted production before the last backup, that copy contains files that are already encrypted. Hence the value of keeping several versions and being able to go back to a date before the attack.

Can an administrator shorten the immutability period?

In a true WORM “compliance” mode, no: neither the administrator nor the provider can lift the lock before it expires. Some products offer a “governance” mode in which a privileged account can lift it; this mode protects against mistakes, not against an attacker who has stolen that account.

Should all your backups be made immutable?

Rarely. Immutability is reserved for data whose loss would be critical or that must be kept unaltered. The rest of the IT estate can stay on conventional backup with history, which costs less and remains more flexible.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.