What Is an Immutable Backup?

An immutable backup is a copy that can't be changed or deleted until a set date, by anyone, including the administrator who made it. For an MSP, it's the copy that survives when an attacker holds your admin passwords, because no password can shorten the lock. Attackers go after backups first, because deleting them is what turns an incident into a ransom payment. Immutability turns it back into a restore.

Two Kinds of Lock, and Only One Holds

Object lock on cloud storage comes in two modes. Governance mode lets an account with a special permission shorten or remove the lock. Compliance mode doesn't: until the lock expires, nobody can delete the object, not even the account that owns the storage. The difference matters because the account holding that bypass is exactly the account an attacker goes after. A backup under governance mode is as safe as your most privileged login. So ask every vendor two questions: which mode, and can anyone shorten a lock?

Where Copies Live

Where the copy livesWho can delete it earlyImmutable?
A NAS or server you administerAnyone holding your admin credentialsNo
A hardened backup applianceAnyone with root on the appliance, or on the host running itNo, deletion-resistant
Cloud storage under a governance-mode lockAny account granted the bypassNot against a stolen admin login
Cloud storage under a compliance-mode lockNobody, until the lock expiresYes

What Doesn't Count

A NAS or server you administer isn't immutable because it takes snapshots. If your admin account can delete them, so can whoever steals it. A hardened backup appliance isn't immutable either. It can resist ransomware on the machines it protects, but root on the appliance, or on the host running it as a virtual machine, can still destroy its local copy. Those copies still earn their place, because they're the fast ones to restore from. They just aren't the copy that survives the worst day. That one belongs on storage your own credentials can't administer.

How EnterProtect Locks Every Copy

Every cloud copy EnterProtect accepts goes under an object lock in compliance mode, never governance mode. The lock is a rolling 30 days, renewed daily for as long as the recovery point is retained, so a point you keep for seven years stays locked for all seven. A lock can be extended and never shortened: not from the console, not by your Owner account, not by EnterProtect. A missed renewal is a security incident, not a retry. A failed payment pauses new backups and never shortens a lock. And the appliance's local copy is called what it is: a fast cache, deletion-resistant, not immutable.

Immutable Backup Questions

Is an air-gapped backup the same as an immutable backup?

Not quite. An air-gapped copy is disconnected, so nothing online can reach it. An immutable copy stays reachable but can't be changed or deleted until its lock expires. Both stop an attacker deleting your backups. Immutability does it without anyone carrying a disk out of the building.

How long should immutable backups be kept?

As long as the client's retention needs to be. With EnterProtect, retention is a setting of any length, and every retained point stays under a rolling 30-day compliance lock, so long retention never needs a long contract.

Can I point EnterProtect at my own cloud storage?

No, by design. Storage you administer is storage you, or whoever compromises your accounts, can empty, and an immutability promise over it is one nobody could keep. EnterProtect keeps the locked copy on storage it controls and gives you the lock receipts.

Contact Us

Need a Copy Nobody Can Delete Early?

EnterProtect BCDR keeps every cloud copy under a compliance-mode lock that only ever extends.

See BCDR