Cyber insurance applications now include a question that surprises many small business owners: “Do you maintain immutable, air gapped, or offline backups of your critical data?”
That question is there for a reason. Ransomware attackers have learned that the fastest way to force payment is to delete backups first, then encrypt everything else. Federal agencies and law enforcement have repeatedly documented this pattern. If your backups can be wiped using the same admin credentials an attacker just stole, you are left with no recovery option other than paying the ransom.
This guide explains what immutable backup actually means, which common setups do not qualify, what to ask your IT provider before signing the form, and how to proceed if your answer is no.
What immutable backup actually means
An immutable backup is one that cannot be changed or deleted for a defined period of time, no matter who tries.
That includes:
- You
- Your IT provider
- Anyone using stolen administrator credentials
This last point is what matters most to insurers. In a typical setup, an admin account can delete backups. Immutability removes that risk by enforcing protection at the storage level, where no user permission can override it during the retention window.
You may hear different terms depending on the platform, such as object lock or write once read many storage. The terminology varies, but the control is the same.
Three common setups that do not qualify
These scenarios come up often and are usually misunderstood.
A NAS or external drive in the office
Local storage devices are accessible from your network. If ransomware spreads, it can reach them. If an attacker gains admin access, those backups can be deleted.
They can still play a role in your strategy, but on their own they do not meet the requirement.
Treating Microsoft 365 retention as a backup
Microsoft 365 includes retention features, but they are not the same as a true backup.
A compromised global admin account can still delete data or remove retention protections. Microsoft’s shared responsibility model makes it clear that protecting your data is still your responsibility.
If this is your only layer of protection, the honest answer to the insurance question is no.
Cloud backups without immutability enabled
Many modern backup platforms support immutability, but the feature is not always turned on.
This is one of the most common gaps. A business may be paying for a solid backup solution, but the critical setting is disabled. You cannot assume it is configured correctly without verifying it.
Three questions to ask your IT provider
Before you check the box on your application, send these questions directly to whoever manages your backups.
1. Are our backups immutable, and how long is the retention window
Most insurers look for a minimum of 14 days, with 30 days becoming the new standard. This gives you recovery points from before an attacker entered your environment.
2. If our admin accounts were compromised, could they delete our backups
The correct answer should be no. If the answer is yes or unclear, your backups do not meet the requirement.
3. Can you provide proof that immutability is enabled
This could be a screenshot or vendor documentation tied to your environment. A provider who has configured this properly should be able to show it.
What a compliant setup looks like
For your answer to hold up, several elements need to be in place together.
- Immutability must be enabled, not just available
- Backup credentials must be separate from your primary admin accounts
- The retention window must be long enough to account for delayed attacks
- Restore testing must be completed and documented
Using a reputable vendor alone is not enough. The configuration and separation of access are what matter.
What to do if your answer is no
Answer the application honestly, then use the renewal as a trigger to fix the gap.
Start by asking if your current backup platform supports immutability. In many cases, it does and simply needs to be enabled.
If your provider cannot clearly answer the questions above, that is a signal this area has not been properly addressed and needs attention.
One thing to avoid is checking yes when the control is not in place. Cyber insurance applications function as warranty documents. If a claim occurs and your backups do not match what you declared, the insurer can void the policy entirely and deny coverage.
Answering no may increase your premium or limit coverage, but that cost is predictable. Misrepresentation creates a much larger risk.
FAQs
What does immutable backup mean in simple terms
It means nobody can delete or change the backup for a set period, even with admin access.
Is Microsoft 365 retention enough
No. It does not prevent a compromised admin from removing data.
How long should backups be protected
At least 14 days, with 30 days becoming more common as a baseline.
Can this be fixed without buying new tools
Often yes. Many platforms already support immutability and just need configuration changes.
What happens if I answer incorrectly
The insurer can void your policy after a claim, leaving you without coverage.
