Cyber Insurance

What "Immutable Backup" Means on Your Cyber Insurance Form

There is a question on most cyber insurance renewal applications that catches business owners off guard: “Do you maintain immutable, air-gapped, or offline backups that cannot be deleted using domain administer credentials?” This article explains what that question is actually asking, which common setups don’t qualify, and what to verify before you sign.

immutable backups

%

of ransomware attacks now target backup systems first

$1.85M

average ransomware recovery cost without clean backups

%

of SMB cyber policies now require immutable backups

Why Carriers are Asking this Question Now

Ransomware payments grew significantly between 2020 and 2024 because attackers consistently found and deleted backup copies before triggering the encryption. Carriers that paid out those claims updated their underwriting requirements. Immutable backup is now a standard line item on most SMB cyber policies, and misrepresenting your backup configuration on the application is grounds for a denied claim.

cyber insurance

Immutable Backup, in Plain English

A backup is immutable when the backup platform itself enforces a lock at the storage layer and no credentials, however privileged, can override it during a retention window. It is not enough for a backup to be difficult to delete. The platform must make deletion technically impossible for a set period.

Some platforms call this object lock, write-once-read-many, or WORM storage. The terminology varies, but the control is the same: once a backup is written, no user action can alter or delete it until the retention window expires.

“A backup that can be deleted with stolen admin credentials does not qualify, regardless of where it is stored.”

How a Ransomware Operator Actually Uses Your Backups Against You

Understanding the attack sequence shows why the insurance question matters.

Credentials Stolen

Phishing or dark web purchase

U

Backups Located

Mapped via admin access

Backups Deleted

Before encryption begins

~

Production Encrypted

No clean copy to restore

Three Common Backup Setups That Don't Qualify

These are the setups most commonly misunderstood when filling out the insurance form.

OneDrive/Google Drive/ Dropbox

What It Does: Syncs files to cloud in real time.

Qualifies? No.

Why Not: Ransomware encryption syncs within minutes. Nothing is locked.

NAS/Network-attached Drive

What It Does: Stores backups on a local network device

Qualifies? No.

Why Not: Accessible via domain credentials. Attackers map and wipe it first.

Microsoft 365 Retention Policies

What It Does: Protects against end-user deletion

Qualifies? No.

Why Not: A Global Admin account can override them. Not storage-layer immutability.

Object Lock + WORM Storage

What It Does: Enforces deletion lock at the storage layer

Qualifies? Yes!

Why: No credentials can override the lock during the retention window.

One of the most common gaps we find is a cloud backup with immutability switched off. Many reputable backup platforms (Veeam, Datto, Acronis) include immutability as a feature. The setting is not always enabled by default. The capability exists. Someone needs to turn it on. Your business may be paying for a backup solution that looks credible on paper while the immutability toggle sits in the off position.

What a Qualifying Setup Actually Looks Like

A qualifying immutable backup uses a dedicated backup platform that writes copies to object storage with object lock enabled and a defined minimum retention period. The vendor’s management console cannot delete a locked object during that window, even with the highest-privilege credentials. A second copy stored offline or in a separate cloud tenant with no live network path adds additional resilience.

immutable backups

Before you sign, make sure you ask these three questions:

Question One

Does our backup platform support object lock or WORM storage and is it currently enabled on our backup sets?

Question Two

Can any account (including your MSP admin account) delete a backup before the retention window expires?

Question Three

Are our security alerts being reviewed on a regular schedule, and by whom?

What To Do if Your Honest Answer is No

Check the renewal form carefully. Some carriers offer coverage at a higher premium for businesses without immutable backups, with a requirement to remediate within a defined person. Others will exclude ransomware recovery costs entirely. Knowing where you stand before you sign is always the better position. 

If you need to remediate, this is a configuration project in most cases – not a full replacement of your current backup environment. The timeline and cost depend on what you are running today.

If questions like this are coming up on your renewal form and you are not sure where your environment stands, that is exactly what working with a managed IT provider is designed to address. Cleartech Group manages backup configuration, monitors for threats, and handles the technical detail so business owners are not left guessing on insurance paperwork.

(978) 466-1938 | cleartechgroup.com

Article adapted from The Technology Press.

Have questions about your setup?

We start every partnership the same way: a conversation about where you are, where you’re headed, and what you actually need.