A ransomware incident does not stop at encrypted office files. For a manufacturer, it can prevent access to ERP or MRP data, production schedules, quality records, CAD files and machine configuration data. That is why the question of air gapped versus immutable backups matters: both can stop attackers from destroying your recovery route, but they do so in different ways and with different operational trade-offs.
The right choice is rarely one or the other. Manufacturers with a mix of cloud services, legacy systems and connected shop-floor equipment usually need a recovery design that combines fast restoration with a protected last line of defence.
Air Gapped Versus Immutable Backups: The Core Difference
An air-gapped backup is separated from the systems it protects. In its strictest form, it is kept offline and has no network connection at all. A backup may be written to removable media, copied to a disconnected storage device or held in a secure off-site location. Because it cannot be reached over the network, ransomware cannot normally encrypt or delete it during an attack.
An immutable backup remains connected or accessible through a controlled service, but the backup data cannot be altered or deleted for a defined retention period. Once written, it is locked. An administrator, compromised user account or attacker may be able to see that it exists, but cannot change its contents before the retention period expires.
The distinction matters in a live incident. Air gapping aims to remove the backup from the attacker’s reach. Immutability accepts that the backup may be online, then prevents unauthorised changes to it.
Why Manufacturing Environments Need Both Speed and Separation
A conventional backup can fail when it is most needed. Attackers increasingly look for backup consoles, backup administrator credentials and storage repositories before triggering encryption. If they can delete recovery points or shorten retention, the business may be left deciding between a lengthy rebuild and a ransom demand.
Manufacturing adds further complications. Production networks may include older operating systems that cannot be patched in the same way as office devices. A machine supplier may require remote access for support. Shared terminals, engineering workstations and file shares often hold data that is essential to keeping work moving. Even when a production machine itself is not encrypted, a loss of scheduling, labels, drawings or ERP connectivity can halt output.
A recovery strategy must therefore answer two separate questions: can the business restore quickly enough to protect production, and can it still restore if an attacker has gained privileged access across the network?
The Strengths and Limits of Air-Gapped Backups
The principal benefit of air-gapped backups is isolation. A properly disconnected copy is extremely difficult for a remote attacker to compromise. This makes it valuable as a recovery safeguard against ransomware, destructive malware and serious administrative error.
For critical data, an air gap can also provide reassurance that is easy to explain to directors, customers and auditors: there is a known-good copy that is not continuously exposed to the production environment.
The trade-off is practicality. Creating and managing a truly offline process can introduce manual work, handling risk and longer recovery times. If removable media is not rotated, stored securely and checked, the business may discover too late that the copy is old, incomplete or unreadable. A disconnected backup is not useful if nobody can locate it, decrypt it or confirm which system it belongs to.
Air-gapped backups are usually best treated as a protected recovery tier rather than the only backup method. They are particularly appropriate for periodic copies of the most important systems, such as ERP databases, finance data, engineering drawings, core file servers and documented machine configurations.
Logical air gaps need scrutiny
Some providers describe a backup as air gapped when it is simply stored in a separate cloud account or isolated network. This can offer worthwhile protection, but it is not the same as a physical disconnection. If the same privileged credentials can access production systems and the backup environment, an attacker who steals those credentials may still reach both.
A logical air gap can be effective when it includes separate identities, tightly controlled access, multi-factor authentication, monitored administration and an independent security boundary. The key is to understand exactly what is separated, who can cross that boundary and how quickly an attacker could do the same.
The Strengths and Limits of Immutable Backups
Immutable backups are well suited to businesses that need frequent backups and fast recovery. They can be automated, monitored and retained in a protected state without relying on someone to disconnect and reconnect storage. When configured correctly, they reduce the chance that ransomware or a compromised administrator account can erase recent recovery points.
This is especially valuable for systems where data changes throughout the day. An ERP database, for example, may need frequent backup points to limit the amount of order, stock or production data that must be recreated after an incident. Immutability can preserve those points while keeping them available for a controlled restore.
However, immutability is not a complete security strategy. It protects the data after it has been written, not the quality of the backup itself. If a compromised system backs up encrypted or corrupted data for several days before the issue is discovered, the organisation needs retention long enough to reach a clean recovery point.
It also depends on correct configuration. Retention periods, deletion controls, access permissions, encryption keys and backup alerts must be reviewed. An immutable repository that is configured with short retention or administered through a poorly protected account can still leave material gaps.
Choosing the Right Recovery Design
For most manufacturers, the decision is not about selecting a single technology. It is about assigning the right level of protection to each system according to its recovery time objective and business impact.
Start with the systems that stop production when they fail. This may include ERP and MRP platforms, identity services, virtual servers, file storage, design data, warehouse systems and network configurations. Then consider the less obvious assets: machine recipes, programmable logic controller backups, supplier documentation, licence servers and the configuration of legacy equipment.
For each system, establish how long the business can operate without it and how much data it can afford to lose. A frequently changing ERP database may require immutable backups several times a day, with a clearly tested restoration procedure. A stable machine configuration may be better protected by a controlled offline copy, updated whenever an authorised engineering change is made.
A sensible layered design commonly includes frequent immutable backups for operational recovery, separate backup administration credentials and a protected offline or independently isolated copy for disaster recovery. This approach supports speed without placing all trust in one backup platform or security boundary.
Recovery Testing Is the Real Measure of Protection
A backup report showing a green tick is not proof that recovery will work. The business needs evidence that critical systems can be restored within the timescales production requires.
Testing should cover more than restoring a single file. It should include recovering a server or virtual machine, validating database consistency, confirming application access and checking that restored systems can communicate safely with dependent services. For production environments, this must be planned carefully so testing does not interrupt machinery, shift patterns or order fulfilment.
Document the recovery order as well. Restoring an application before its identity service, database or network configuration may waste valuable time. Clear ownership between internal teams, software suppliers and IT support providers prevents confusion when every hour of downtime affects output.
Questions to Ask Before Investing
When reviewing an air-gapped or immutable backup service, ask whether backup administration is separated from normal user accounts, how long recovery points are protected from deletion and whether restoration tests are included. Establish where data is held, how encryption keys are controlled and what happens if the backup provider’s own platform is unavailable.
Also ask for recovery times based on your real data volumes and connection speeds, not a theoretical promise. Restoring several terabytes of ERP, file and virtual machine data is a different proposition from recovering a handful of documents. A credible plan accounts for bandwidth, storage performance, application dependencies and the time needed to validate the restored environment.
Syn-Star helps manufacturers design backup and recovery arrangements around production continuity, including protected recovery copies, legacy-system considerations and tested restoration plans.
The most useful backup is not the one with the most impressive label. It is the one that remains clean, accessible and tested when a cyber incident threatens to stop the factory floor.
