Why Immutable Backups Are Critical for Ransomware Protection
Immutability is one of the biggest pieces of that strategy. Basically, once you create an immutable backup, it can’t be altered or deleted during its protection period, not even by its authorized creators.
That matters because an attacker who gets into your environment may also be able to get administrative privileges. If your backups are accessible to that same administrator account, the attacker may be able to corrupt or delete them too. An immutable copy gives you a layer of protection that an attacker can’t simply work around by taking over an admin account.
Solutions from vendors such as Veeam and Commvault have built-in ransomware detection, scanning and anomaly detection capabilities as well. So, you’re not just making a copy of your data and forgetting about it. The software can look for things that don’t make sense — unusual changes, suspicious activity or other indicators that something may be wrong.
But even an immutable backup doesn’t do you much good if you don’t know whether you can restore it.
That’s where testing comes in. A lot of businesses tell me, “We have a backup in the cloud” or, “We have another copy of everything.” Then I ask when they last tested it, and sometimes the answer is never.
Regular backup testing is essential: verify that your backups are healthy and that you can restore from them. Quarterly or at least biannual testing will offer good benchmarks. The goal isn’t just to make sure the technology works. It’s also to make sure your people know what to do when something goes wrong.
Just as you wouldn’t wait until a building is on fire to figure out where the emergency exits are, you need to practice breach scenarios in advance, so that when something actually happens, everyone knows what to do.
READ MORE: How to improve visibility throughout your ecosystem.
Build a Ransomware Recovery Strategy Around Your RTO and RPO
How frequently should you create immutable backups? It depends on how much data you can afford to lose and how long you can afford to be down.
That’s where recovery point objectives (RPO) and recovery time objectives (RTO) come into the conversation. If losing a day’s worth of data would have a major financial impact, you should create immutable copies at least daily. If your business can tolerate several days of downtime or data loss, you may have more flexibility.
The important thing is to make that decision deliberately rather than simply accepting whatever your current backup schedule happens to be.
I’d also recommend looking for a backup platform that can automate as much of this process as possible. Small businesses often have one person or a very small team responsible for the entire IT environment. You don’t want them manually checking every backup every day. Modern platforms increasingly provide scanning, alerting, anomaly detection and other security capabilities that can take some of that work off their plate.
And don’t keep your recovery plan only on the computer. If you’re hit with ransomware, that computer may be inaccessible. Keep a copy somewhere the attacker can’t reach and make sure the people responsible for recovery have practiced the process.
At the end of the day, the biggest mistake is assuming it can’t happen to you. No one thinks they’re the target — until they are.
You may not be able to prevent every ransomware attack. But with immutable backups, tested recovery procedures and a strategy built around your actual RTO and RPO, you can make sure that when something does happen, you have a way back.

