IT Glossary · Data Protection
An immutable backup is a backup copy that cannot be altered, encrypted, or deleted by anyone — including an administrator with full credentials — for a set retention period. It uses write-once-read-many (WORM) storage logic: once written, that specific backup version is locked, so even if an attacker gains full control of your systems and your admin accounts, the backup itself remains untouchable until its retention period naturally expires.
Modern ransomware doesn't just encrypt live data — sophisticated attacks specifically hunt for and try to delete or encrypt backup copies first, because a business with a working backup can simply restore and refuse to pay a ransom. This is why "we have backups" stopped being sufficient reassurance several years ago: if those backups are reachable and modifiable by the same compromised credentials that encrypted your live data, the attacker deletes them in the same session. Immutability closes that specific gap by making the backup storage itself refuse modification requests, regardless of who — or what compromised account — sends them, for a defined lock period (commonly 30-90 days, sometimes longer for compliance-driven retention). The related concept "air-gapped" backup goes a step further architecturally — the backup infrastructure is logically or physically separated from your production network and identity systems, so a compromised domain admin account in your main environment has no credential path to the backup vault at all, immutability aside. Cloud-native backup platforms increasingly deliver both together: an air-gapped vault holding immutable backup copies, which is the combination that actually defeats a determined ransomware operator rather than just slowing them down.
Ransomware recovery is one of the most common and costly incidents Indian mid-market and enterprise IT teams deal with, and the businesses that recover fastest are consistently the ones whose backup copies survived the attack untouched — the ones that recover slowest, or not at all, are the ones whose "backup" turned out to be reachable and encryptable by the same compromised credentials. Indian regulators and cyber-insurance underwriters increasingly ask specifically about immutable/air-gapped backup as part of ransomware-resilience assessments, separate from generic "do you have backups" questions. For businesses evaluating backup vendors, this is one of the highest-value questions to ask directly: is the backup copy immutable, for how long, and is the backup infrastructure genuinely air-gapped from production identity — not just "backed up to the cloud", which alone doesn't guarantee either property.
Related terms: Immutable Backup, Air-Gapped Backup, WORM Storage, Ransomware Recovery, Backup Retention, Disaster Recovery, RTO/RPO, 3-2-1 Backup Rule
They're complementary, not the same thing. The 3-2-1 rule (3 copies, 2 different media types, 1 off-site) is about redundancy and geographic diversity. Immutability is about a specific copy being unmodifiable regardless of who tries. A backup strategy can follow 3-2-1 without any copy being immutable — the strongest ransomware-resilient setups combine both.
Not during the lock period — that is the entire point. Legitimate deletion requests (a genuine need to remove data for compliance reasons, for instance) have to wait until the retention lock naturally expires, or go through a separately authenticated, audited process outside the normal admin path, specifically so a single compromised account can't override it.
Modern cloud-native backup platforms like Druva typically build immutability into the core product rather than pricing it as a costly add-on, since it has become close to a baseline expectation for ransomware resilience rather than a premium feature. Check specifically whether your current backup vendor includes it or charges separately — older/legacy backup products are more likely to treat it as an extra.
Long enough to exceed realistic ransomware dwell time — the gap between initial compromise and the attack actually triggering, which security research commonly puts at weeks to months for sophisticated attacks. 30 days is a reasonable minimum; many Indian mid-market and BFSI deployments set 60-90 days specifically to cover slower-moving, more sophisticated attack patterns.
WhatsApp +91 98119 98370 for an INR quote with GST invoice, deployment support, and ongoing service from National IT Service.