Veeam · Immutable Backup

Immutable Backup for Veeam: How to Make Your Backups Unerasable

Veeam is only as safe as the storage it writes to. If an attacker can reach and delete your backup repository, the backups are not protection, they are a second target. Immutability fixes that. Here is how immutable backup works with Veeam, the three ways to do it, and why we point most organisations at a purpose built appliance.

The short answer

Immutable backup for Veeam means the backup files cannot be changed or deleted for a fixed retention window, so ransomware or a rogue admin cannot destroy your last clean copy. With Veeam you can achieve it three ways: an object storage target with Object Lock, a hardened Linux repository, or a purpose built appliance like Object First Ootbi. All three deliver immutability. They differ sharply in how much you have to build, harden and maintain yourself.

Ransomware has changed what a backup has to survive. The attacker no longer just encrypts your production data, they go looking for the backups first, because destroying your ability to recover is what forces the payment. A backup repository that sits on the network with credentials an attacker can steal is exactly what they hope to find. Immutability is the answer, and Veeam supports it well. The real decision is which route to immutability fits your team.

What immutable actually means here

An immutable backup is written once and then locked for a retention period you choose. During that window it cannot be modified, encrypted or deleted by anyone, not an administrator, not a stolen account, not malware that has spread across the estate. When you need to recover, the locked copy is guaranteed to be exactly what Veeam wrote. This is the extra layer in the modern backup rule, 3-2-1-1, where the final one is a copy that is immutable or offline. Everything else can be compromised and you still walk away clean.

The three ways to make Veeam immutable

Veeam gives you genuine choice here, and we are happy to help you weigh any of them honestly.

Object storage with Object Lock

Cloud or on premises S3

Veeam can write immutable backups to S3 compatible object storage using Object Lock, in the public cloud or on your own object platform. It works, but cloud egress and retrieval costs bite at recovery time, and rolling your own on premises object store is a project in itself.

Hardened Linux repository

The build it yourself route

Veeam supports immutability on a hardened Linux server using single use credentials and the immutable flag. It has no appliance cost, but you build it, harden it, patch it and keep it configured correctly for years, and a single drift in that hardening quietly removes the protection.

A purpose built appliance

Object First Ootbi

An appliance built only for Veeam, immutable by default using S3 Object Lock on a hardened Linux base with no root access. It racks in minutes, there is nothing to harden or tune, and there is no configuration you can quietly get wrong. This is the route we recommend for most.

All three are legitimate. The honest question is not which is technically immutable, they all are, but which one stays immutable in real life, under a stretched IT team, three years after it was set up. That is where a self built repository tends to drift and an appliance does not. We compare the two directly in Ootbi versus a hardened Linux repository.

The point most people miss

Immutability is only worth anything if it is still correctly in place on the day you are attacked. A repository that was hardened perfectly at install and then never touched is the one that fails, because a patch, a permissions change or a well meaning tweak can silently break the lock. The value of an appliance is not that it is more immutable, it is that it stays immutable without depending on anyone remembering to keep it that way.

Why we point most organisations at Object First

We supply Object First because it removes the two things that go wrong with immutable Veeam repositories: the initial hardening being imperfect, and the configuration drifting over time. It is built for Veeam and nothing else, so it can be locked down in ways a general purpose box cannot, and it needs almost no ongoing care. We are independent advisers first, so if your team genuinely has the skills, time and discipline to run a hardened repository well, we will tell you so. For most, the appliance is the lower risk answer. Read the full picture on our Object First guide.

Want your Veeam backups genuinely immutable?

Tell us what your Veeam setup looks like and how much you protect, and we will give you a straight recommendation on the right route to immutability, appliance or otherwise. No obligation, and if the build it yourself route suits you better we will say so.

Prefer email? Reach us directly at hello@c4cgroup.co.uk.

Frequently asked questions

What is an immutable backup in Veeam?

It is a backup that Veeam writes to storage which then locks it for a set retention period. During that window the backup cannot be modified, encrypted or deleted by anyone, including an administrator or an attacker using stolen credentials. When you recover, the locked copy is guaranteed to match exactly what Veeam wrote.

What are the ways to make Veeam backups immutable?

There are three main routes. You can write to S3 compatible object storage with Object Lock, in the cloud or on premises. You can use a hardened Linux repository with single use credentials and the immutable flag. Or you can use a purpose built appliance such as Object First Ootbi. All three deliver immutability, and they differ mainly in how much you have to build and maintain yourself.

Is a hardened Linux repository as safe as an appliance?

It can be, on the day it is built. The difference is over time. A hardened repository depends on being patched and kept configured correctly for years, and a single change can quietly break the immutability without anyone noticing. An appliance is built to stay locked down with almost no ongoing effort, which is why it tends to be the lower risk choice for busy teams.

Does immutable backup stop ransomware completely?

No. Immutability protects the backup copy so you always have something clean to recover from. It does not stop the initial attack or the encryption of live data. It is the layer that guarantees recovery is possible, which is what removes the attacker leverage that forces a payment. It works alongside detection, good hygiene and tested recovery, not instead of them.

Do I need Veeam to use Object First?

Yes. Object First Ootbi is built for Veeam and works with Veeam only. If you are already on Veeam it is a natural fit as your immutable repository. If you are not, the immutable object storage or hardened repository routes may apply, and we are happy to talk you through the wider picture.