Ransomware recovery is getting harder, not easier, and new research from analyst firm Omdia points to a surprisingly basic reason why: most organisations still don't have backup storage that genuinely cannot be altered or deleted. That gap undermines one of the last lines of defense companies rely on when an attack succeeds, and it's a reminder that immutable backups ransomware protection strategies only work if the immutability is real.

What Omdia's Research Actually Found

Omdia's findings, reported by SecurityBrief Asia, center on a straightforward but troubling observation: the majority of organisations lack backup storage that is truly immutable, meaning data that attackers cannot modify, encrypt, or delete once it's written. Without that protection, ransomware recovery becomes significantly harder, because attackers who compromise a network can often reach backup systems too, corrupting or wiping the very copies a company would need to restore operations.

This matters because backups have become the default recovery plan for most ransomware victims. Paying a ransom is neither guaranteed to restore data nor advisable from a security or legal standpoint, so a clean, unaltered backup is often the difference between a quick recovery and a prolonged, costly outage. Omdia's research suggests that too many organisations are operating without that safety net, even if they believe they have one.

Why 'Immutable' Backups Aren't Always Immune to Ransomware

The term "immutable" gets used loosely across the backup and storage industry, and that's part of the problem. Not every product or configuration marketed as immutable actually prevents deletion or tampering under all circumstances. Misconfigurations, expired retention policies, compromised administrative credentials, and gaps between backup and production environments can all create openings that attackers exploit, even when immutability features are technically present.

For a closer look at how these gaps happen in practice, including the specific attack vectors that let ransomware operators bypass supposedly untouchable backups, our deep dive on why immutable backups still get hit by ransomware breaks down the technical details. The short version: immutability is a control, not a guarantee, and it needs to be paired with proper configuration, access management, and isolation to function as intended.

The Gap Between Backup Claims and Real Recovery Capability

One of the more important takeaways from Omdia's research is the distance between what organisations believe about their backup posture and what actually happens during a real recovery event. Many companies assume they have immutable backups simply because a vendor's marketing says so, without validating that the configuration is enforced correctly or that recovery actually works end to end.

This is a familiar pattern in security more broadly. Encryption, VPNs, firewalls, and backup systems all provide real protection, but only when they're implemented correctly and tested regularly. A backup that can't be restored quickly, or that turns out to be reachable by an attacker with elevated credentials, offers little more than false confidence. Omdia's warning is essentially that this false confidence is widespread, and it's worsening ransomware recovery outcomes across the board.

What This Means For You

If you manage IT infrastructure for a business, this research is a prompt to actually verify your backup immutability rather than assume it. That means checking retention lock settings, confirming that backup administrators don't have the ability to override immutability rules, and testing full recovery scenarios rather than just confirming that backups complete successfully.

For individuals and smaller organisations, the lesson scales down neatly: a password manager, a VPN, or strong encryption habits are valuable pieces of a broader security posture, but none of them replace the need for a genuinely separate, tamper-resistant backup of important data. Ransomware doesn't just target production systems; it actively hunts for backups, so any recovery plan that assumes backups will simply be there when needed is incomplete.

Actionable Takeaways

Organisations serious about immutable backups ransomware protection should start by auditing existing backup infrastructure to confirm immutability is actually enforced, not just advertised. Test recovery processes regularly under realistic conditions, including scenarios where attackers have compromised administrative accounts. Keep at least one backup copy isolated from the main network, whether through air-gapping, offline storage, or a separate cloud environment with strict access controls. Finally, review who has the authority to change retention policies or delete backup data, since that access point is often the one attackers target first.

Omdia's research is a useful checkpoint for any organisation that has treated backups as a solved problem. The technology to make backups genuinely immutable exists and works, but only when it's configured, monitored, and tested with the same rigor applied to other critical security controls.