Use an immutable backup to protect data integrity after a ransomware attack

Traditional backup is no longer enough against ransomware attacks

A modern ransomware attack doesn't just encrypt production data: it actively seeks out backups, encrypts or deletes them before proceeding. If the backup is accessible from the same compromised environment, even with administrative credentials, it doesn't offer real protection. Immutability solves this problem at its root: immutable data cannot be modified or deleted for the configured retention period, regardless of who attempts to do so and with what credentials.

The 3-2-1-1-0 Rule

The 3-2-1-1-0 rule is the data protection framework recommended by Veeam and adopted as an industry standard. For an MSP or IT manager, it's the minimum foundation to start from.

3-2-1-1-0 backup rule

How is immutability achieved with CloudFire?

CloudFire supports backup immutability through two distinct paths, each employing technologies and

Veeam and Object Lock on Scalable Object Storage

With Veeam Backup & Replication, immutability is achieved by configuring CloudFire's Scalable Object Storage as an S3 repository with Object Lock enabled in WORM mode. The backup is written to the bucket and locked for the defined retention period: no process, no credentials, and no malware can modify or delete it before its expiration.

Learn more about Veeam Cloud Platform →
Backup & Immutability - Veeam schema
Backup & Immutability - Acronis schema

Acronis Cyber Protect Cloud with Native Immutability

With Acronis Cyber Protect Cloud, immutability is built directly into the service: it doesn't require separate S3 repository configuration or specific additional licenses. Acronis manages immutable storage through its own protection layer, which prevents modifications or deletions of backups for the set retention period.

Learn more about Acronis Cyber Protect Cloud →

Why choose Immutability?

Ransomware protection
Immutable backups cannot be encrypted or deleted, even if ransomware reaches the backup environment or compromises administrative credentials.
Regulatory compliance
Regulations in many industries require data to be preserved intact for defined periods. Immutability meets this requirement by design, not by declaration.
Human error prevention
Immutable data cannot be accidentally deleted by an operator, a faulty script, or a misconfigured retention policy.
Verifiable integrity
With Veeam SureBackup and Acronis' automated verifications, you can test the recovery of immutable backups and document that your data is intact and recoverable.

Resources

FAQ

What does it mean for a backup to be immutable?

An immutable backup is written in Write Once Read Many (WORM) mode: once created, it cannot be modified, encrypted, or deleted for the configured retention period. This protection applies even if administrative credentials are compromised.

What is the difference between immutability with Veeam and Acronis offered by CloudFire?

With Veeam, immutability is achieved by configuring Object Lock on the S3 bucket of Scalable Object Storage CloudFire: this is a technical implementation that requires Veeam Enterprise licenses or higher and specific bucket configuration. With Acronis Cyber Protect Cloud, immutability is integrated into the service and does not require additional repository configurations.

Do Veeam Community Edition or Essentials support Object Lock?

No. Object Lock via Veeam requires Enterprise licenses or higher for the Scale-Out Repository. With lower-tier licenses, you can use Scalable Object Storage as a standard S3 repository, but without WORM immutability.

Are immutable backups accessible for recovery?

Yes. Immutability prevents modification and deletion, not reading. Backups remain fully accessible for recovery for the entire retention period.

Where are backups physically stored with CloudFire?

Veeam Cloud Platform is used in the MI1 datacenter in Milan (Data4). Acronis Cyber Protect Cloud is chosen in Acronis's Frankfurt datacenter.

How do you verify that an immutable backup is actually restorable?

Veeam uses SureBackup, which performs automatic VM boot tests from backups and verifies data integrity. Acronis Cyber Protect Cloud includes built-in automatic verification. Both generate auditable reports.

Does immutability also protect against retention configuration errors?

Partially. WORM immutability protects against data being deleted before its expiration. It does not protect against retention being configured too short: if you set 7 days and ransomware is discovered after 10, older backups might not be available. Retention planning is part of the strategy, not a detail.