Backup · 6 min read

The Key to Ransomware Protection: Implementing Immutable Backups

An immutable backup cannot be altered or deleted, even by an admin, until its retention window expires. How it works, how to design it and how to test it.

By ZNG Solutions Engineering · Updated

Every ransomware crew knows the fastest way to force a payment is to destroy the backups first. Immutable backups take that option away: once written, the data cannot be changed or deleted by anyone, including a compromised administrator, until a fixed retention period ends.

What "immutable" means in practice

Immutability is enforced by the storage layer, not by permissions. Object storage with object lock (for example S3 Object Lock in compliance mode), hardened Linux repositories with immutability flags, and purpose-built backup appliances all refuse delete and overwrite requests for locked objects regardless of who asks. Deleting the credentials, the backup server or even the whole account does not remove the locked data before its time.

The 3-2-1-1-0 rule

  • 3 copies of your data.
  • 2 different media or platforms.
  • 1 copy off-site.
  • 1 copy immutable or air-gapped.
  • 0 errors on the last verified restore.

Designing it for a small or mid-size business

  1. Local fast tier. A backup server or NAS on-premises for quick restores of single files and virtual machines.
  2. Immutable off-site tier. Nightly copies to cloud object storage with object lock, retention of 14 to 30 days for daily points and longer for monthly ones.
  3. Separate identity. The backup platform uses its own accounts and MFA, never domain administrator credentials.
  4. Air gap where it matters. For the most critical systems, a copy that is physically or logically disconnected between backup windows.

Windows Server specifics

Image-level backups of Windows Servers let you restore an entire machine, including the operating system and applications, onto new hardware or into the cloud in hours rather than days. Combine that with application-aware processing for Exchange, SQL Server and Active Directory so restored systems are consistent, not just copied.

Test it or it does not exist

A backup that has never been restored is a hope, not a plan. Schedule quarterly restore tests: one single file, one full virtual machine, and one bare-metal or cloud recovery of a critical server. Time each one and record it. Those numbers become your real recovery time objective, and they tell you whether your retention and tiering are right.

Choosing software

Look for native support for immutable targets, automated restore verification, ransomware detection on the backup data itself, and reporting that a non-technical owner can read. Avoid any product where an administrator can shorten or remove a retention lock after the fact.

How ZNG helps

ZNG Backup & Restore delivers exactly this design for Windows Servers: near-line recovery, immutable off-site copies, air-gapping for critical systems and scheduled restore testing with a report. Pair it with ZNG Watch monitoring so a failed backup job pages an engineer the same night, not the morning after an incident.

Keep reading

More from the NOC.

Get in touch

Ready to make it happen?

Our team is made up of professionals who are passionate about their fields and constantly learning to stay ahead of the latest threats and technology. Connect with us and get the benefit of that experience.

We reply within one business day. No spam, ever.