Backups that ransomware can’t touch
Backups lock the moment they're made. No one can change them. Not hackers. Not even the owner.

Ransomware targets backups first
Picture this. It's 3 AM and ransomware just hit. The backups are encrypted too. Here's why: attackers hunt down the backups first. In fact, 94% of ransomware victims had their backups targeted during the attack (Sophos 2024). If a backup can be changed, it will be. Backups have to lock shut the second they're made.
What does a ransomware attack really cost?
Drag the sliders to match the infrastructure. The numbers add up fast.
One command. Total protection.
Back up
Run rdc repo push production --immutable. The data is saved and locked right away.
Lock
The lock happens in the storage layer itself. No changes allowed. Not by ransomware. Not by an admin with the top password.
Recover
When disaster hits, a clean backup is ready. The whole setup is back in under 5 minutes.
Why ransomware can’t encrypt these backups
Rediacc takes a read-only copy, a frozen snapshot of the files at one moment. Once that copy is sealed, the storage layer itself blocks any change. This isn't a software lock that malware can pick. Even with the top admin password, ransomware can't encrypt, change, or delete a sealed copy.
Why ransomware can’t encrypt these backups
| Traditional backup tools | Rediacc (locked in storage) |
|---|---|
| Software 'locks' that an admin password can switch off | Read-only copies guarded by the storage layer, safe even with the top admin password |
| Backups sit as normal files on disk, easy to find and encrypt | Copies live in the storage layer, hidden from regular malware |
| 'Backup completed' is the only proof on offer | We copy, boot, and health-check it daily, so it's truly verified |
| Full copy each time: 380 GB × 30 days = 11.4 TB of storage | Shortcut copies: 30 daily backups share data (~40 GB total) |
Short on time?
Skip the deep-dive. Grab the five-minute version, short enough to read at a stand-up.
Download short brief (PDF)The only backup locked in the storage layer itself
Other backup tools promise locked backups using software locks. Ransomware can pick those locks. Rediacc builds the lock into the storage layer, where ransomware can't reach.
The only backup locked in the storage layer itself
| Capability | Veeam | Rubrik | Commvault | Druva | Zerto | Rediacc |
|---|---|---|---|---|---|---|
| Locked backups | ✓ | ✓ | ✓ | ✓ | ✗ | ✓ |
| Locked in the storage layer | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Automatic daily restore test | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Shortcut copies that save space | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Instant copy for testing | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Recovery time | Minutes | Minutes | Minutes | Minutes | Seconds | <5 min |
| Runs on owned servers, no cloud needed | ✓ | ✓ | ✓ | ✗ | ✓ | ✓ |
Sources(22)
- Sophos, “The Impact of Compromised Backups on Ransomware Outcomes,” March 2024. “94% of organizations hit by ransomware in the past year said that the cybercriminals attempted to compromise their backups during the attack.”
- IBM Security, “Cost of a Data Breach Report 2024,” July 2024. “The global average cost of a data breach reached $4.88 million in 2024, as breaches grow more disruptive and further expand demands on cyber teams.”
- Coveware, “Quarterly Ransomware Report Q2 2022,” July 2022. “In Q2, the average days of downtime was measured at 24 days, a decrease of 8% from Q1 2022.”
- Veeam Hardened Repository provides Linux-based immutable backup storage using XFS with the immutable flag set at the file level.
- Rubrik Atlas filesystem stores all backup data in proprietary append-only immutable format that cannot be modified or deleted.
- Commvault supports WORM storage lock and compliance lock on disk libraries for immutable backups.
- Druva's SaaS architecture stores backups in an air-gapped, immutable cloud decoupled from the customer's environment.
- Veeam SureBackup automatically verifies backup recoverability by booting VMs in an isolated Virtual Lab environment.
- Veeam Instant VM Recovery mounts backups directly on ESXi/Hyper-V hosts for near-instant VM recovery and testing.
- Rubrik Live Mount instantly mounts backup snapshots as live VMs or file shares for testing and recovery.
- Commvault Live Recovery boots VMs directly from backup via NFS export for instant testing and recovery.
- Druva Instant Restore boots VMware VMs directly from backup cloud in under 5 minutes with live migration.
- Zerto continuous replication with journal-based recovery delivers near-zero RPO and minutes-level RTO for instant recovery.
- Veeam Instant VM Recovery enables sub-5-minute RTO by booting VMs directly from backup files.
- Rubrik Instant Recovery enables sub-5-minute recovery by mounting VMs directly from immutable snapshots.
- Commvault Live Recovery enables sub-5-minute RTO by mounting VMs from backup with background Storage vMotion.
- Druva Instant Restore minimizes downtime with sub-5-minute VM recovery directly from backup cloud storage.
- Zerto's always-on replication with sub-10-second RPOs and minute-level RTOs enables near-instant full-environment recovery.
- Veeam Backup & Replication is deployed on-premises on Windows Server with full customer control over infrastructure.
- Rubrik is deployed as on-premises appliances (r6000 series) with integrated compute, storage, and software.
- Commvault supports fully self-hosted on-premises deployments with CommServe, MediaAgent, and Access Node components.
- Zerto is deployed on-premises with a Zerto Virtual Manager and per-host Virtual Replication Appliances.
Explore Other Solutions
Stop worrying about ransomware
Protect the production servers. Start the 14-day free trial.
Start free trial 14-day free trial · Cancel anytime