Solutions

Having backups is not the same as having a recovery position.

Immutable snapshots that an attacker with credentials cannot alter, geographically separated copies in EU data centres, and in-line reduction that makes long retention affordable.

  • Immutable snapshots
  • EU data residency
  • FIDO2 MFA on Vault drives

The problem

The backup that fails is the one taken by an account the attacker owns.

Modern ransomware does not begin with encryption. It begins with credentials, then reconnaissance, then the deliberate destruction of recovery options — because an organisation that can restore does not pay.

Which means the question is not whether backups run. It is whether the backup can be altered or deleted by an account an attacker has already compromised. If it can, it is a copy, not a recovery position.

Long-term retention has a quieter problem. Retention obligations are set in years, capacity grows every year, and the cost of holding data nobody reads is rarely revisited once the system is in place.

Immutable snapshots across an incidentA timeline of six immutable snapshots. An incident occurs after the last one. Live data after the incident is compromised, but every snapshot before it remains unalterable, so recovery is a revert to the last good point rather than a search for an intact copy.live data encryptedlast goodincidentcredentials compromisedrevert, not restorenowIMMUTABLE ONCE TAKEN — CANNOT BE ALTERED OR DELETED
Modern ransomware destroys recovery options before it encrypts anything, because an organisation that can restore does not pay. A snapshot an administrator account can delete is a copy; one it cannot delete is a recovery position.

What STORViX does about it

Immutability on site, separation off site, reduction throughout.

Three mechanisms, each doing a distinct job: snapshots that cannot be rewritten, copies that are not in the same building, and reduction that makes the whole thing affordable.

  • Copy-on-write immutable snapshots

    AiRE's transactional model produces point-in-time snapshots that cannot be altered once taken. Recovery from a ransomware event is a revert to a known-good point rather than a restore from a separate system.

    • Immutable once taken
    • Instant recovery
    • Instant clones with no extra space
  • Block-level incremental replication

    Snapshots replicate at the block level, synchronising only the differences. That is what makes frequent off-site copies practical rather than aspirational.

    • Deltas only
    • Minimal bandwidth
    • On-site and off-site targets
  • Vault, in geographically separated EU facilities

    One-way replication into STORViX-operated data centres in Sweden, Italy and other EU countries, protecting against site-specific disasters. STORViX states a cost reduction of up to 50% against comparable cloud archive.

    • One-way replication — a compromised source cannot reach back
    • SHA AES 256 at rest
    • FIDO2 multi-factor authentication on physical drives
    • Zero-knowledge privacy policy and DPA
  • Recovery over the wire or by courier

    Data can be recovered from Vault over the network, or by having the physical drives shipped. When the recovery objective is measured in terabytes and hours, the second option is sometimes the faster one.

    • Network recovery
    • Shipped physical drives
    • EU facilities throughout
  • DRaaS for orchestrated recovery

    Disaster Recovery as a Service runs on Vault infrastructure and restores IT function rather than merely returning files. Recovery objectives and runbooks are agreed per engagement.

    • Runs on the Vault estate
    • Orchestrated, not raw restore
    • Scoped per engagement
  • In-line reduction, applied per data set

    Deduplication with 256-bit checksums and compression via LZ4 or GZIP9 happen during the write. Archive data sets can carry maximum compression while primary data sets do not.

    • Per-data-set control
    • GZIP9 where density matters
    • Published customer factors of 2× and 3×

Outcomes

What changes in practice

  • A recovery position, not just a copy

    Immutability means the recovery path survives an attacker who already has administrative credentials.

  • Off-site copies you can afford to take often

    Sending only block-level deltas changes replication frequency from a bandwidth negotiation into a policy decision.

  • Retention cost that scales with reduction

    Archive data sets configured for maximum density hold more per usable terabyte, which is what makes a decade of retention a manageable line item.

  • Jurisdiction you can point to

    Vault copies sit in named EU countries under a zero-knowledge policy — an answer to an auditor's question, not a shrug toward a region setting.

Design the recovery position, then the backup.

Start from what has to be recoverable, how quickly, and who must not be able to alter it. The retention design follows from that, rather than the other way round.