Backups Only Matter If Ransomware Can’t Delete Them
Ikram Massabini
July 20, 2026
Most businesses know they need backups.
The real question is whether those backups would still be there after an attack.
Ransomware attackers do not just encrypt files and hope for the best. They often look for backups first. If they can delete or damage the recovery path, the business has fewer options, more downtime, and more pressure to pay.
That is why backup strategy has moved beyond simply asking, “Are backups running?”
The better question is this: if an attacker had admin access today, could they delete your backups before anyone noticed?
What Immutable Backup Means
An immutable backup is a backup copy that cannot be changed or deleted for a set period of time.
That protection applies even if someone has administrator credentials. The lock is enforced by the backup platform, not by a normal user permission.
Some systems call this object lock, WORM storage, or write-once-read-many storage. The terminology varies, but the purpose is the same. It keeps a protected copy of your data available even if the rest of the environment is compromised.
That matters because ransomware recovery depends on clean, usable backups. If backups can be deleted by the same account that manages everything else, they may not survive the attack.
Why Regular Backups May Not Be Enough
A backup that runs every night is better than no backup at all, but it may not be enough.
A network drive in the office can still be reached by ransomware if it is connected to the same environment. An external drive that stays plugged in can be encrypted or wiped along with everything else. A cloud backup may be stronger, but only if immutability is turned on and properly configured.
This is a common gap.
Many backup platforms support immutable storage, but that does not mean the feature is active. Businesses may assume they are protected because the tool is reputable, when the most important setting has never been enabled.
Microsoft 365 retention can also create confusion. Retention policies help preserve certain data, but they are not the same as a separate, protected backup. Email, SharePoint, OneDrive, and Teams data still need a recovery plan that accounts for accidental deletion, malicious activity, and compromised admin access.
Why Backup Resilience Matters Locally
For a regional business, downtime is not abstract. If files are locked, projects stop. If schedules disappear, appointments back up. If accounting systems are unavailable, invoices, payroll, and payments can stall.
That is why backups need to be more than a nightly copy. They need to be protected, tested, and separated from the accounts an attacker would try to compromise first.
A business in Buffalo does not need a massive enterprise recovery setup to be better prepared. It does need to know that its backups cannot be wiped out in the same attack that takes down the rest of the environment.
Questions to Ask About Your Backups
Start with a few direct questions.
Are our backups immutable?
How long are protected backup copies retained?
Could a compromised domain admin or Microsoft 365 global admin account delete the backups?
Are backup credentials separate from everyday administrator accounts?
When was the last successful restore test?
Those answers should be documented. A vague “we have backups” is not enough when the business is relying on them to recover.
A Stronger Backup Strategy
A stronger backup strategy includes multiple layers.
There should be protected backup copies that cannot be altered during the retention window. Backup administration should be separated from normal business accounts. Critical systems should have clear recovery priorities. Restore testing should happen regularly enough that everyone knows the backups actually work.
The retention window matters too. If an attacker has been inside the environment for days or weeks before ransomware is triggered, yesterday’s backup may not be clean. Keeping protected restore points for a longer window gives the business more recovery options.
Testing is just as important as storage. A backup that has never been restored is still an assumption.
Recovery Needs to Be Planned Before the Attack
Backups are only useful if they survive the incident and can be restored when needed.
That means businesses need to look beyond whether backups are running and ask whether those backups are protected from the same attack that could take down the main environment.
Ransomware recovery is not about having a copy somewhere. It is about having a clean, protected, tested path back to normal operations.
The best time to confirm that path is before you need it.