Home›Guides›IT backup

IT backup

What is an immutable backup?

An immutable backup is a copy that nobody can modify or delete before the end of a set period: not the user, not the administrator, and not an attacker who has stolen their credentials. When the period ends, the copy can expire or be renewed; until then, it remains read-only.

Updated October 20263 min read4 sources cited

Key points

  • Immutability is enforced by the storage itself, not by a setting the administrator could untick.
  • It protects copies against deletion by ransomware or a stolen account, but replaces neither encryption, nor antivirus, nor restore tests.
  • Against ransomware, the usual target is 30 to 90 days; for a legal obligation, the period set by the law, applied only to the documents concerned.
  • The ANSSI, France’s national cybersecurity agency, recommends keeping at least one offline copy: immutability is its logical equivalent for a copy that stays online.

Why immutability exists

Standard backups remain files that the backup software is able to delete. This is useful to avoid filling up the storage. It is also exactly what ransomware does when it takes control of the console: delete the copies before encrypting production, leaving no choice but to pay. Immutability moves the decision: deletion is refused by the storage itself for N days, not by a checkbox the administrator can untick.

It also serves as proof. An accounting document or a record that must be produced unaltered cannot live on a volume where any operator can rewrite the history.

Immutable, offline, standard: three levels of protection

The ANSSI recalls the so-called “3-2-1” rule: three copies of the data, on two different media, one of which is offline. The offline copy remains the safest defence against ransomware, because no connected account can reach it. The immutable copy plays the same role for a backup that must stay online, and therefore quick to restore.

Standard backupImmutable backupOffline copy
Deletion by an administratorPossibleRefused until expiryImpossible without physical access
Resistance to a stolen accountLowHighHigh
Restoration speedHighHighSlower (media to be retrieved)
Discipline requiredLowLowRegular media rotation

What immutability is not

  • It is not encryption. Encryption prevents reading without the key. It does not prevent deletion.
  • It is not retention. Retention says “we keep 30 days”. If the administrator can shorten that period or purge, it is not immutable.
  • It is not antivirus. Production can still be encrypted. Immutability is there to recover an earlier version.
  • It is not instantaneous. The immutable copy is as old as the last successful backup. If the last clean copy dates from the previous day, you lose a day’s work.

How to implement it

The most widespread mechanism is called WORM: write once, read many. You write once, read as often as you like, and never overwrite. Cloud object storage and some NAS devices offer object locking. The lock must still not be liftable by the same account as production, and the period must exceed the time needed to discover the attack.

Three points to check before choosing a solution:

  1. Who can lift the lock? In “compliance” mode, nobody before expiry. In “governance” mode, a privileged account can: that account must then be protected like the rest of the backup infrastructure.
  2. Are actions logged? A refused deletion request is a valuable warning sign.
  3. Is the backup console isolated from production? The ANSSI recommends dedicated, named administration accounts, and backup servers that do not join the production directory.

A tape removed from the drive and stored off site is a physical form of immutability, provided someone actually carries out the rotation.

Useful period

Against ransomware: often 30 to 90 days, sometimes more if detection is slow, because an intrusion can remain unnoticed for several weeks before encryption. For a legal retention obligation: the period set by the applicable law (in Mauritius, for accounting and tax records, the Income Tax Act 1995 and the Companies Act: have it confirmed by your accountant), applied only to the documents concerned, not to the full server image every night. The details are in Immutable backup: how long should data be kept?.

At WeDoBack

The IMMUTABLE offer relies on WORM storage. For the chosen period, up to ten years, data can be neither modified nor deleted, even if console access were stolen. Every action, including an attempted deletion by an administrator, is logged and the log cannot be erased. The public price is €20 excl. VAT per 100 GB block per month, plus one agent per machine. The offer can be taken out on its own or in addition to a SMART or INTEGRAL backup. At expiry, simply subscribe again to start a new protection period. The encryption key stays with the client: immutability guarantees that the copy is not altered, but you still need to keep the key to be able to read it.

Frequently asked questions

Can ransomware encrypt an immutable backup?

No, as long as the lock period is running: the storage refuses any overwrite. However, if the ransomware encrypted production before the last backup, that copy contains files that are already encrypted. Hence the value of keeping several versions and being able to go back to a date before the attack.

Can an administrator shorten the immutability period?

In a true WORM mode known as “compliance”, no: neither the administrator nor the provider can lift the lock before it expires. Some products offer a “governance” mode in which a privileged account can lift it; this mode protects against mistakes, not against an attacker who has stolen that account.

Should all your backups be made immutable?

Rarely. Immutability is reserved for data whose loss would be critical or which must be kept unaltered. The rest of the estate can stay on standard backup with history, which costs less and remains more flexible.

Sources

Documents consulted in October 2026.

  1. Information system backup – The fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI, France’s national cybersecurity agency
  2. Guideline on Ransomware Removal — CERT-MU
  3. Income Tax Act 1995 (consolidated version) — Mauritius Revenue Authority
  4. IMMUTABLE offer: WORM storage and prices — WeDoBack

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.