All insights

What is an immutable backup, and does a small business need one?

2 min readBy Brendon Whiting, Founder · 1 April 2026

An immutable backup is a copy that cannot be modified or deleted for a defined retention period, by anyone, including an administrator. It exists because modern ransomware does not just encrypt your live data; it hunts down and destroys the backups first, using credentials it has already stolen. Immutability is what makes that attack fail.

The threat it answers is specific and worth understanding, because it changed what a good backup means. Attackers learnt that a business able to restore does not pay, so the reconnaissance phase now looks for backup servers, snapshots and network shares, and deletes them before anything visible happens. Every conventional protection assumes the person holding administrator credentials is authorised. Once an attacker holds those credentials, permissions, passwords and even offsite copies on the same network are all reachable. Immutability breaks that chain by removing deletion as an option at the storage layer, so authority stops being the thing that decides.

For a small business the practical version is straightforward: immutable retention on your cloud backup, set to a window that covers the time between an attack starting and anyone noticing. That gap is the number that matters, because compromises are often weeks old when discovered, and a seven-day immutable window against a three-week dwell time protects nothing. Fourteen to thirty days is a common, defensible starting point, and it costs storage rather than complexity. This is also what the 3-2-1-1-0 version of the old backup rule is pointing at with its extra one.

Does a small business need it? If your business would struggle to survive three days without its data, yes, and the reasoning is not size but consequence: ransomware operators are indiscriminate, and small businesses are targeted precisely because their backups are usually reachable. The honest caveat is that immutability protects the copy, not the business. It does nothing to stop the intrusion, and it will not shorten the recovery. It simply guarantees there is something to recover from, which is the difference between a bad fortnight and a closed company. If you want to know whether any of your copies are genuinely out of reach today, call 1800 456 567.

Put one copy out of reach

We configure immutable retention so a copy of your data survives even an attacker holding your administrator credentials.

Frequently asked questions

Not until its retention period expires, and that is the entire point: a copy you can delete under pressure is a copy an attacker can delete with your credentials. It does mean choosing the period deliberately, since you are committing to the storage. Most small businesses find a short immutable window plus longer conventional retention is the sensible balance.

They solve the same problem differently. An offline copy, genuinely disconnected, cannot be reached at all; an immutable copy is online but cannot be altered. Immutable is usually more practical because it needs no one to remember to swap anything, and the discipline of rotating offline media is exactly the discipline that lapses in a busy month.

Yes, and it is an underrated everyday benefit. The same property that defeats an attacker defeats a well-meaning administrator clearing space at the end of a long day. Immutability does not care about intent, which is precisely why it works on the failure modes nobody plans for.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.