Skip to main content
Cyber Resilience6 min read

Why Basic Backups Aren't Enough - And What Immutable Backups Actually Do

"Modern ransomware targets your backups first. What immutable backup storage is, why it matters for small businesses, and what a working backup setup actually costs."

Author

Lior Refael

Published

Apr 10, 2026

Back to Articles

The backup problem most small businesses don't know they have

Most small businesses think they have backups. What they actually have is a scheduled copy job that runs nightly to an external drive or a cloud folder - and hasn't been tested in 18 months.

Why that's a problem in 2026:

Modern ransomware attacks your backups first. Before encrypting your main files, ransomware typically deletes or encrypts your backup locations. If your backup tool is running as an admin process on the same network, the ransomware can reach it.

Your backups are a target, not a bystander. Sophos found backup repositories were targeted in 96% of ransomware attacks and successfully compromised in 76% of those attempts - and organisations whose backups were compromised faced recovery costs around eight times higher than those whose backups survived[1]. A backup an administrator can delete is a backup an attacker can delete.

Untested backups fail when you need them. Corrupted files, changed paths and quiet misconfiguration are discovered at the moment of crisis, not before it. The only way to know your recovery time is to have measured it.

Backup is not recovery. A backup is the file. Recovery is being able to restore that file to a working state, on a working system, within an acceptable timeframe. These are different problems.

The cost of getting it wrong is measurable, and it is not mostly the ransom. Sophos puts the mean cost of recovering from a ransomware attack at USD 1.7 million excluding any ransom paid, driven by downtime, device replacement and lost revenue[2].

Mean cost to recover from a ransomware attack, excluding any ransom paid

USD millions per incident

2024 report
2025 report
2026 report

Recovery costs fell sharply in 2025 then rose again, driven by downtime, device replacement and lost revenue rather than by ransom payments. None of these figures include the ransom itself.

Show the data
Column chart of the mean ransomware recovery cost excluding ransom: USD 2.73 million in the 2024 Sophos report, USD 1.53 million in 2025 and USD 1.7 million in 2026.
USD millions per incidentMean recovery cost
2024 report$2.73M
2025 report$1.53M
2026 report$1.7M

Source: Sophos, The State of Ransomware 2026 (2026)

What immutable backups actually mean

An immutable backup is a copy of your data stored in a way that cannot be modified or deleted - not by ransomware, not by an admin who makes a mistake, and not by an attacker who has gained full access to your network.

Immutable and air-gapped are not the same thing

These two words get used interchangeably by providers, and they should not be:

  • Immutable means the data cannot be changed or deleted for a defined retention window, even by an account with full administrative rights. The restriction is enforced by the storage layer itself (object lock / write-once-read-many). The copy is still online and reachable - it just cannot be altered.
  • Air-gapped means the copy is not reachable from your production environment at all: separate credentials and separate infrastructure at minimum, physically disconnected media in the strictest form. The restriction is enforced by the absence of a path, not by a policy on the storage.

You want both, and for different failure modes. Immutability defeats an attacker who has your admin credentials but is still inside the same platform. An air gap defeats an attacker who has compromised the platform or the backup console itself. A vendor claiming "immutable, air-gapped backup" for a single online repository is describing one control and charging for two.

That distinction is not academic. Veeam's ransomware research consistently finds that attackers attempt to destroy backup repositories in the large majority of incidents, and that recovery success tracks closely with whether at least one copy was beyond the attacker's reach[3].

Acronis Cyber Protect achieves this through:

  • Write-once storage: Once written, backup data cannot be overwritten for a defined retention period (typically 30-90 days). Offline, encrypted and immutable copies are exactly what CISA's ransomware guidance asks for[4]
  • Air-gapped replication: A copy exists in a physically separate cloud infrastructure that your main environment cannot directly access
  • Behavioral detection: Monitors for file encryption patterns and pauses suspicious processes before they can reach the backup vault

The practical result: even if ransomware fully compromises your primary environment, yesterday's clean backup is untouched and restorable.

What each kind of copy actually protects against

Capability grid comparing built-in Microsoft 365 retention, a local NAS backup and an immutable cloud vault across six protection properties. Only the immutable vault protects against an attacker holding admin credentials or ransomware reaching the local network.
CapabilityBuilt-in retentionLocal NAS backupImmutable cloud vault
Survives accidental deletionProtectsProtectsProtects
Survives deletion past the retention windowExchange Online holds deleted items for 14 days by default, 30 at most.Does not protectProtectsProtects
Survives an attacker with admin credentialsDoes not protectDoes not protectProtects
Survives ransomware reaching the local networkDepends on setupDoes not protectProtects
Cannot be overwritten before retention expiresDoes not protectDoes not protectProtects
Restore tested on a scheduleA copy nobody has restored from is a copy nobody knows works.Does not protectDepends on setupProtects
  • Protects
  • Depends on setup
  • Does not protect

Only the last column holds when the attacker has your administrator credentials - which, in the incidents Sophos studied, is the normal case rather than the unlucky one.

TechSuit's assessment of the three backup approaches we see most often in small businesses.

What "instant restore" actually means for a 10-person business

For a 10-person business with 2TB of data:

  • Full system restore from Acronis: typically 2-4 hours
  • Individual file recovery: minutes
  • "Bare metal" restore to a replacement device: 4-8 hours

Without immutable backups, a ransomware incident typically costs 3-10 days of disruption plus the recovery fee (often €5,000-€20,000 for professional data recovery, if it's even possible). With tested immutable backups, it's a bad morning - not a business-ending event.

What this costs

For a 10-person business: €100-€200/month for Acronis Cyber Protect Cloud, including:

  • Daily backups of all devices and Microsoft 365 data
  • 90-day immutable retention
  • Quarterly restore test support
  • Replication to a secondary data centre

That's €1,200-€2,400/year to protect against an incident that typically costs €10,000-€50,000 when it happens.

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. The State of Ransomware 2025Sophos · 2025Backup repositories targeted in 96% of attacks and compromised 76% of the time; compromised backups raise recovery costs around eightfold. (opens in a new tab)
  2. The State of Ransomware 2026Sophos · 2026Mean recovery cost of USD 1.7M excluding ransom; 56% of attacks encrypted data; backup-based recovery in 66% of encrypted cases. (opens in a new tab)
  3. #StopRansomware GuideCISA / MS-ISAC · 2023Government guidance recommending offline, encrypted, immutable backups and regular restore testing. (opens in a new tab)
  4. Recoverable Items folder in Exchange OnlineMicrosoft Learn · 2026Deleted item retention defaults to 14 days and is configurable to a maximum of 30 days. (opens in a new tab)
  5. OneDrive retention and deletionMicrosoft Learn · 202693-day recycle bin window across both stages, and the retention period for a deleted user's OneDrive. (opens in a new tab)
  6. Shared responsibility in the cloudMicrosoft Learn · 2026Which layers the provider secures and which remain the customer's, including their own data. (opens in a new tab)

Figures last checked 28 July 2026

When did you last test your backup restore?

Book a free 30-minute call. We'll review your current backup setup and tell you honestly whether it would actually protect you - and what a working setup would cost.