Immutable backup – the cyber insurance question most firms get wrong

Immutable backup the cyber insurance question most firms get wrong

There’s a question on most cyber insurance renewal forms that catches a lot of people out:

“Do you maintain immutable, air-gapped, or offline backups of your critical business data?”

Most managing partners tick yes. The firm has backups, the backups run every night, an IT provider looks after them. That feels like a yes.

The carrier is asking a more specific question. If an attacker had your IT admin password right now, could they delete your backups before you noticed?

A backup on the same network, under the same admin account, doesn’t pass that test. Microsoft 365’s native retention doesn’t either. And most cloud backup setups have the immutability switch sitting in the off position.

This matters more than the premium. Tick yes when the honest answer is no, and the carrier can rescind the policy after a claim. That means the cover is treated as though it never existed, and any prior payouts under the same policy term can be clawed back. The whole incident cost lands on the firm.

What “immutable” actually means

An immutable backup is one that cannot be changed or deleted for a fixed period, including by you, by your IT provider, and by anyone using stolen admin credentials. The backup platform itself enforces the lock at the storage layer. No login, however privileged, can override it during the retention window.

Vendors call this object lock, write-once-read-many, or WORM storage. The terminology shifts; the control is the same.

Three setups that don’t qualify

A NAS or external drive in the office. Reachable from your network by design. If ransomware spreads across the environment, the NAS goes with it. A weekly external drive left plugged in has the same exposure. These devices have a role in a wider strategy, but on their own they don’t satisfy the question.

Microsoft 365 native retention treated as a backup. Microsoft retains data, but a global admin can delete it and purge retention holds. Microsoft’s own shared responsibility model places backup of your tenant data on the customer, not on Microsoft. If your only protection is what Microsoft provides natively, the honest answer is no.

A cloud backup with immutability switched off. This is the most common gap we see. Several reputable platforms include immutability as a feature, but it isn’t always enabled by default. The capability is there; nobody turned it on. You can’t tell from the outside without checking.

Three questions to send your IT provider

Copy these into an email before you tick the box on the form.

  1. Are our backups immutable, and if so, how long is the immutability window?” – Most insurers now want at least 14 days, with 30 days the increasingly preferred floor. Attackers often sit in a network for weeks before triggering ransomware. Yesterday’s backup may already be compromised.
  2. If our Microsoft 365 global admin account were stolen tomorrow, could that account be used to delete our backups?” – The correct answer is no. If the answer is yes, or “I’m not sure,” your backups aren’t immutable in the way the form means.
  3. Can you send me a screenshot or vendor confirmation showing immutability is enabled on our account?” – A provider who can send something concrete has done the work. Verbal reassurance with nothing to show should be treated as a no until they can demonstrate otherwise.

What a qualifying setup looks like

The backup platform needs immutability turned on, not only available as a feature. Veeam, Datto, Rubrik and Acronis all support it, as do most cloud providers with S3-compatible object lock. A vendor name on the invoice is not, by itself, the answer.

The backup credentials need to sit outside your day-to-day administrative accounts. If the same login that manages Microsoft 365 also controls the backup platform, one compromised admin reaches both.

The retention window needs to be long enough. A 24-hour rolling backup doesn’t help if an attacker has been quietly inside the environment for a week.

Restores also need to be tested. A backup nobody has attempted to restore in the last 12 months isn’t something to rely on when it matters.

If your honest answer is no

Declare what you have on the form, and use the renewal as the reason to fix what isn’t there.

In many cases, immutability can be enabled on your existing platform with a configuration change rather than a new purchase. If your provider can’t give clear answers to the three questions above, that response is itself useful information.

Don’t tick yes to dodge a premium increase. Cyber applications act as warranty documents. Misrepresentation discovered after a claim is one of the more expensive mistakes a firm can make on an insurance form.

If you’d like us to sanity-check your backup setup before your next renewal, we’re happy to have a look.