Offsite, air-gapped, immutable, and recoverable are four different properties. Most backup strategies in Asia Pacific deliver one of them but assume they have all four.
Ask an infrastructure team anywhere in Asia Pacific what their offsite backup copy protects against, and you will hear a different version of the same answer: A fire, a flood, a failed array, or a data center that goes dark.
Those answers are not wrong, but an offsite backup is built for a threat model that is about twenty years old.
The event that now decides whether an organization survives a bad quarter is not a site failure. It is a person who has been inside the environment for weeks, who holds privileged credentials, who has read the runbooks, and who understands that the recovery path is the only thing standing between the organization and a payment.
So, they act accordingly. Veeam’s 2025 Ransomware Report found that 89% of organizations hit by ransomware had their backup repositories targeted by a threat actor. These repositories were not incidentally encrypted but targeted as an objective. The same research found only 32% of those organizations used repositories that were configured as immutable.
Nine in ten attacks go for the backups. Three in ten organizations have hardened them. That is not a technology gap; it is a definitional one, because most teams believe they already have this covered. They have an offsite copy so they ticked the box.
Four Words We Use Interchangeably, and Shouldn’t
Offsite is about geography. What happens if this building is destroyed? Nearly everyone has solved this.
Air-gapped is about reachability. If the credentials that administer my environment are already in someone else’s hands, can they reach this copy at all? A copy 3,000 kilometers away, inside the same tenancy, governed by the same identity provider, reachable by the same privileged account, is offsite. It is not air-gapped.
Immutable is about alterability. If they reach it, can they change or delete it? And if your follow-up most architectures fail, can anyone reach it? Including your most trusted administrator? Including you?
Recoverable is about provability. Can I get the data back, verified clean, inside the window the business can survive? An untested copy is a hypothesis, not a recovery plan.
Here is the uncomfortable test: Write down every account in your organization that can delete both production data and the backup copy of that data. Include service accounts and the identity that runs the backup software itself.
If that list is not empty, your offsite copy is protecting you from weather. It is not protecting you from an adversary — because the adversary’s objective is to become one of the names on that list.
The Region’s Regulators Got There First
This is not a vendor argument.
In June 2024 the Australian Prudential Regulation Authority wrote to all regulated entities on the security and adequacy of backups. APRA expects entities to “maintain sufficient isolation of backups from the production environment so that a compromise of the production environment does not compromise backups,” with controls preventing “any single account or person to have permission to modify or delete both production and backup.” APRA named three recurring weaknesses: Insufficient segregation, inadequate testing that backups remain protected from unauthorized alteration, and insufficient testing of recovery within tolerance.
Read that as a sentence written by a banking regulator, and the list test stops being rhetorical.
India’s position is more specific still. The Reserve Bank of India’s cyber resilience directions for non-bank payment system operators require half-yearly testing that backup data is recoverable without loss of transactions or audit trails, a near-zero recovery point objective (RPO), and a disaster recovery (DR) facility in a different seismic zone from the primary data center. That last requirement is quintessentially Asia Pacific, and it is fundamentally an argument about blast radius. Singapore and Hong Kong are moving the same direction through the Cybersecurity Act amendments, the Digital Infrastructure Bill and the Protection of Critical Infrastructures Ordinance.
The supervisory question is shifting from “do you have backups” to “can a compromise of your environment compromise your backups, and can you prove otherwise.”
The Sovereignty Trap
For a decade, the answer to residency concerns in regulated Asia Pacific markets was to keep it in the building. Keep tape in a vault and a second data center down the road.
That logic was sound when the threat was environmental. It’s now less sound, when the threat became an intruder with your credentials. “Keep it in the building” now means keeping the last copy inside the same identity perimeter and the same administrative blast radius.
An example of this, is Indonesia’s national data center incident in June 2024. Ransomware disrupted services across roughly 210 government institutions, including immigration and passport processing. The head of Indonesia’s national cyber agency later confirmed that 98% of the data in one affected facility had no backup at all — backup had been an optional, chargeable add-on that agencies declined on budget grounds. The government refused to pay but there was nothing to restore from.
Sovereignty had been achieved. Resilience had not. They are not the same thing.
The Insurance Question
Cyber claim notifications in Asia rose 50% between 2022 and 2024, and underwriters have responded by asking harder questions. Immutable, isolated backup copies now come up routinely in underwritten conversations alongside multi-factor authentication (MFA), EDR and incident response readiness.
It would be easy, and wrong, to present an immutable copy as the answer. It is one control among many. What it changes is the conversation you have during an incident. Organizations prioritizing data resilience recover up to seven times faster; across all victims, only 10% recovered more than 90% of their data. Leverage in a ransom negotiation is not bought with a policy. It is built beforehand, in architecture.
The Premier Bank PLC in Bangladesh cut recovery time objectives by 65% and reduced backup management effort by 75%, citing immutable, encrypted and air-gapped storage as its ransomware mitigation. It was not spared an attack, but it was spared being held hostage. That is the realistic definition of success.
The question for your next risk committee is not “do we have an offsite backup?”, since everyone does.
“If an attacker holds our most privileged credentials tomorrow morning, which copy of our data can they not reach, cannot alter, and can we prove we can restore from — and is it in a jurisdiction our regulator accepts?”
If the room can answer that in one sentence, the architecture is sound. If the answer needs a caveat, that caveat is the plan.
What “Designed to Survive an Attack” Looks Like
Veeam Vault is not a cheaper bucket with a Veeam badge on it. It is a Veeam-managed storage service whose design choices only make sense if you assume the customer’s environment is already compromised.
Immutability that is not a configuration option. Backups land in a write-once, read-many state by default. Immutability cannot be switched off, there is no object lock mode to select, and no administrator, script, or root-level user that can alter or remove data before its retention period expires. In a self-managed bucket, immutability is something you configure, keep configured, and prove is still configured, which is precisely the control-testing weakness APRA called out.
Separation that survives credential compromise. Veeam Vault sits in a Veeam-managed tenancy that’s logically air-gapped from your environment. Authorization is federated and role-based rather than credential-based, with no long-lived access keys or static secrets stored server-side. Data is protected with AES 256-bit encryption in flight and at rest, and you hold the keys.
Residency you choose. Veeam Vault is available in 50+ regions across 27 countries on Azure and AWS, including 22 regions across Asia Pacific and Japan — Australia, Hong Kong, India, Indonesia, Japan, Malaysia, New Zealand, Singapore, South Korea, Taiwan and Thailand. For organizations who’ve been told for a decade that air-gapped and in-country were mutually exclusive, that is where the objection stops being architectural.
Economics that don’t penalize recovery. Veeam Vault’s per-TB pricing includes storage, API calls and egress. That sounds commercial, but it’s actually a security property. Recovery testing you avoid because of the retrieval bill is recovery testing that does not happen — which is the third weakness on APRA’s list. Veeam’s latest cloud storage solution, Veeam Vault Archive, extends the same immutable, air-gapped model into long-term retention, which is a conversation of its own.
Go Deeper
This article accompanies “Beyond the Vault: Rethinking Immutability, Retention and Resilience”, a three-part webinar series for security, infrastructure, and risk leaders across Asia Pacific and Japan.
Watch the session: Beyond Cloud Storage: Building a Backup Copy That Survives an Attack. See how air-gap, immutability, and recoverability work together, and where an immutable copy fits (and doesn’t) in your cyber insurance conversation.
Regulatory, residency and retention requirements vary by jurisdiction and sector and continue to evolve. References are current as at the dates cited. Organizations should confirm their obligations with their own regulator or legal counsel.