Cybersecurity
Immutable Backups: What Your Cyber Insurance Application Is Really Asking
Cyber-insurance applications increasingly ask whether critical data is protected by immutable, offline, or air-gapped backups. This plain-English guide explains what qualifies, which common setups fall short, and what proof to request before signing the application.
Cyber-insurance applications increasingly ask a question that can catch business owners off guard: Do you maintain immutable, air-gapped, or offline backups of critical business data?
The question is not asking whether a backup job runs every night. It is asking whether an attacker who steals an administrator account can destroy every recovery copy before launching ransomware. If the same credentials can reach production systems and delete the backups, the recovery plan may fail exactly when the business needs it.
This guide explains immutable backups in plain English, identifies common setups that may not satisfy the question, and gives you specific proof to request before signing an insurance application.
What Immutable Backup Means
An immutable backup cannot be changed or deleted during a defined retention period. The storage system enforces the lock, including against administrators and attackers using stolen privileged credentials.
Vendors may describe the control as immutability, object lock, write once read many, or WORM storage. The name matters less than the result: a protected recovery copy remains available even if an attacker compromises the main network or ordinary administrative accounts.
The CISA StopRansomware Guide recommends offline, encrypted backups, regular restoration tests, and delete protection or object lock because ransomware frequently attempts to delete or encrypt accessible backups. Immutability is therefore one layer of a complete recovery program, not a substitute for testing or good access control.
Three Backup Setups That May Not Qualify
1. A NAS or external drive that stays connected. A network-attached storage device is reachable from the network by design. An external drive left connected has the same weakness. Either can be useful as one copy in a broader strategy, but neither is automatically immutable or isolated.
2. Microsoft 365 retention treated as a complete backup strategy. Microsoft 365 provides valuable retention and recovery controls, and Preservation Lock can prevent even a global administrator from weakening a locked retention policy. Those features should not be dismissed. However, retention is designed primarily for information governance, and its protection depends on licensing, scope, configuration, workload, and policy state. Microsoft also states that customers retain responsibility for their information and data. A business should verify whether its configured controls meet the insurer's exact wording and whether an independent cloud-to-cloud recovery copy is appropriate.
3. A cloud backup platform with immutability available but not enabled. A product name on an invoice does not prove the control is active. Object lock may require a specific repository, retention setting, credential boundary, or license. The configuration and evidence are what count.
The Three Questions To Ask Your IT Provider
1. Are our critical backups immutable, and what is the enforced retention period? Ask for a direct answer for each critical system, including servers, cloud workloads, Microsoft 365 data, and line-of-business applications.
2. If our domain administrator or Microsoft 365 global administrator account were stolen, could that account delete every recovery copy? The goal is a protected copy outside the normal administrative path. If the answer is yes or uncertain, the design needs review.
3. Can you show us evidence that the control is enabled and that a recent restore succeeded? Useful evidence includes configuration screenshots, storage-policy reports, access-control records, and a dated restore-test result. A green backup dashboard alone proves that a job ran; it does not prove that the business can recover.
What A Strong Recovery Design Looks Like
A credible design protects more than the backup file itself. It separates backup administration from normal day-to-day accounts, uses multi-factor authentication, limits privileges, records administrative activity, and protects at least one copy from alteration or deletion.
The backup scope must also match the business. It should include the systems and data required to operate, not merely the easiest folders to copy. That may include servers, Microsoft 365 email and collaboration data, application databases, configurations, encryption keys, and the documentation needed to rebuild services.
Retention should reflect the time an attacker may remain undetected. There is no universal number that fits every insurer or business. The correct window depends on carrier language, risk, storage capacity, recovery objectives, and how far back the company may need to reach for a clean restore point.
Finally, restores must be tested. A useful test confirms that the data opens, the application starts, dependencies are present, and the recovery finishes within the business's required timeframe. Document the date, scope, result, exceptions, and corrective actions.
Microsoft 365 Needs A Careful Answer
Microsoft 365 is not a simple yes-or-no case. Native retention, versioning, recycle bins, records management, and Preservation Lock can provide meaningful protection when properly licensed and configured. Microsoft documents that Preservation Lock can prevent anyone, including a global administrator, from turning off a policy or making it less restrictive.
That does not automatically make every tenant's native configuration a complete backup and disaster-recovery program. Coverage differs by workload, deleted-item behavior, retention scope, and the recovery scenario. An independent cloud-to-cloud backup can add a separate administrative boundary, consistent recovery workflows, and another copy of critical information.
The accurate insurance answer must describe what is actually configured in your tenant. Do not rely on a generic statement that Microsoft either backs up everything or backs up nothing.
What To Do If The Honest Answer Is No
Answer the application accurately and ask your broker or carrier what evidence and retention language they require. Insurance forms and policy terms differ. An inaccurate statement can jeopardize coverage or a later claim, so legal or coverage questions belong with your broker and counsel.
Then determine whether the existing backup platform already supports immutability. The fix may be a configuration and credential-separation project rather than a full replacement. If the current system cannot provide a protected recovery copy, build a remediation plan with an owner and deadline.
Cyber One Solutions can review the current design, document the gaps, and help build an immutable backup and disaster-recovery program around the systems the business actually depends on. We can also help prepare the supporting evidence for a cyber-insurance readiness review.
Article FAQs
What Does Immutable Backup Mean In Plain English?
It is a backup copy that cannot be changed or deleted for a set period, even by an administrator. The storage platform enforces the lock so stolen credentials cannot erase every recovery option.
Does An External Drive Count As An Immutable Backup?
Not by itself. A connected drive can often be reached, encrypted, or erased from the same environment it protects. It can still serve as one backup copy, but immutability or true offline isolation must be deliberately designed and verified.
Is Microsoft 365 Retention The Same As Backup?
Not automatically. Microsoft 365 has strong retention and recovery capabilities, including Preservation Lock, but the result depends on licensing and configuration. Retention supports governance, while backup and disaster recovery must also address independent recovery, scope, administration, and tested restoration.
How Long Should Backups Stay Immutable?
There is no universal period for every business or insurance policy. Set the window using carrier requirements, business recovery objectives, threat dwell time, and available clean restore points. Ask the insurer or broker for the exact requirement rather than assuming a number.
How Do We Prove Our Backups Work?
Perform a documented restore test. Record what was restored, when the test occurred, whether the recovered system or data worked, how long it took, and which corrective actions remain. Configuration evidence plus a successful restore is much stronger than a dashboard status alone.
Can Cyber One Solutions Review Our Current Backup Setup?
Yes. We can map critical systems, review immutability and access controls, examine restore evidence, and identify practical changes. Contact us for a complimentary initial conversation before your next insurance renewal.
