Security

Immutable Backups & Your Cyber Insurance Form

server backup storage

The Backup Question That Trips Up Small Businesses

If you’re renewing your cyber insurance policy, there’s a good chance you’ve already seen this question: “Do you maintain immutable, air-gapped, or offline backups of your critical business data?”

It’s not there by accident. Ransomware operators long ago worked out that wiping backups before encrypting everything else is the fastest way to force a payout. ACSC advisories and international guidance from the FBI and CISA have all documented this as a standard move in modern ransomware playbooks. If an attacker can delete your backups using the same admin credentials they just stole, you have no recovery path other than paying the ransom.

This article covers what immutable backup actually means, three common setups that don’t qualify, the questions to send your IT provider before you sign the form, and what to do if your honest answer is no.

What Immutable Backup Actually Means

An immutable backup is one that cannot be modified or deleted for a fixed period of time — by you, by your IT provider, or by anyone using stolen admin credentials. That last part is what insurers are really asking about.

Most backup systems can be wiped by anyone with admin access. Immutability means the backup platform enforces the lock at the storage layer, and no credentials — however privileged — can override it during the retention window. Depending on the platform, you might see this called object lock, write-once-read-many (WORM), or a similar term. The terminology varies, but the underlying control is the same.

Three Common Setups That Don’t Qualify

A NAS or External Drive On-Site

A network-attached storage device in your server room is reachable from your network by design. Ransomware that spreads across your environment can reach it. An attacker with domain admin credentials can wipe it. An external drive that stays plugged in after the weekly backup has the same exposure. These devices have a role in a broader strategy — on their own, they don’t satisfy the immutability question.

Microsoft 365 Native Retention

M365 includes data retention features, and some businesses treat them as a backup solution. They aren’t — not in the sense the form is asking about. An attacker with Global Administrator access to your tenant can delete data and purge retention holds. Under Microsoft’s shared responsibility model, backup and protection of your data is the customer’s responsibility, separate from what the platform provides natively. If Microsoft 365 native retention is your only protection, the honest answer to the immutability question is no.

A Cloud Backup with Immutability Switched Off

This is the most common gap. Many reputable backup platforms include immutability as a feature, but it isn’t always enabled by default. Your business may be paying for a credible-looking backup solution while the immutability setting sits in the off position. You can’t tell from the outside without checking.

Three Questions to Send Your IT Provider Before You Sign

Question one: “Are our backups immutable, and if so, how long is the immutability window?”

Most insurers want a minimum of 14 days, with 30 days increasingly cited as the preferred floor. Attackers sometimes sit in a network for weeks before triggering ransomware — a backup from yesterday may already be compromised.

Question two: “If our domain admin or M365 Global Administrator account were stolen tomorrow, could that account be used to delete our backups?”

The correct answer is no. If the answer is yes, or your provider isn’t sure, your backups aren’t immutable in the way the form means.

Question three: “Can you send me a screenshot or vendor documentation confirming that immutability is enabled on our account?”

A provider who can send something concrete has done the work. Verbal reassurance with nothing to show should be treated as a no until demonstrated otherwise.

What a Qualifying Setup Looks Like

For your backup to honestly satisfy the question, a few things need to be true simultaneously:

  • Immutability is turned on, not just available as a feature
  • Backup credentials sit outside your regular admin accounts — if the same login that manages your M365 environment also controls your backup platform, a compromised admin account reaches both
  • The retention window is long enough — a 24-hour backup that overwrites daily won’t help if an attacker has been in your environment for a week
  • Restores are tested — most insurers now ask for the date of your last successful restore test, and the ACSC’s Essential Eight lists tested, immutable backups as a baseline control

What to Do If Your Honest Answer Is No

Declare what you have and use the renewal process as the prompt to fix what isn’t there. Ask your IT provider whether immutability can be enabled on your existing platform — in many cases it’s a configuration change, not a new product purchase.

One thing to avoid: don’t check yes on the form to avoid a premium increase. Cyber insurance applications function as warranty documents. If a forensic investigation after a claim finds your backups didn’t match what you declared, the insurer can rescind the policy — voids coverage retroactively and can claw back prior payouts. Under Australian law, misrepresentation on an insurance application carries serious consequences. Take the honest hit on the application and use the time before your next renewal to close the gap.


Not sure where your backups stand? That’s worth sorting out before your next renewal date. Get in touch with the team at IT TechNinjas and we’ll walk you through exactly what you have, what qualifies, and what needs to change.

Ready to scale safely?

Book a discovery call and we'll map out where you stand and what comes next.