What is WORM storage?
WORM stands for write once, read many: write once, read as many times as needed. WORM storage refuses to overwrite or delete an object for a period set at the time of writing. It is the technical mechanism behind most immutable backups and evidential archives.
Updated October 20264 min read4 sources cited
Key points
- WORM creates an irreducible period, not everlasting data: at expiry, the object can be deleted.
- Two modes to distinguish: governance (an administrator can lift the lock) and compliance (nobody can before expiry).
- Only compliance mode withstands the theft of administrator credentials.
- WORM replaces neither encryption nor the offline copy that the ANSSI, France’s national cybersecurity agency, recommends keeping.
- Locked volume is paid for until expiry: the period is chosen before writing.
How it behaves
When the backup is written, a lock end date is recorded. Until that date:
- reading remains possible for a restore;
- replacing the file with a “new” version is refused;
- deletion is refused, even by a storage administrator account, if the mode is a compliance lock and not merely a lock the administrator can lift.
After that date, the object can be deleted by the normal retention cycle, or kept if a new period is applied. WORM therefore does not make data everlasting. It creates an irreducible period.
NIST, in its security guidelines for storage infrastructure, defines immutability as the ability to lock data after its creation to prevent its modification or deletion. It also points out that attackers have every interest in targeting not only the primary data, but also its backups and copies.
Weak lock and strong lock
Vendors do not all give the word the same meaning.
- Reversible lock (often called governance): an authorised administrator can still shorten the period or delete. Useful against an operator error. Insufficient if the attacker has become that administrator.
- Compliance lock: nobody, not even the account owner, can lift the lock before expiry. This is the one that withstands credential theft. It must be chosen knowingly: a mistake in the period cannot be corrected.
| Governance mode | Compliance mode | |
|---|---|---|
| Deletion before expiry | Possible with a special right | Impossible |
| Shortening the period | Possible with a special right | Impossible |
| Protects against operator error | Yes | Yes |
| Protects against a compromised administrator | No | Yes |
| Main risk | The privileged account | A poorly chosen period or scope |
Ask which of the two is being sold. The word “immutable” on a brochure is not enough. As the ANSSI stresses, the robustness of immutability varies with the technologies used.
WORM, backup and archiving
WORM is a type of storage. Backup is the process that places copies on it. You can use WORM without backing up the whole machine: for example, placing only PDF invoices on it. You can back up without WORM: the copies exist, but an administrator can empty them. The difference between the two uses is explained in What is the difference between backup and archiving?.
WORM comes from the preservation of evidence. In the United States, the SEC long required brokers to keep their records in a “non-rewriteable, non-erasable” format. Since 2022, it has also accepted an alternative: a system that keeps an audit trail allowing the original to be recreated if it has been modified or deleted. For anti-ransomware backup, this nuance matters: an audit trail lets you prove, WORM prevents destruction.
Encryption is independent. Encrypted WORM data whose key is lost remains intact and unreadable. The two subjects are managed together: who writes, who cannot delete, who can decrypt.
WORM or offline copy?
The ANSSI recommends keeping at least one offline backup or, failing that, an off-site one, and considers the offline copy more robust than an online WORM solution. WORM has the advantage of fast restoration and no media handling. In an SME, the two are often combined: an off-site WORM copy for everyday use, and a less frequent offline copy for the worst-case scenario.
Limits
- The lock only protects what has already been written. Production itself can still be attacked.
- A backup that is already malicious, written after the attack began, will also be locked. Hence the value of several dates, not a single WORM object.
- Locked volume is paid for until expiry, even if you no longer need it. That is the price of refusing deletion.
- The storage’s clock and identity must be robust. A WORM whose clock can be turned back is not a WORM.
At WeDoBack
The storage of the IMMUTABLE offer is WORM storage: data can be neither modified nor deleted for the chosen period, up to ten years, at the public price of €20 excl. VAT per 100 GB block per month, plus one agent. It is designed for sensitive documents and to prevent tampering, including if access credentials are stolen. The exact period is chosen at subscription. It must be long enough to cover the scenario (ransomware or retention obligation), because serious WORM cannot be shortened after the fact. Data is encrypted on the machine before it is sent, and the key stays with the client.
Frequently asked questions
Is WORM the same thing as an immutable backup?
Almost. WORM is a property of the storage; an immutable backup is the result you get when backup software places its copies on WORM storage. A backup can also be made immutable by an offline copy, such as a tape removed from the drive.
Can WORM data be deleted in case of error?
In compliance mode, no: neither the administrator nor the provider can delete before expiry. This is what protects you against an attacker, and it is also why a mistake in scope or duration has to be paid for until the end. In governance mode, a privileged account can lift the lock.
Where does the term WORM come from?
From non-rewritable optical media, then from financial regulation. In the United States, the SEC has long required brokers to keep certain records in a “non-rewriteable, non-erasable” format, and in 2022 added an alternative based on an audit trail that allows the original to be recreated.
Sources
Documents consulted in October 2026.
- Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI, France’s national cybersecurity agency
- SP 800-209, Security Guidelines for Storage Infrastructure (October 2020) — NIST
- Final Amendments to Electronic Recordkeeping Requirements (fact sheet) — U.S. Securities and Exchange Commission
- IMMUTABLE offer: WORM storage and prices — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
