Showing results for 
Search instead for 
Did you mean: 

NBU Flex Appliance Zero Trust Architecture to Protect you from Ransomware

Level 1

NetBackup Flex Appliances provide a complete immutable storage solution to defend your backup data from ransomware. NetBackup Flex WORM storage provides immutability and indelibility for your data. Immutable and indelible data cannot be changed for a determined length of time to protect data against cybercriminal intrusion and internal threats. This property protects the backup image from being deleted before it expires to ensure your data is protected from malicious deletion. To get more details on how to set up WORM storage check this wonderful demo.

Cohasset Associates evaluated NetBackup’s capabilities against compliance regulations and showcased how NetBackup with WORM-capable storage meets the requirements. NetBackup WORM capability is vendor-agnostic and will run on devices with immutable storage. Flex Appliances offer a hardened solution with immutable storage that prevents access to backup data by malicious invaders. 

NetBackup and Flex Appliance immutability solutions have completed the Cohasset Associates’ immutability assessment (in compliance mode), specifically:

  • Securities and Exchange Commission (SEC) in 17 CFR § 240.17a-4(f)

  • Financial Industry Regulatory Authority (FINRA) Rule 4511(c)

  • Commodity Futures Trading Commission (CFTC) in regulation 17 CFR § 1.31(c)-(d)

To see the full assessment, visit

Lock Down Mode

The NetBackup primary server communicates with the storage unit to gather the immutability and indelibility capability and WORM retention period (min/max) settings. The primary server sets up immutability controls on the storage unit and applies the WORM retention period policy. NetBackup provides backup image management with a visual representation of the immutable lock, image deletion after the WORM retention period (via the command line interface [CLI]), and honors legal hold on the catalog.


NetBackup Flex Appliances have an immutable storage server to provide WORM capability, retention locks, and platform hardening to protect against malware infiltration and ransomware attacks. A specially designed secure Compliance Clock is used to manage retention periods and is independent from the OS time. NetBackup Flex Appliances have two lock-down immutability modes—Enterprise and Compliance. You can enable the appliance lock-down state at any time. You can choose either Compliance mode or Enterprise mode for an MSDP storage instance but you cannot mix the two modes. The table below lists the differences between Enterprise mode and Compliance mode.


Veritas provides a unified, multi-layered, hardened, and secure appliance platform that optimizes operational efficiency and seamlessly integrates comprehensive protection and malware detection into an industry-leading backup and recovery solution.