Your cyber insurance renewal form includes one question that trips up a lot of small business owners:

“Do you maintain immutable, air-gapped, or offline backups of your critical business data?”

At first glance, it looks like a simple yes-or-no box. In practice, that one phrase — immutable backup — carries more weight than almost anything else on the application. Carriers added the question for a reason, and the reason is ransomware.

Here’s the pattern they worry about. Modern ransomware crews no longer just encrypt your files and wait. First, they hunt down your backups and destroy them. Then they encrypt everything else. CISA, the FBI, and the Internet Crime Complaint Center have all flagged this move as one of the most common plays in today’s ransomware playbook. The logic is cold but effective: a business that cannot restore from backup has only one way out, and that way out is paying the ransom.

So when the form asks about immutable backup, it’s really asking a sharper question. If an attacker steals your admin credentials tomorrow, can they still wipe your last clean copy? If the answer is yes, checking that box could cost you your entire claim later.

This article breaks down what immutable backup actually means, three common setups that quietly fail the test, the exact questions to send your IT provider before you sign, and what to do if your honest answer today is no.

immutable backup for cyber insurance compliance

What Immutable Backup Actually Means

An immutable backup is a copy of your data that nobody can change or delete for a fixed period of time. That “nobody” is the important part. It includes you, it includes your IT provider, and above all, it includes an attacker holding stolen admin credentials.

Most backup systems fail on that last point. If someone has admin access, they can usually delete whatever they want, backups included. Immutability closes that door. The backup platform locks the data at the storage layer, and no login, however privileged, can override the lock while the retention window is active.

You’ll see vendors describe this feature under different names. Some call it object lock, others call it write-once-read-many, and a few use the term WORM storage. The label changes from product to product, yet the underlying control stays the same: once the data is written, it’s frozen until the clock runs out.

Three Common Backup Setups That Don’t Qualify

Plenty of business owners assume they already have this covered. Often they don’t. Three setups come up again and again that feel like real protection but fail the immutability test.

A NAS or External Drive in Your Office

A network-attached storage device in your server room connects to your network by design. That’s the whole point of it. Unfortunately, it also means ransomware can reach it. If malware spreads across your environment, or an attacker logs in with domain admin credentials, that NAS becomes fair game. An external drive that someone plugs in weekly and then leaves connected carries the same risk.

AMA Networks Managed Backup and Disaster Recovery Services

These devices still have a place in a well-rounded backup strategy. On their own, though, they don’t answer the immutability question on the form.

Microsoft 365 Retention Treated as a Backup

Microsoft 365 includes retention features, and many businesses lean on them as their backup plan. That’s a mistake, at least as far as the insurance form is concerned. A global admin, or anyone who steals that global admin login, can delete your data and purge the retention holds right along with it.

Microsoft is upfront about this. Under its shared responsibility model, protecting and backing up your own data stays with you, the customer, separate from the platform-level features Microsoft provides. So if native Microsoft 365 retention is your only safety net, the honest answer to the immutability question is no.

A Cloud Backup With Immutability Switched Off

This one is the most common gap of all, and also the most frustrating, because the fix is often already sitting in front of you. Many reputable backup platforms include immutability as a feature. Yet the setting frequently ships turned off, and someone has to switch it on.

The result? Your business may be paying for a backup solution that looks airtight on the invoice while the immutability toggle sits in the off position. You can’t tell from the outside. Someone has to log in and check.

Three Questions to Send Your IT Provider Before You Sign

Before you check that box, copy these three questions into an email and send them to whoever manages your backups.

1. “Are our backups immutable, and if so, how long is the immutability window?”

Carrier expectations have tightened over the past two years. Most insurers now want a window of at least 14 days, and 30 days shows up more and more as the preferred floor. The reason is simple: attackers often lurk in a network for weeks before they trigger the ransomware. A backup from yesterday may already be tainted. Your window needs to reach back far enough to give you a clean restore point from before the intruder ever showed up.

2. “If our domain admin or Microsoft 365 global admin account were stolen tomorrow, could that account delete our backups?”

You want to hear a clear no. If the answer is yes, or if your provider hesitates, then your backups are not immutable in the way the form means, no matter what the marketing says.

3. “Can you send me a screenshot or vendor documentation showing immutability is enabled on our account?”

A provider who has done the work can show you proof. If all you get back is a verbal “you’re covered” with nothing to back it up, treat that as a no until they can demonstrate otherwise.

What a Qualifying Setup Actually Looks Like

For your backup to honestly satisfy the form, several things need to be true at the same time.

First, immutability has to be turned on, not merely available. Several major vendors, including Veeam, Datto, Rubrik, and Acronis, offer the capability, and so do most cloud storage providers that support S3-compatible object lock. A recognizable vendor name on your invoice does not answer the question by itself. Someone has to enable the setting, scope it correctly, and tie it to the right credentials.

Second, your backup credentials need to live outside your everyday admin accounts. If the same login that runs your Microsoft 365 environment also controls your backup platform, then one stolen password reaches both. A qualifying setup keeps backup access isolated from your day-to-day identity environment.

Third, the retention window has to be long enough to matter. A backup that overwrites itself every 24 hours won’t save you if an attacker has been inside for a week. CISA’s #StopRansomware Guide lists immutable, tested backups as a baseline control, and most insurers now line up behind that position.

Finally, someone has to test the restores. A backup nobody has actually restored in the past year is a leap of faith, not a recovery plan. Most carriers now ask for the date of your last successful restore test, and they expect a recent one.

What to Do If Your Honest Answer Is No

If you can’t check yes truthfully, don’t panic, and don’t fake it. Report what you actually have, and treat the renewal as your reason to close the gap.

Start by asking your IT provider whether immutability can be enabled on your current platform. In a lot of cases, the platform already supports it, and switching it on is a configuration change rather than a brand-new purchase. When that’s the situation, the whole thing can often be resolved in a few days.

If your provider doesn’t understand the question, or can’t give a straight answer to the three questions above, that response tells you something important on its own. This area needs attention before your next renewal, even if the rest of your IT setup runs smoothly.

One thing you should never do: check yes to dodge a premium increase. Cyber insurance applications work as warranty documents. If a forensic investigation after a claim finds that your backups didn’t match what you declared, the carrier can rescind the policy outright. At that point your coverage gets treated as if it never existed, and any earlier payouts under the same policy term can be clawed back. Misrepresentation discovered after a claim ranks among the most expensive mistakes a small business can make on an insurance form.

Checking no will probably cost you something at renewal, whether in premium or in coverage terms. That’s a known, manageable cost. Take the hit on the application, then use the months before your next renewal to fix the gap for real.

How AMA Networks Can Help

Most of the businesses we work with across San Diego land in that “not sure” category, and that’s completely normal. Backups are easy to set up and easy to forget, and the immutability setting is exactly the kind of detail that slips through the cracks.

Our team can review your current backups, confirm whether immutability is actually enabled, isolate your backup credentials from your main environment, and run a restore test so you know your recovery plan works before you ever need it. When your renewal form asks the question, you’ll be able to check the box honestly, with documentation to back it up.

If you’re staring at that question right now and you’re not sure how to answer it, let’s talk. Reach out to AMA Networks, and we’ll help you get a clear, honest answer before you sign.

Frequently Asked Questions

What does immutable backup mean in plain English?

It’s a backup that nobody can change or delete for a set period of time, even with administrator credentials. The storage platform enforces the lock at the system level, so user permissions can’t override it.

Is Microsoft 365’s built-in retention a backup?

No. A global admin, or anyone who steals that account, can bypass native retention. Under Microsoft’s shared responsibility model, backing up your own data stays with you, separate from the retention features Microsoft provides.

How long should the immutability window be?

Most insurers and security frameworks point to a minimum of 14 days, and 30 days is increasingly the preferred floor. Some carriers want longer. A longer window gives you more confident recovery if an attacker has been sitting in your environment for weeks.

Can my IT provider just turn immutability on?

Often, yes. If your backup platform already supports the feature and nobody has enabled it, this is usually a configuration change rather than a new purchase. Ask for written confirmation once it’s done.

What happens if I check yes on the form when I shouldn’t?

The carrier can rescind the policy after a claim, which voids your coverage retroactively. Any earlier payouts under the same policy term can also be clawed back. Misrepresentation is one of the most common reasons cyber insurance claims get denied.