Why Basic Backups Aren't Enough - And What Immutable Backups Actually Do
"Modern ransomware targets your backups first. What immutable backup storage is, why it matters for small businesses, and what a working backup setup actually costs."
The backup problem most small businesses don't know they have
Most small businesses think they have backups. What they actually have is a scheduled copy job that runs nightly to an external drive or a cloud folder - and hasn't been tested in 18 months.
Why that's a problem in 2026:
Modern ransomware attacks your backups first. Before encrypting your main files, ransomware typically deletes or encrypts your backup locations. If your backup tool is running as an admin process on the same network, the ransomware can reach it.
Your backups are a target, not a bystander. Sophos found backup repositories were targeted in 96% of ransomware attacks and successfully compromised in 76% of those attempts - and organisations whose backups were compromised faced recovery costs around eight times higher than those whose backups survived[1]. A backup an administrator can delete is a backup an attacker can delete.
Untested backups fail when you need them. Corrupted files, changed paths and quiet misconfiguration are discovered at the moment of crisis, not before it. The only way to know your recovery time is to have measured it.
Backup is not recovery. A backup is the file. Recovery is being able to restore that file to a working state, on a working system, within an acceptable timeframe. These are different problems.
The cost of getting it wrong is measurable, and it is not mostly the ransom. Sophos puts the mean cost of recovering from a ransomware attack at USD 1.7 million excluding any ransom paid, driven by downtime, device replacement and lost revenue[2].
Mean cost to recover from a ransomware attack, excluding any ransom paid
USD millions per incident
2024 report
2025 report
2026 report
Recovery costs fell sharply in 2025 then rose again, driven by downtime, device replacement and lost revenue rather than by ransom payments. None of these figures include the ransom itself.
Show the data
Column chart of the mean ransomware recovery cost excluding ransom: USD 2.73 million in the 2024 Sophos report, USD 1.53 million in 2025 and USD 1.7 million in 2026.
An immutable backup is a copy of your data stored in a way that cannot be modified or deleted - not by ransomware, not by an admin who makes a mistake, and not by an attacker who has gained full access to your network.
Immutable and air-gapped are not the same thing
These two words get used interchangeably by providers, and they should not be:
Immutable means the data cannot be changed or deleted for a defined retention window, even by an account with full administrative rights. The restriction is enforced by the storage layer itself (object lock / write-once-read-many). The copy is still online and reachable - it just cannot be altered.
Air-gapped means the copy is not reachable from your production environment at all: separate credentials and separate infrastructure at minimum, physically disconnected media in the strictest form. The restriction is enforced by the absence of a path, not by a policy on the storage.
You want both, and for different failure modes. Immutability defeats an attacker who has your admin credentials but is still inside the same platform. An air gap defeats an attacker who has compromised the platform or the backup console itself. A vendor claiming "immutable, air-gapped backup" for a single online repository is describing one control and charging for two.
That distinction is not academic. Veeam's ransomware research consistently finds that attackers attempt to destroy backup repositories in the large majority of incidents, and that recovery success tracks closely with whether at least one copy was beyond the attacker's reach[3].
Acronis Cyber Protect achieves this through:
Write-once storage: Once written, backup data cannot be overwritten for a defined retention period (typically 30-90 days). Offline, encrypted and immutable copies are exactly what CISA's ransomware guidance asks for[4]
Air-gapped replication: A copy exists in a physically separate cloud infrastructure that your main environment cannot directly access
Behavioral detection: Monitors for file encryption patterns and pauses suspicious processes before they can reach the backup vault
The practical result: even if ransomware fully compromises your primary environment, yesterday's clean backup is untouched and restorable.
What each kind of copy actually protects against
Capability grid comparing built-in Microsoft 365 retention, a local NAS backup and an immutable cloud vault across six protection properties. Only the immutable vault protects against an attacker holding admin credentials or ransomware reaching the local network.
Capability
Built-in retention
Local NAS backup
Immutable cloud vault
Survives accidental deletion
Protects
Protects
Protects
Survives deletion past the retention windowExchange Online holds deleted items for 14 days by default, 30 at most.
Does not protect
Protects
Protects
Survives an attacker with admin credentials
Does not protect
Does not protect
Protects
Survives ransomware reaching the local network
Depends on setup
Does not protect
Protects
Cannot be overwritten before retention expires
Does not protect
Does not protect
Protects
Restore tested on a scheduleA copy nobody has restored from is a copy nobody knows works.
Does not protect
Depends on setup
Protects
Protects
Depends on setup
Does not protect
Only the last column holds when the attacker has your administrator credentials - which, in the incidents Sophos studied, is the normal case rather than the unlucky one.
TechSuit's assessment of the three backup approaches we see most often in small businesses.
What "instant restore" actually means for a 10-person business
For a 10-person business with 2TB of data:
Full system restore from Acronis: typically 2-4 hours
Individual file recovery: minutes
"Bare metal" restore to a replacement device: 4-8 hours
Without immutable backups, a ransomware incident typically costs 3-10 days of disruption plus the recovery fee (often €5,000-€20,000 for professional data recovery, if it's even possible). With tested immutable backups, it's a bad morning - not a business-ending event.
What this costs
For a 10-person business: €100-€200/month for Acronis Cyber Protect Cloud, including:
Daily backups of all devices and Microsoft 365 data
90-day immutable retention
Quarterly restore test support
Replication to a secondary data centre
That's €1,200-€2,400/year to protect against an incident that typically costs €10,000-€50,000 when it happens.
Questions we get asked
Sources
Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.
Book a free 30-minute call. We'll review your current backup setup and tell you honestly whether it would actually protect you - and what a working setup would cost.