Your cyber insurance renewal lands in your inbox, and buried on page four is a question that looks simple enough to check without thinking too hard: “Do you maintain immutable, air-gapped, or offline backups of your critical business data?”
You have backups. They run every night. Someone gets paid to make sure they run every night. So you check yes, sign the form, and move on with your day.
That’s the exact moment most small business owners in Michiana get into trouble, and they don’t find out until months or years later, after a ransomware claim, when a forensic investigator asks to see the immutability logs and there aren’t any.
We get it. Insurance forms are written by underwriters, not by people who explain things in plain English, and “immutable” isn’t a word that shows up in a normal conversation about backups. Here at Ma3SP, we sit down with business owners across South Bend, Goshen, Elkhart, and Mishawaka every renewal season and walk through exactly this question, because getting it wrong doesn’t just cost you a few extra dollars in premium. It can cost you the entire policy.
Carriers added this question to renewal forms because ransomware operators worked out that the fastest way to force a payout is to wipe the backups first and encrypt everything else second. CISA, the FBI, and the Internet Crime Complaint Center have all documented this as one of the most common moves in current ransomware playbooks. A business whose backup copies can be deleted using the same admin credentials an attacker just stole has no recovery path other than paying the ransom — which is exactly the leverage the attacker is counting on.
This post walks through what immutable backup actually means, three common backup setups that don’t qualify even though owners assume they do, the three questions to send your IT provider before you sign the form, what a setup that genuinely qualifies looks like, and exactly what to do if your honest answer turns out to be no.
Immutable backup, defined
An immutable backup is one that cannot be modified or deleted for a fixed period of time — including by you, by your IT provider, and by anyone using stolen admin credentials.
That last part is the piece carriers actually care about. Most backup systems can be wiped by anyone with admin access, which sounds fine right up until you remember that admin access is exactly what a ransomware attacker steals first. Immutability means the backup platform itself enforces the lock at the storage layer, and no credentials — however privileged — can override it during the retention window. Some platforms call this object lock, write-once-read-many, or WORM storage. The terminology shifts between vendors, but the underlying control is the same: once the data is written, nothing short of the clock running out can touch it.
Think of it less like a lock and more like a time capsule buried in concrete. You can bury a new one every day, but you can’t dig up yesterday’s early, no matter whose shovel you’re holding.
Three common backup setups that don’t qualify
Three setups come up constantly in the audits we run for small businesses in Elkhart County and South Bend, and none of them satisfy the immutability question, even though owners are usually confident they do.
A NAS or external drive in your office
A network-attached storage device in your server room is reachable from your network by design. That’s the whole point of it — your team needs to get to it. But if ransomware spreads across your environment, it can reach the NAS too. An attacker with domain admin credentials can wipe what’s sitting on it in minutes. An external drive someone plugs in once a week and leaves connected has the same exposure, just on a slower schedule.
These devices absolutely have a role in a broader backup strategy — they’re fast to restore from and cheap to run. On their own, though, they don’t satisfy the immutability question, and we’ve seen more than one Michiana business owner assume otherwise until a claim proved them wrong.
Microsoft 365 retention treated as a backup
Microsoft 365 includes data retention features, and a lot of businesses lean on those as their backup solution because it feels like “it’s already in there, so we’re covered.” They aren’t a backup in the sense the insurance form is asking about. An attacker with global admin access to your tenant can delete data and purge retention holds just as easily as your own IT team can.
Under Microsoft’s shared responsibility model, customers retain responsibility for backing up and protecting their own data, separate from whatever Microsoft provides at the platform level. Microsoft keeps the lights on. You’re still responsible for the fire escape. If your only protection for Microsoft 365 data is what Microsoft provides natively, the honest answer to the immutability question is no.
A cloud backup with immutability switched off
This is the gap we find most often, and it’s the sneakiest one because it looks fine from the outside. Many reputable backup platforms include immutability as a built-in feature, but it isn’t always turned on by default. The capability exists — someone just has to flip the switch. Your business may be paying full price for a backup solution that looks completely credible on the invoice while the immutability toggle sits quietly in the off position, and there’s genuinely no way to know without checking the actual configuration.
We’ve walked into audits where the backup vendor was excellent, the monthly invoice was being paid on time, and the immutability setting had simply never been enabled during the original setup. Nobody did anything wrong on purpose. It just wasn’t part of the original conversation.
Three questions to send your IT provider before you sign the form
Copy these three into an email and send them before you check the box on your renewal, whoever your provider is. If it’s us, we’ll have concrete answers back to you the same day.
Question one: “Are our backups immutable, and if so, how long is the immutability window?”
Carrier guidance has tightened over the past two years. Most insurers want a window of at least 14 days as a floor, with 30 days increasingly cited as the preferred minimum. Attackers sometimes sit inside a network for weeks before ever triggering ransomware, quietly mapping out what’s valuable, which means yesterday’s backup may already be sitting on a compromised system by the time anyone notices. The window needs to be long enough to give you clean restore points from before the attacker ever showed up in the first place.
Question two: “If our domain admin account or Microsoft 365 global admin account were stolen tomorrow, could that account be used to delete our backups?”
The correct answer is no, full stop. If the answer is yes, or your provider isn’t sure, your backups aren’t immutable in the way the form means, regardless of what the marketing material for the backup product promises.
Question three: “Can you send me a screenshot or vendor documentation showing that immutability is enabled on our account?”
A provider who can send something concrete has actually done the work and can prove it. If they come back with verbal reassurance and nothing to show for it, treat that as a no until they can demonstrate otherwise. This isn’t about distrust — it’s about the fact that an insurance claim is not the moment you want to discover the gap between what was promised and what was configured.
What a qualifying setup actually looks like
For your backup to honestly satisfy the question on the form, several things need to be true at the same time, not just one of them.
The backup platform needs immutability turned on, not just available as a feature buried in the settings menu. Several major vendors — Veeam, Datto, Rubrik, Acronis — offer it, along with most cloud storage providers that support S3-compatible object lock. A vendor name on the invoice doesn’t, by itself, answer the question your insurer is asking. The setting has to actually be on, scoped correctly, and tied to credentials that live outside the rest of your environment.
The backup credentials need to sit outside your regular administrative accounts. If the same login that manages your Microsoft 365 environment also controls your backup platform, a single compromised admin account can reach both, which defeats the entire purpose of immutability. A qualifying setup uses isolated credentials that live outside your day-to-day identity environment, so a stolen password from Tuesday’s phishing email doesn’t also hand over the keys to your recovery plan.
The retention window needs to be long enough to matter. A 24-hour backup that overwrites itself daily doesn’t help if an attacker has been quietly inside your environment for a week already. CISA’s #StopRansomware Guide lists immutable, tested backups as a baseline control, and most insurers now align their underwriting with that exact position.
Restores also need to be tested, not just theoretically possible. A backup nobody has actually tried restoring in the past 12 months isn’t something you can rely on the day it matters most. Most carriers now ask for the date of your last successful restore test on the application itself, and they genuinely want to see one, not a promise that it would probably work.
What to do if your honest answer is no
Declare what you actually have on the form, and use the renewal process as the reason to fix what isn’t there yet. This is the single most important piece of advice in this entire article, so we’ll say it plainly: honesty on the form now is dramatically cheaper than a denied claim later.
Start by asking your IT provider whether immutability can be enabled on your existing platform. In many cases it already supports the feature, and turning it on is a configuration change, not a new product purchase or a budget conversation with your accountant. If the platform supports it and nobody’s switched it on, that conversation can usually be resolved within a few days.
If your provider doesn’t know what you’re asking, or can’t give you a clear answer to the three questions above, that response is itself important information. It means this area needs attention before your next renewal date, even if every other part of your IT setup is handled perfectly well.
One thing to avoid entirely: don’t check yes on the form just to dodge a premium hike. Cyber insurance applications function as warranty documents, not as a formality. If a forensic investigation after a claim finds your backups didn’t match what you declared, the carrier can rescind the policy — coverage treated as if it never existed, and any prior payouts under the same term clawed back. Misrepresentation discovered after a claim is one of the most expensive mistakes a small business can make on an insurance form, and it’s an entirely avoidable one.
Checking no will likely cost you something at renewal, either in premium or in coverage terms. That’s a known, manageable, budgetable cost. Take the hit on the application if you need to, and use the months between now and your next renewal to close the gap for real.
Frequently Asked Questions
What does “immutable backup” mean in plain English?
A backup nobody can change or delete for a set period of time, even with administrator credentials. The storage platform enforces the lock at the system level, so user permissions can’t override it, no matter how privileged the account.
Is Microsoft 365’s built-in retention a backup?
No. Native retention can be bypassed by a global admin, or by anyone who steals one. Microsoft’s shared responsibility model places backup of your data on the customer, separate from retention, which is a distinction that catches a lot of business owners off guard.
How long should the immutability window be?
Most insurers and security frameworks point to a minimum of 14 days. 30 is increasingly the preferred floor, and some carriers want longer. A longer window gives you more confident recovery if an attacker’s been inside your environment for a while before triggering the attack.
Can my IT provider just turn immutability on?
Often, yes. If your backup platform supports the feature and it hasn’t been enabled, this is a configuration change rather than a new purchase. Ask for written confirmation once it’s done, so you have something concrete for the next renewal.
What happens if I check yes on the form when I shouldn’t?
The carrier can rescind the policy after a claim, voiding coverage retroactively. Any prior payouts under the same policy term can also be clawed back. Misrepresentation is one of the most common reasons cyber claims get denied, and it’s almost always avoidable with an honest answer up front.
Graham’s Take
This is the same gap we see on the insurance side across the board — most owners genuinely believe they’re covered because “we have backups.” The insurance form is asking a much narrower, much more specific question than that, and it’s worth ten minutes with your IT provider to get a real answer before you sign anything. If you’re a small business anywhere in Michiana and you’re not sure which category your backup falls into, that’s exactly the kind of thing we check for free during a checkup — no pressure, no sales pitch, just an honest read on where you stand before your renewal date arrives.
