
All size organizations need to face an unpleasant truth. It is not a question of “if” they will experience a ransomware attack, it is a matter of “when.” While cybersecurity software serves as a first line defense against ransomware, some attacks do unfortunately succeed. In those instances, organizations may use immutable storage solutions to protect their data and as a source to recover it.
An Ounce of Prevention
Statista, a global research firm, revealed that 304 million ransomware attacks occurred worldwide in 2020, or about 800,000 attacks daily. Posts on Quora estimate the entire world contains about 300 million companies. This approximate 1:1 ratio of companies to attacks means any internet connected organization may expect an attack at any time.
To defeat these likely attacks, the adage “an ounce of prevention is worth a pound of cure” applies. Cybersecurity software continues to represent the first and best line of defense organizations should embrace to thwart ransomware attacks. They will find it far better to stop a ransomware attack than trying to recover from one.
However, many organizations recognize cybersecurity software alone does not prevent all ransomware attacks. As a result, organizations must assume that some attacks will succeed. To prevent an attack from becoming a catastrophic occurrence, they must protect their production and backup data against this attack.
Immutable Storage Solutions
To stop ransomware from encrypting data, organizations may use immutable storage solutions. Storing copies of production and backup data on these solutions provides a viable means of securing this data from attacks.
Once stored in an immutable state, even ransomware cannot alter the data. These solutions protect data from the attack and provide a source to recover data in an unencrypted format.
New immutable storage options now exist from cloud storage and networked storage appliance providers. However, their solutions differ on critical features such as speed of data access, storage costs, and ease of management.
Cloud Storage
Using cloud storage to store backup and production data appeals to organizations now more than ever. Many cloud storage offerings include data immutability features that they deliver in one or both of the following two ways:
- Journaling or versioning. If existing data stored in the cloud gets changed or modified, the cloud does not delete this old. Rather, the cloud retains the existing version of the data. Using this method, a ransomware attack will still change the visible or production data. However, it will not destroy or encrypt previously existing data. Organizations may select a prior, existing version of unencrypted data and use that version to recover.
- Object lock. Amazon Web Services (AWS) introduced S3 Object Lock in 2018, an S3 feature other cloud providers have since released. Object Lock operates like write once, read many (WORM), a technology many organizations know well. Organizations apply and enforce retention policies on data they store on cloud storage. Once data gets written, nothing may change or delete the data until the data’s retention period expires.

These two features set cloud storage up as a logical option to protect organizational data from a ransomware attack. Organizations may obtain cloud storage from multiple general purpose and purpose-built cloud providers. Any of these options offer cloud storage’s lower costs (when compared to production storage), ease of scaling, and storing data off-premises.
The latest backup software and storage appliances further simplify cloud storage’s adoption and use. To use cloud storage, these solutions support the simple storage service (S3) API. These solutions use S3 to interface with the cloud to manage data placement and assigning retention policies to the data.
Organizations should not automatically equate a backup or storage solution’s support of cloud storage with protection from ransomware. These solutions must support turning on versioning or setting the object lock on the data placed in the cloud. If the solution supports versioning, also verify it offers an option to select past points in time for recovery.
Cloud Storage’s Hidden Costs
An argument against using cloud storage to protect against ransomware often comes from its hidden costs. If storing data with a third-party cloud storage provider, storage costs may increase dramatically. These costs will vary depending on the technology used and how well enterprises implement and manage each cloud storage option.
If using versioning and your organization has data with high change rates, the cloud will retain all those changes. This results in your cloud provider charging for the extra storage consumed by those changes.
If using Object Lock, organizations cannot change or expire the data once stored. In this case, organizations need to ensure they set data retention policies appropriately. This especially applies to backup data. Once stored, they will pay for the cloud storage until the data’s retention period expires. Once expired, they should then promptly delete data otherwise they will continue to pay to retain and store it.
Networked Storage with Secure Object Data Stores

Cloud storage has become simpler to implement and use in recent years. Unfortunately, its recurring costs and S3 APIs may still preclude many organizations from adopting it. Further, storing production and/or backup data off-premises in the cloud may lengthen recoveries to unacceptable times.
In its stead, more on-premises storage solutions intended for use as primary and secondary storage appliances offer immutable data storage options. These appliances offer a standard file system interface that supports the NFS and SMB networked file protocols. In this way, organizations may deploy and access data on these appliances like any networked storage solution.
Object Store Beneath the Covers
Beneath their file system presentation layer, these storage appliances use an immutable object store. Applications, clients, and users only see and write data to their file system. Once written, the appliances automatically store data on their underlying object store.
Using this approach, applications, clients, and users may still change or delete data presented through the appliance’s file system interface. However, the appliance’s underlying object store neither changes nor deletes prior versions of the data.
Instead, the appliance’s object store journals all changes. It chronicles new writes as well as any changes, additions, or deletions of existing data. This technique safely preserves new data as well as prior, original versions of the data.
By preserving this data, should a ransomware attack occur, organizations may roll back to a prior point in time. On these appliances, they can select a point prior to when the ransomware attack started and recover the data.
Object Store Differentiators
Storage appliances that use object stores to store data differ both in where they store data and how they manage it once stored. For instance, some appliances store and retain these changes to the data on the appliance itself.
Other appliances store and retain all changes to the data but do not keep all data on the appliance. Rather, they retain only the most recent changes (1 – 30 days) on the appliance while storing the rest with a cloud storage provider.
Where each appliance stores the data impacts the solution’s ongoing costs and data retention capabilities. If it stores data with a cloud storage provider, it can retain much more data and offer more granular recovery points. However, organizations should prepare to see increasing monthly recurring cloud storage costs and perhaps longer recovery times.
If the appliance keeps all data on-premises, organizations will avoid cloud storage costs and maintain predictable recovery times. However, the appliance will have limits on how much data it can retain. It may also not keep all data changes but only snapshots of the snapshots to preserve storage capacity on the appliance.
Immutable Storage’s Critical Role in Responding to a Ransomware Attack
Every organization should use available cybersecurity software as its first line defense against ransomware attacks. Detecting ransomware and stopping an attack still better serves organizations than recovering from an attack. However, cybersecurity software does not provide a foolproof defense against ransomware attacks.
This data protection gap dictates organizations have a recovery plan in place. Placing data on an immutable storage solution plays a critical role in recovering from a ransomware attack.
Immutable object stores preserve all data in an unaltered state providing organizations with multiple, viable recovery points. These may go back days, weeks, months, and even years. These immutability features used in conjunction with cybersecurity software help ensure organizations have the appropriate level of defenses in place against a ransomware attack.
