Ransomware Recovery Playbook: Immutable Backups and Journal Rewind
Attackers dwell 14 days on average, and their goal is now recovery denial rather than data theft. How immutability and journals work together.
Short answer: Ransomware defeats most recovery plans because attackers delete or encrypt the backups first. Two controls change the outcome: immutable backup copies that cannot be deleted even by a compromised administrator, and a continuous journal that lets you return to seconds before encryption started. Replication alone does not help, because it copies the encryption faithfully to your recovery site.
Why standard backup fails against ransomware
Attackers do not encrypt immediately. They wait inside the environment and learn where the backups are. In Mandiant's M-Trends 2026 report, global median dwell time is 14 days, rising to 26 days when the tip-off comes from outside. The same report names the trend: ransomware operators have shifted from data theft to recovery denial. Their primary goal is now to make your recovery impossible.
The result shows up in Veeam's 2025 research: only 10% of those attacked recovered more than 90% of their data, and 57% recovered less than half.
This is why successful backup reports are not a defense. What matters is whether a backup exists that the attacker could not reach.
Control 1: immutability that survives a compromised administrator
In a Veeam hardened repository, immutability is enforced by the Linux kernel through the chattr flag, not by application logic. During the immutability window, files cannot be changed, moved or deleted by anyone, root included. The credentials used to set up the repository are not stored in the backup infrastructure, so compromising the backup server does not grant access to the store.
The critical parameter is the immutability period, and you can now base it on the figure above instead of guessing. A seven-day window is shorter than the 14-day median. The backups that would take you back to before the intrusion have already fallen out of that window; what remains are copies taken while the attacker was inside. Thirty days is a defensible floor; we covered the setup detail in how Veeam works.
Control 2: journal rewind for speed
An immutable backup brings your data back, but not quickly, because large restores take time.
A continuous data protection journal of the kind Zerto uses holds recovery points seconds apart, across a window configurable from one hour to 30 days, with a vendor recommendation of eight days to cover the ransomware scenario. That makes it possible to return to a checkpoint just before encryption started and to fail over in minutes rather than hours. For Tier 1 systems that is the difference between a bad morning and a bad quarter. The architecture is covered in how Zerto works.
Used together, the journal provides speed and the immutable backup provides the guarantee.
The response order that works
- Isolate. Before anything else, separate the affected segments. Restoring into an environment that is still compromised means reinfection.Preserve evidence. Snapshot affected systems before changing them; your insurer and your regulator will ask.Establish time zero. Determine when encryption started. Your recovery point must be earlier. This is the step that most often goes wrong under pressure, and the 14-day dwell figure explains why it is hard: encryption is the end of the breach, not the beginning.Recover Tier 1 from the journal. Pick the last clean checkpoint and fail over.Recover the rest from immutable backup.Verify before reconnecting. Confirm systems are clean and applications work.Reopen network access in stages, watching closely.
Who starts that sequence should also be written down; we calculated the cost of the authority gap in the incident escalation matrix.
What to verify before you need this
- Whether the immutability period exceeds the 14-day median.Whether the backup repository sits outside the production identity domain.Whether journal retention reaches back to a point before the attack.Who has authority to declare an incident after hours.Whether the sequence above has only been written down or also rehearsed. We explain how to rehearse it in the disaster recovery failover test guide.
Frequently asked questions
Does replication protect against ransomware? No. It copies the encrypted data to the recovery site. Replication is for availability, not integrity.
Can attackers delete immutable backups? Not within the immutability period in a correctly configured hardened repository; the protection works at the kernel level.
How far back should the journal reach? Far enough back to cover the median dwell time. Zerto supports journal retention up to 30 days depending on capacity, with a vendor recommendation of eight days.
Should we pay? That is a legal and management decision, not a technical one. A tested recovery capability takes the question off the table.
Sources
- Mandiant M-Trends 2026: dwell time and the recovery denial trendVeeam 2025 Ransomware Trends: recovery rates actually achievedHow we build this layer: security operations