Cyber Insurance
What "Immutable Backup" Means on Your Cyber Insurance Form
There is a question on most cyber insurance renewal applications that catches business owners off guard: “Do you maintain immutable, air-gapped, or offline backups that cannot be deleted using domain administer credentials?” This article explains what that question is actually asking, which common setups don’t qualify, and what to verify before you sign.
%
of ransomware attacks now target backup systems first
$1.85M
average ransomware recovery cost without clean backups
%
of SMB cyber policies now require immutable backups
Why Carriers are Asking this Question Now
Ransomware payments grew significantly between 2020 and 2024 because attackers consistently found and deleted backup copies before triggering the encryption. Carriers that paid out those claims updated their underwriting requirements. Immutable backup is now a standard line item on most SMB cyber policies, and misrepresenting your backup configuration on the application is grounds for a denied claim.
Immutable Backup, in Plain English
A backup is immutable when the backup platform itself enforces a lock at the storage layer and no credentials, however privileged, can override it during a retention window. It is not enough for a backup to be difficult to delete. The platform must make deletion technically impossible for a set period.
Some platforms call this object lock, write-once-read-many, or WORM storage. The terminology varies, but the control is the same: once a backup is written, no user action can alter or delete it until the retention window expires.
“A backup that can be deleted with stolen admin credentials does not qualify, regardless of where it is stored.”
How a Ransomware Operator Actually Uses Your Backups Against You
Understanding the attack sequence shows why the insurance question matters.
Credentials Stolen
Phishing or dark web purchase
Backups Located
Mapped via admin access
Backups Deleted
Before encryption begins
Production Encrypted
No clean copy to restore
Three Common Backup Setups That Don't Qualify
These are the setups most commonly misunderstood when filling out the insurance form.
OneDrive/Google Drive/ Dropbox
What It Does: Syncs files to cloud in real time.
Qualifies? No.
Why Not: Ransomware encryption syncs within minutes. Nothing is locked.
NAS/Network-attached Drive
What It Does: Stores backups on a local network device
Qualifies? No.
Why Not: Accessible via domain credentials. Attackers map and wipe it first.
Microsoft 365 Retention Policies
What It Does: Protects against end-user deletion
Qualifies? No.
Why Not: A Global Admin account can override them. Not storage-layer immutability.
Object Lock + WORM Storage
What It Does: Enforces deletion lock at the storage layer
Qualifies? Yes!
Why: No credentials can override the lock during the retention window.
One of the most common gaps we find is a cloud backup with immutability switched off. Many reputable backup platforms (Veeam, Datto, Acronis) include immutability as a feature. The setting is not always enabled by default. The capability exists. Someone needs to turn it on. Your business may be paying for a backup solution that looks credible on paper while the immutability toggle sits in the off position.
What a Qualifying Setup Actually Looks Like
A qualifying immutable backup uses a dedicated backup platform that writes copies to object storage with object lock enabled and a defined minimum retention period. The vendor’s management console cannot delete a locked object during that window, even with the highest-privilege credentials. A second copy stored offline or in a separate cloud tenant with no live network path adds additional resilience.
Before you sign, make sure you ask these three questions:
Question One
Does our backup platform support object lock or WORM storage and is it currently enabled on our backup sets?
Question Two
Can any account (including your MSP admin account) delete a backup before the retention window expires?
Question Three
Are our security alerts being reviewed on a regular schedule, and by whom?
What To Do if Your Honest Answer is No
Check the renewal form carefully. Some carriers offer coverage at a higher premium for businesses without immutable backups, with a requirement to remediate within a defined person. Others will exclude ransomware recovery costs entirely. Knowing where you stand before you sign is always the better position.
If you need to remediate, this is a configuration project in most cases – not a full replacement of your current backup environment. The timeline and cost depend on what you are running today.
If questions like this are coming up on your renewal form and you are not sure where your environment stands, that is exactly what working with a managed IT provider is designed to address. Cleartech Group manages backup configuration, monitors for threats, and handles the technical detail so business owners are not left guessing on insurance paperwork.
(978) 466-1938 | cleartechgroup.com