Why ordinary backups fail against ransomware
For decades, backups were designed to survive hardware failure and human error — not a determined adversary living inside your network. Attackers who gain administrative access routinely locate backup systems, delete or encrypt the recovery points, and only then trigger the main encryption. When the victim reaches for their backups, there's nothing there.
A backup an attacker can reach is a backup an attacker can destroy. That single insight reframes the whole problem.
What 'immutable' actually means
An immutable backup cannot be altered or deleted for a defined retention period — not by an administrator, not by ransomware, not by anyone, until the clock runs out. Combined with air-gapping (keeping recovery points logically or physically separated from the production network), immutability ensures that even an attacker with full domain control cannot reach the escape route.
- Immutable: write-once, can't be modified or deleted within the retention window.
- Air-gapped: isolated from the production network the attacker controls.
- Tested: proven to restore, regularly, not assumed to work.
Immutability is necessary but not sufficient
Having clean recovery points is half the battle. The other half is restoring them fast, in the right order, and verified clean. A hospital that can technically recover but takes three weeks to do it by hand has still suffered a catastrophic outage. And restoring a system that silently carries the attacker's foothold just restarts the incident.
Recovery has to be orchestrated: bring back identity and network foundations first, then critical clinical systems like the EHR, then ancillary systems — each validated clean before it returns to service.
How Immune approaches recovery
Immune treats recovery as an automated, first-class capability, not an afterthought. It maintains immutable, air-gapped recovery points that an attacker can't reach, and its self-healing process restores affected systems in clinical priority order — validating each one clean before it comes back online. The aim is to make recovery a controlled operation measured in minutes to hours, so paying a ransom is never the fastest way back.
Sources
- CISA — #StopRansomware Guide (data backup guidance)
- U.S. HHS 405(d) — Health Industry Cybersecurity Practices
Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.
