
Immutable backups: the last line against ransomware
S3 Object Lock, air gap, and restore tests that prove resilience against encryption.
Ransomware encrypting production and backups in the same AD domain is a recurring scenario in PR consulting — NAS synced with compromised server, Veeam copies reachable from corporate network. Immutable backups break that chain: S3 Object Lock in Compliance mode, legal hold retention, and backup credentials outside attacked domain controller reach. The AWS Security Blog details Object Lock patterns; CISA recommends offline/immutable copies in anti-ransomware guides.
Modern air gap does not require vault tape — it requires separate AWS account with hardware MFA root, bucket policy deny delete except backup role, and no backup share mount on general workstations. Krebs on Security documents groups specifically hunting Veeam and shadow copies — cloud immutability is proven response.
Test restore monthly with documented scenario: "simulated ERP server deletion, full restore in sandbox, integrity validation." Backup without tested restore is wishful thinking. For PR clinics and legal with multi-year retention, Object Lock Governance vs Compliance — choose Compliance if regulatory hold applies.
Updated 3-2-1 rule: 3 copies, 2 media, 1 offline/immutable minimum. S3 Glacier Deep Archive + Object Lock cost is fraction of average ransomware ransom. Integrate alerts if backup job fails twice consecutively — monitoring silence is incident accomplice.
Bruce Schneier emphasizes defense in depth; immutable backups are final layer when MFA, EDR, and segmentation fail. Puerto Rico SMBs do not need tape robots; they need backup architecture assuming total prod breach.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


