Immutable copies: the backup gaining prominence against ransomware
Organizations are reviewing their backup systems to prevent an attacker from also being able to encrypt or delete backup copies.

News summary
The conversation about ransomware is changing. The goal is no longer solely to prevent an attacker from entering the network, but to ensure that the company can continue to operate and recover its systems even when prevention fails. In this context, immutable backups are gaining prominence.
An immutable copy is one that cannot be modified or deleted for a defined period, even if an account with elevated privileges is compromised. This feature makes it difficult for an attacker to destroy the organization’s last recovery resource, a common tactic in more sophisticated ransomware campaigns.
But immutability alone does not solve the problem. Companies are also paying more attention to credential separation, the isolation of backup repositories and periodic restoration testing. Having a copy does not mean being able to recover the business quickly. It is necessary to know the restoration order, the dependencies between applications and the maximum time the company can be without each service.
The cloud brings new possibilities for designing distributed copies, automating retention policies and maintaining replicas outside the main environment. At the same time, it requires careful configuration of permissions, encryption and storage costs to avoid surprises.
For an SME, the recommendation is clear: review which data is truly critical, define recovery objectives and test downtime scenarios before they are needed. A simple exercise can reveal that a copy is incomplete, that a password is not available or that one system depends on another that no one had considered.
As a practical reference, a company should be able to answer three questions without improvising: which is the last recoverable copy, how long would it take to restore it and where are the credentials needed to do so. If any answer is not clear, there is an immediate opportunity for improvement. Restoration tests must include complete applications, not just isolated files.
What happened
Immutable backups, which cannot be modified or deleted for a defined period, are gaining prominence against ransomware. The reason is that more sophisticated campaigns no longer aim only to encrypt systems but also to destroy backup copies to force ransom payment.
An immutable copy resists that attempt even if an attacker obtains privileged credentials. But the protection only works when combined with credential separation, isolation of backup repositories and regular restore testing; having a copy does not guarantee the business can recover quickly.
What it means for a mid-sized business
For an SME, the real risk is not just losing data but being unable to operate for days if recovery has not been rehearsed. Knowing the restore order, the dependencies between applications and the maximum tolerable downtime for each service is the difference between an hours-long disruption and a weeks-long one.
The cloud makes it easier to build distributed backups and automate retention policies, but it requires careful configuration of permissions, encryption and storage costs so protection is real rather than only theoretical.
What to review
Questions a company should be able to answer without improvising:
- What the latest recoverable copy of each critical system is and how old it is.
- How long it would actually take to restore a complete application, not just isolated files.
- Where the credentials needed to restore are kept and whether they are accessible with core systems down.
- Whether backup repositories are isolated from the network's usual administrative credentials.
Frequently Asked Questions
- What makes an immutable backup different from a normal one?
- It cannot be modified or deleted for a defined period, not even by a compromised account with elevated privileges.
- Is it enough to have immutable backups to be protected?
- No. Credentials also need to be isolated and full application restores tested regularly.
- How do you know if a backup plan is good enough?
- If the company can answer without hesitation what the latest recoverable copy is, how long it would take to restore it, and where the needed credentials are.
Concepts mentioned in this article: Cloud · Storage · Backup · Immutable backup · Retention · Ransomware
Seintec can help you design a backup and recovery strategy adapted to your systems, combining local and cloud protection when it makes sense. If you want to know how long it would take your company to recover from ransomware today, contact us and we will analyse it with you.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.