Immutable Backups and Air Gaps: What Each Actually Protects

Updated: 13 hours ago
“Immutable” and “air-gapped” often appear together in backup proposals. They address related risks, but they describe different controls.
Understanding the distinction helps an IT team ask better questions about a proposed design, compare vendors fairly and explain the risk position to management and auditors.
Immutability concerns whether a protected copy can be altered or deleted during its enforced retention period. Isolation concerns the paths through which another system or identity can reach that copy. A resilient design usually needs both, and a tested way to recover from them.
What each control protects against
Ransomware encrypts or deletes backups: Immutability: Retention locks prevent deletion or change of the copy. Isolation: The copy is not reachable from the compromised network.
A privileged admin account is stolen: Immutability: The lock cannot be shortened or bypassed by that account. Isolation: Separate credentials and management planes are required.
Malicious change to backup policies: Immutability: Policy and retention changes need more than one approver. Isolation: The isolated copy keeps its own policies.
Data was already corrupted before backup: Immutability: It does not help, because corrupted data is preserved as well. Isolation: It does not help on its own.
Site-wide outage or disaster: Immutability: Only if the immutable copy is off site. Isolation: A separated copy provides a recovery source.
The fourth point matters. Neither control creates a clean copy. They preserve what they were given, so recovery still depends on finding a good recovery point.
Check what is actually enforced
A retention setting alone does not explain the strength of a control. Ask which users can change it, which administrative exceptions exist and what happens if an administrator account is compromised.
Useful questions for any vendor or design:
Can a single administrator shorten retention or delete a locked copy? If so, under what conditions?
Is there a compliance mode that even the vendor's support cannot override?
Are critical actions protected by multi-person approval or multi-factor authentication?
Is the system clock protected, so retention cannot be bypassed by changing time?
How are the storage layer and the backup application's own catalogue protected?
Review the protected copy's storage, management access and retention configuration. The answer should come from the specific product implementation and security model, not from a product brochure.
Describe the air gap precisely
A physical air gap removes network connectivity, for example tape stored off site. Other designs use controlled connectivity, separate management boundaries or isolated vaulting services that connect only for short replication windows.
Ask when data can enter the isolated environment, which identities authorise access and how restores leave it. A scheduled connection introduces a transfer window that must be monitored and managed.
A second backup location is valuable, but geographic separation alone does not establish isolation. Shared credentials, management access, Active Directory trust or network paths can link environments that look separate on a diagram.
Find a clean recovery point
Attackers often stay in a network for some time before they act. Backups taken during that period may contain dormant malware or already-encrypted files.
Plan how the team will choose a recovery point after an incident: anomaly alerts on change rates, malware scanning of backup copies, and a record of which snapshots were verified. Keep enough retention to reach back past the likely dwell time.
Prove the return journey
Protecting a copy is only half the exercise. Define how it will be accessed after an incident and where it will be restored.
Confirm that approved administrators can reach the recovery controls when production systems, Active Directory or email are unavailable. Test the recovery procedure in an appropriate isolated environment, checking application behaviour and the chosen recovery point.
Measure how long it takes to bring back a critical service from the isolated copy, not only how long the data transfer takes. That time is the figure the business needs.
For GCC customers with restrictions on cloud use or data location, these controls can be assessed against approved on-premises and cloud options. The decision should follow the requirements and the available implementation.
Virtech helps organisations review backup security, design isolated copies and test recovery across NetBackup and Cohesity environments. Learn more about our NetBackup and Cohesity backup and recovery services.
Ask for a cyber recovery design review that covers both protection of the copy and restoration of the service.
Email sales@virtech.ae or call +971 4 580 7555 to speak with our specialists.
Frequently asked questions
Is an immutable backup the same as an air-gapped backup?
No. Immutability stops a copy being changed or deleted during retention. An air gap limits who and what can reach the copy. They complement each other.
Is tape still a valid air gap?
Yes, when tapes are removed from the library and stored securely. The trade-off is slower recovery, so tape usually sits alongside a faster isolated disk or cloud copy.
How often should we test recovery from the isolated copy?
At least once a year for critical services, and after significant changes to the backup platform, identity services or network design.




Comments