What Does “Immutable Backup” Mean? (And Why Your Cyber Insurance Company Cares)

You are currently viewing What Does “Immutable Backup” Mean? (And Why Your Cyber Insurance Company Cares)
Understanding what "immutable backup" means can help you answer your cyber insurance renewal with confidence

If you’re renewing your cyber insurance policy, you may come across a question that makes you stop and scratch your head:

“Do you maintain immutable backups of your critical business data?”

If your first thought is, “I’m not even sure what that means,” you’re not alone.

“Immutable backup” isn’t a term most business owners use every day. Yet it’s showing up on more and more cyber insurance applications because insurance companies know something many businesses don’t: today’s ransomware attacks often target your backups before they ever encrypt your files.

The good news? You don’t need to become an IT expert to understand what your insurance company is asking. In this article, we’ll explain immutable backups in plain English, discuss why they matter, and share a few simple questions you can ask your IT provider before checking “Yes” on your renewal form.

What Is an Immutable Backup?

Let’s start with the simplest explanation.

An immutable backup is a copy of your important business data that cannot be changed or deleted for a set period of time—even if someone gains administrator access to your network.

Think of it like putting your most important documents into a vault that automatically locks for 30 days. During that time, no one can throw those documents away—not you, not your IT provider, and not a cybercriminal who steals your administrator password.

That’s exactly why immutable backups have become so important.

Many ransomware attacks don’t begin by encrypting your files. Instead, attackers first look for your backups. If they can delete those backups, they’ve eliminated your easiest path to recovery. Only then do they launch the ransomware attack, leaving businesses with far fewer options.

An immutable backup helps prevent that by ensuring at least one copy of your data remains protected until the retention period expires.

Why Insurance Companies Are Asking About Immutable Backups

As we discussed in our recent article on how hackers target small businesses, today’s cybercriminals are constantly looking for the easiest path into a business. Once they’re inside, one of their first goals is often to locate and disable your backups before launching a ransomware attack.

A few years ago, simply having backups was enough to satisfy most cyber insurance carriers.

Today, that’s no longer the case.

Cybercriminals have become much more sophisticated. Rather than immediately encrypting a company’s files, many attackers first look for the backups. If they can delete or disable those backups, they’ve made it much harder for a business to recover without paying a ransom.

That’s why cyber insurance companies have started asking more detailed questions during the renewal process. They want to know not only if you have backups, but whether those backups would still be available if an attacker gained administrator access to your systems.

In other words, they’re trying to determine whether your backup strategy would still work on your worst day.

This emphasis on immutable, tested backups isn’t unique to insurance companies. CISA’s #StopRansomware Guide recommends maintaining secure, tested backups as one of the most effective ways to recover from a ransomware attack.

Three Common Backup Setups That May Not Qualify

Many business owners are surprised to learn that having backups doesn’t automatically mean they can answer “Yes” to the immutable backup question.

Here are three common situations that often don’t meet an insurance company’s expectations.

1. An External Hard Drive or Network Storage Device

Keeping copies of your data on an external hard drive or a network-attached storage (NAS) device is certainly better than having no backups at all.

However, if that device is connected to your network and an attacker gains administrator access, there’s a good chance they can delete those backups too.

These devices can be part of a solid backup strategy—but by themselves, they usually aren’t considered immutable.


2. Relying Only on Microsoft 365’s Built-In Retention

Many businesses assume that because their email and files are stored in Microsoft 365, everything is automatically backed up.

Unfortunately, that’s a common misconception.

Microsoft provides tools to help retain and recover data, but under its shared responsibility model, protecting your business data is ultimately your responsibility. If someone gains control of your Microsoft 365 administrator account, your native retention settings may not provide the protection your insurance company is asking about.


3. Cloud Backups with Immutability Turned Off

Here’s one that surprises people.

Many modern backup platforms include immutable backup as a feature—but that feature isn’t always enabled by default.

In other words, your business may already be paying for a backup solution that’s capable of meeting the requirement, but a critical setting was never turned on.

That’s why it’s important to verify your backup configuration rather than assume you’re covered.

Before You Check “Yes,” Ask Your IT Provider These Three Questions

If you’re not sure whether your backup system meets your insurance company’s requirements, don’t guess. Instead, send these three questions to your IT provider before you complete your renewal application.

1. Are our backups immutable? If so, how long is the immutability period?

Many insurance carriers now expect immutable backups to be retained for at least 14 days, with 30 days becoming increasingly common. The exact requirement can vary, but the important thing is knowing whether the feature is actually enabled—not just available.


2. If someone stole our administrator credentials tomorrow, could they delete our backups?

This question gets to the heart of why insurance companies ask about immutable backups in the first place.

If someone could use stolen administrator credentials to erase your backups, then those backups may not provide the level of protection your insurer expects.


3. Can you show me that immutability is enabled?

This is one of the simplest—and most important—questions you can ask.

A reputable IT provider should be able to provide documentation, a screenshot, or other confirmation showing that immutability is enabled for your backup solution. If they can’t, it’s worth digging a little deeper before checking “Yes” on your renewal form.

What If You’re Not Sure?

If your IT provider can answer all three questions clearly, that’s a great sign your backup strategy is on the right track.

If the answers are vague, or you’re told, “I think so,” don’t panic. It doesn’t necessarily mean your backups aren’t properly configured—it simply means it’s worth taking a closer look before you submit your cyber insurance renewal.

The goal isn’t to catch anyone doing something wrong. It’s to make sure you can answer your insurance company’s questions with confidence, knowing your backup strategy will protect your business if you ever need it.

What If the Honest Answer Is “No”?

If you discover that your current backup strategy doesn’t meet your cyber insurance company’s requirements, don’t panic. In many cases, the solution is simpler than you might think.

Many modern backup platforms already support immutable backups. Sometimes it’s just a matter of enabling the feature or adjusting the configuration. Other times, it may require a conversation about whether your current backup solution is still the right fit for your business.

The important thing is to answer your insurance application honestly and use the renewal process as an opportunity to ask questions. A few simple conversations today can help you avoid much bigger headaches down the road.

If you’re not sure where your business stands, start by asking your IT provider the three questions we covered above. A good provider should be able to explain your backup strategy in plain English, show you how it’s configured, and help you understand whether it meets your insurance company’s expectations.

At Cornerstone IT Professionals, we believe technology shouldn’t require a translator. Whether you’re reviewing your cyber insurance renewal or simply want a better understanding of your current backup strategy, we’re happy to answer your questions and help you make informed decisions—without the technical jargon.