Short answer
Immutable backups are write-once copies that cannot be altered or deleted within the retention window, so attackers cannot encrypt or erase them. FirstNet uses immutable storage for Private Cloud backups and in its Backup as a Service vault to give you a clean recovery point after ransomware.
In detail
Ransomware often goes after backups first, because traditional backups can be tampered with or encrypted by attackers. If your backups survive intact, you still have a clean point to restore from.
How FirstNet applies immutability:
- Private Cloud: Veeam backups write to immutable storage as part of the recommended baseline, with retention typically 7, 14 or 30 days
- Backup as a Service: data lands in the Veeam Data Cloud Vault encrypted and can be set as immutable for the retention period
- Vault editions: both Foundation and Advanced support immutability
- Deletion protection: recovery points cannot be changed or deleted until retention expires, which also guards against accidental or malicious deletion
Immutability works best as one layer among several. FirstNet also uses encryption in transit and at rest, isolated recovery copies, backup anomaly alerts and regular restore testing. Choose the retention and immutability period during design, because it sets how far back you can recover.
Source: FirstNet Data Protection & Ransomware Resilience service page →
Didn’t answer your question?
