What is WORM storage?
WORM stands for write once, read many: you write once and read as many times as necessary. WORM storage refuses to overwrite or delete an object for a period set at the time of writing. It is the technical mechanism behind most immutable backups and archives that serve as evidence.
Updated October 20264 min read4 sources cited
Key points
- WORM creates a period that cannot be shortened, not data that lasts forever: when the period ends, the object can expire.
- Two modes to tell apart: governance (an administrator can lift the lock) and compliance (nobody can before expiry).
- Only compliance mode withstands the theft of administrator credentials.
- WORM replaces neither encryption nor the offline copy that the ANSSI, France’s national cybersecurity agency, recommends keeping.
- You pay for locked volume until expiry: the period must be chosen before writing.
How it behaves
When the backup is written, a lock end date is recorded. Until that date:
- reading remains possible for a restore;
- replacing the file with a “new” version is refused;
- deletion is refused, including by a storage administrator account, if the mode is a compliance lock and not merely a lock that the administrator can lift.
After that date, the object can be erased by the normal retention cycle, or kept if a new period is applied. WORM therefore does not make data last forever. It creates a period that cannot be shortened.
In its storage infrastructure security guide, NIST defines immutability as the ability to lock data after it is created to prevent its modification or deletion. It also points out that attackers have every interest in targeting not only the primary data but also its backups and copies.
Weak lock and strong lock
Vendors do not all give the word the same meaning.
- Reversible lock (often called governance): an authorised administrator can still shorten the period or delete. Useful against an operator error. Insufficient if the attacker has become that administrator.
- Compliance lock: nobody, including the account owner, can lift the lock before expiry. This is the one that withstands credential theft. It must be chosen with full knowledge of the consequences: an error in the period cannot be corrected.
| Governance mode | Compliance mode | |
|---|---|---|
| Deletion before expiry | Possible with a special permission | Impossible |
| Shortening the period | Possible with a special permission | Impossible |
| Protects against operator error | Yes | Yes |
| Protects against a compromised administrator | No | Yes |
| Main risk | The privileged account | A poorly chosen period or scope |
Ask which of the two you are being sold. The word “immutable” on a brochure is not enough. As the ANSSI stresses, the robustness of immutability varies with the technologies used.
WORM, backup and archiving
WORM is a type of storage. Backup is the process that places copies on it. You can use WORM without backing up the entire machine: for example, by placing only PDF invoices on it. You can back up without WORM: the copies exist, but an administrator can wipe them. The difference between the two uses is explained in What is the difference between backup and archiving?.
WORM comes from evidence retention. In the United States, the SEC long required broker-dealers to keep their records in a “non-rewriteable, non-erasable” format. Since 2022, it has also accepted an alternative: a system that keeps an audit trail allowing the original to be recreated if it has been modified or deleted. For anti-ransomware backup, this nuance matters: an audit trail lets you prove, WORM prevents destruction.
Encryption is independent. Encrypted WORM data whose key has been lost remains intact and unreadable. The two topics are managed together: who writes, who cannot delete, who can decrypt.
WORM or offline copy?
The ANSSI recommends keeping at least one offline backup or, failing that, an offsite one, and considers the offline copy more robust than an online WORM solution. WORM has the advantage of fast restores and no media handling. In an SME, the two are often combined: an outsourced WORM copy for everyday use, and a less frequent offline copy for the worst-case scenario.
Limitations
- The lock only protects what has already been written. Production itself can still be attacked.
- A backup that is already malicious, written after the attack began, will also be locked. Hence the value of several dates, rather than a single WORM object.
- You pay for locked volume until expiry, even if you no longer need it. That is the price of refusing deletion.
- The storage’s clock and identity must be robust. A WORM system whose clock can be turned back is not WORM.
At WeDoBack
The storage used for the IMMUTABLE offer is WORM storage: data can be neither modified nor deleted for the chosen period, up to ten years, at the public price of €20 excl. VAT per 100 GB block per month, plus one agent. It is designed for sensitive documents and to prevent tampering, including if access credentials are stolen. The exact period is chosen when you subscribe. It must be long enough to cover the scenario (ransomware or a retention obligation), because serious WORM storage cannot be shortened afterwards. Data is encrypted on the machine before being sent, and the key stays with the client.
Frequently asked questions
Is WORM the same thing as an immutable backup?
Almost. WORM is a property of the storage; an immutable backup is the result you get when backup software places its copies on WORM storage. A backup can also be made immutable through an offline copy, such as a tape removed from the drive.
Can WORM data be deleted if a mistake is made?
In compliance mode, no: neither the administrator nor the provider can delete it before expiry. This is what protects you from an attacker, and it is also why a mistake in scope or period costs you until the very end. In governance mode, a privileged account can lift the lock.
Where does the term WORM come from?
From non-rewritable optical media, and then from financial regulation. In the United States, the SEC has long required broker-dealers to keep certain records in a “non-rewriteable, non-erasable” format, and in 2022 it added an alternative based on an audit trail that allows the original to be recreated.
Sources
Documents consulted in October 2026.
- Backing up information systems – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI (French agency)
- SP 800-209, Security Guidelines for Storage Infrastructure (October 2020) — NIST
- Final Amendments to Electronic Recordkeeping Requirements (fact sheet) — U.S. Securities and Exchange Commission
- IMMUTABLE offer: WORM storage and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
