CTS - Computer Technology Specialists

Immutable Backups for Ransomware Protection

Standard backups do not protect against ransomware if the backup target is reachable from infected systems — ransomware routinely encrypts or deletes backup data before triggering visible file encryption. Immutable backups solve this by locking data in a write-once state that cannot be modified or deleted during the retention period.

Melbourne IT support with visible local credentials

CTS - Computer Technology Specialists has supported Melbourne SMBs since 2000. Contact: 1300 790 780, hello@cts.au, L30 - 35 Collins St Melbourne 3000.

Certifications, affiliations and technology partners

Microsoft Partner, ACSC Essential Eight aligned, ISO 27001 practices, NBN Business Accredited Adviser, Cisco Partner, Dell Partner, HPE Partner, Arcserve Partner, Broadcom Partner, Kyocera Partner.

How ransomware attacks backup systems

Modern ransomware groups prioritise backup destruction before triggering encryption — because a business with clean backups does not need to pay a ransom. Ransomware with domain admin credentials (obtained through credential theft or lateral movement) can access backup management consoles, delete recovery points, and corrupt backup repositories before triggering visible file encryption. This is not a rare technique — it is standard operating procedure for professional ransomware-as-a-service groups. Standard backup solutions that store data on accessible network shares or that use the same admin credentials as the production environment are vulnerable to this approach.

What immutable backups are

An immutable backup stores data in a write-once, read-many (WORM) state where data cannot be modified or deleted during the retention period — even by an administrator with full credentials to the backup management system. This is distinct from an encrypted backup (which can still be deleted) or an offline backup (which requires manual intervention). Cloud object storage with Object Lock (Azure Blob immutability, AWS S3 Object Lock) provides immutability at the storage layer — the backup target enforces the retention period independently of the backup software or the credentials used to manage it.

Retention period design for ransomware coverage

The retention period must be longer than the ransomware dwell time — the period between initial compromise and visible encryption. Professional ransomware groups typically dwell for 7-21 days before triggering encryption, using this time to harvest credentials, map the environment, and access backup systems. A 30-day retention period is the minimum for ransomware protection; 90 days provides significantly better coverage, accommodates slow-moving detection, and satisfies most cyber insurance backup requirements. CTS configures immutable backup retention at 90 days minimum for all managed IT clients.

Microsoft 365 backup — why you need it

Microsoft 365 provides high availability and platform redundancy, but does not provide point-in-time restore for individual user data beyond limited recycle bin retention (93 days for deleted items, 30 days for permanently deleted). A ransomware attack that mass-deletes or corrupts SharePoint content, Exchange emails, or OneDrive files will exhaust Microsoft's native retention windows if not discovered quickly. A third-party Microsoft 365 backup solution provides independent, long-retention, point-in-time restore for Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams — ensuring Microsoft 365 data is protected with the same rigour as on-premises or Azure-hosted data.

Recovery testing — confirming your backups work

An immutable backup that has never been tested is an untested assumption. CTS recommends quarterly restore tests for critical systems — selecting a recovery point, restoring to an isolated environment, and confirming the restored data is functional and complete. Tests should be documented with the recovery point selected, the time taken to complete the restore, any issues encountered, and the validation steps completed. This documentation is required by most cyber insurance policies for backup recoverability evidence and by the ACSC Essential Eight at Maturity Level 2 and above.

Backup architecture for Melbourne SMBs

CTS designs backup solutions for Melbourne managed IT clients using a layered approach: on-premises or Azure-hosted backup agent capturing data at the required RPO frequency, cloud backup target with object lock immutability and 90-day retention, separate backup management credentials not used anywhere in the production environment, and Microsoft 365 third-party backup running independently of the Azure infrastructure backup. The architecture is documented in the client's disaster recovery plan with the RTO and RPO targets confirmed, and the restore procedure tested at least annually.

Frequently asked questions

Is Microsoft 365 automatically backed up?

No. Microsoft provides platform redundancy and limited recycling bin retention, but not point-in-time restore for individual user data. A ransomware attack or accidental mass-deletion can exhaust Microsoft's native recovery options. CTS deploys third-party Microsoft 365 backup for all managed IT clients, providing independent long-retention backup for Exchange, SharePoint, OneDrive, and Teams.

How do I know if my current backups are immutable?

Ask your IT provider or backup software vendor whether the backup target uses object lock or WORM storage, whether backup data can be deleted by an admin before the retention period expires, and when backups were last tested with a documented restore result. If any of these questions cannot be answered clearly, the backup architecture should be reviewed.

Related case studies

Related CTS services

Share this page