Ransomware doesn’t start with encryption anymore. It starts with a hunt for your backups. CISA and the FBI have both warned that attackers now target backup repositories first, since a business with clean backups has little reason to pay. Would yours survive it? Take the quiz and find out.
What is an immutable backup?
An immutable backup is a copy of your data that cannot be changed, encrypted, or deleted once it’s written, not by malware, not by a hacker with stolen admin credentials, and not by accident, for a set retention period. It relies on Write-Once-Read-Many (WORM) technology enforced at the storage layer itself, which is why it holds up even when an attacker already has the keys to everything else on your network.
Three numbers worth sitting with before you take the quiz.
How Well Do You Know Your Backup Environment?
Loading quiz…
The 3-2-1-1-0 rule, decoded
The classic 3-2-1 backup rule, three copies of your data on two types of media with one copy offsite, was built for hardware failures and natural disasters. It was never designed for an attacker who’s already inside your network hunting for exactly those copies. That’s why the standard evolved.
| Element | What it requires |
|---|---|
| 3 | Keep three total copies of your data: production plus two backups. |
| 2 | Store those copies on two different types of media, such as local disk and cloud storage, so a single failure point can’t wipe out everything. |
| 1 | Keep one copy offsite, away from the location of your production systems. |
| 1 | Make one copy immutable, so it can’t be altered, encrypted, or deleted even by someone holding valid admin credentials. |
| 0 | Verify zero recovery errors through regular, tested restores, not just a green checkmark on a backup job. |
What actually enforces an immutable lock
The word “immutable” gets used loosely in a lot of marketing, so it’s worth being specific about what the term is supposed to guarantee. A properly configured immutable backup is locked at the storage layer itself, using Write-Once-Read-Many (WORM) technology, not by a setting inside a dashboard that any sufficiently privileged user could switch off. During the retention window, nobody can shorten it, override it, or delete the underlying data, not your own IT team, not the backup provider’s support desk, and not an attacker holding valid domain admin credentials. That’s the entire point: the protection doesn’t depend on trusting the right person to leave it alone.
Common questions
What is an immutable backup?
+Who can delete or override an immutable backup?
+Do I need immutable backups to qualify for cyber insurance?
+How long should immutable backup retention last?
+Can ransomware still get to immutable backups?
+Is immutable backup the same thing as the 3-2-1 backup rule?
+Ready to find out where your backups actually stand?
A specialist can walk through your current backup architecture, your retention windows, and your cyber insurance requirements, then map what a resilient, immutable recovery strategy looks like for your business.



