IBM i Backup and Recovery Software

Do IBM i backups need immutable or offline copies for ransomware recovery?

Usually yes. IBM i is stable, but the recovery path can still be compromised through shared credentials, connected backup infrastructure, or surrounding Windows and network systems that attackers reach first. An isolated, immutable, or offline copy gives the business one recovery layer that is harder to alter under attack.

Answer

Most ransomware incidents that touch an IBM i environment do not start on IBM i at all. They start on a Windows domain controller or a file server, and the attacker uses harvested credentials to move laterally, sometimes reaching a backup server or an FTP-connected share that has write access to IBM i save files. If that backup infrastructure is online and reachable with the same compromised credentials, an attacker can delete or encrypt the backups right alongside the production data, which turns a recoverable incident into an unrecoverable one. This is exactly why the offline or immutable copy needs to be genuinely out of reach of normal administrative credentials, not just a separate folder or a different login.

When evaluating a vendor's ransomware claim, ask three specific things: can any account, including a domain administrator or an IBM i QSECOFR-equivalent, shorten or delete the retention lock before it expires; does the offline copy require physical media rotation or is it enforced purely through software controls; and has the vendor's own team, or has the customer's IT team, actually performed a full restore from that isolated copy on a schedule. A vendor that cannot answer the credential-bypass question clearly is describing a backup that looks resilient on paper but has not been tested against how real ransomware attacks actually spread.

Back to IBM i Backup and Recovery Software