UK IT leaders have moved fast: 85% now use or plan to use immutable storage within 12 months, according to a 2026 IT-leader survey — yet that still trails the US at 98%. More striking is Acronis's own 2026 telemetry: across its customer base, immutable storage is actively enabled on just 1.4% of all stored data, even though 846,000 tenants have the settings configured. This data study pulls together the clearest 2025-2026 figures on immutable and air-gapped backup adoption, separates genuine hardware-level protection from policy settings a compromised admin account can undo, and sets out what UK buyers should actually be checking before their next insurance renewal or audit.
View the data behind this chart
| UK | France | US | |
|---|---|---|---|
| Using or planning… | %85 | %96 | %98 |
Immutable Backup in 2026: From Best Practice to Baseline
Object First, a vendor specialising in immutable backup storage, reported 118% year-on-year bookings growth in Q1 2026, framing it as evidence that enterprise buyers are actively shifting spend toward immutable-capable storage as a ransomware defence. That figure is vendor-reported revenue momentum rather than an independent market census, but it is a useful directional signal that budget is moving, not just intent.
The harder independent number sits with IBM, which cited 2026 research showing 41% of critical infrastructure facilities globally already run immutable backups. The same source found that 66% of US organisations experienced ransomware attempts specifically aimed at their backup repositories — a reminder that attackers now treat the backup estate itself as a primary target, which is precisely why buyers can no longer treat immutability as an optional extra layered on top of a conventional backup job. For anyone building a resilience case internally, it's worth reading how to explore solutions for robust ransomware protection that assume the backup repository itself is under attack.

The State of UK Adoption, Mid-2026: What the Surveys Actually Say
A 2025 UK resilience survey cited by Acronis found 59% of organisations already have immutable backups in place, while 72% have air-gapped backups — a useful reminder that these are related but distinct controls, and that UK organisations have deployed offline isolation somewhat more widely than true immutability. If the terminology is unclear, it's worth taking time to understand the difference between immutable and air-gapped backups before assuming one substitutes for the other.
A separate 2026 IT-leader survey published via PR Newswire found 94% of IT leaders globally either already rely on immutable data storage or plan to implement it within 12 months. Within that same dataset, UK respondents came in at 85%, below the US at 98% and France at 96% — confirming the UK is moving in the same direction as its peers, just a step behind on both current use and near-term intent.
Confusingly, a separate 2024 enterprise survey cited by Acronis produced an identical-sounding 94% figure for organisations already using or planning to use immutable storage within 12 months. These are two different surveys, a year apart, measuring different populations — a coincidence worth flagging rather than treating as the same data point repeated.
Beyond Ransomware: What's Actually Driving Adoption
Ransomware remains the headline driver, but the data shows presence of backups doesn't equal successful recovery. Sophos reported in 2025, as cited by Acronis, that only 54% of attacked companies actually used their backups to restore data — meaning nearly half of organisations with some form of backup still couldn't rely on it when it mattered.
Rubrik's UK and EU survey of 150 IT leaders across education, technology, finance and the public sector found 75% agree backups are the single most important defence against ransomware. That level of consensus is exactly why immutability and air-gapping are increasingly showing up inside ransomware resilience questionnaires, supplier assurance packs, and cyber insurance renewal conversations — even where no single published UK insurance mandate figure exists yet in the data reviewed here. The practical implication for UK buyers is procurement pressure now arrives from insurers and auditors, not just from IT teams reading vendor blogs.
True Immutability vs Policy-Based Settings: Why the Distinction Matters
Not all "immutable" backup is equal. Hardware or OS-level WORM (write once, read many) enforcement and object-storage Object Lock in compliance mode are difficult to override even with administrative credentials. Policy-based immutability — a flag set inside backup software — can, in weaker implementations, be altered or disabled by whoever controls the console, which is exactly the access sophisticated ransomware operators now target first.
This distinction isn't academic. Rubrik found that 37% of UK and EU IT leaders were not aware of their own backup vendor's immutability and security principles against ransomware. That's more than a third of IT decision-makers unable to say with confidence whether their organisation's protection is enforcement-grade or a policy toggle. Before renewing or selecting a platform, it's worth taking the time to learn more about what immutable backup entails at the enforcement level, not just the marketing level.
The Configuration-to-Protection Gap: Inside the Acronis Telemetry
Acronis's own 2026 platform telemetry offers one of the clearest illustrations of the gap between having a feature and actually using it. Around 846,000 customer tenants have immutability settings configured, but only about 253,000 currently have it enabled — and of those, just 170,000 tenants have immutable storage actively enabled and in use, protecting roughly 49 petabytes of data.
Set against Acronis's total customer backup storage footprint of approximately 3,600 petabytes, that 49PB of actively protected data represents around 1.4% of the entire stored estate. In other words, most data sitting inside backup infrastructure that technically supports immutability isn't actually covered by it day to day.
Rubrik's survey adds a recovery-speed dimension to the same problem: two-thirds of UK and EU IT leaders view instant recovery as central to ransomware recovery strategy, yet only 34% said their current backup solution actually delivers it. Configuring immutability and claiming instant recovery are both easy to tick as boxes; delivering either under pressure is a different exercise entirely.
View the data behind this chart
| Layer | Detail |
|---|---|
| 846,000 tenants | Have immutability settings configured |
| 253,000 tenants | Currently have immutability enabled |
| 170,000 tenants / 49PB | Actively enabled and in use today |
Cost, Compliance and Cyber Insurance: Building the Business Case
None of the sources behind this study publish a reliable, single GBP price point for immutable backup, and any specific UK pricing claim should be checked directly against current reseller or vendor quotes rather than assumed. What the data does support is a shift in where the cost sits: immutability is increasingly bundled into backup software licensing, cloud storage tiers, or purpose-built appliances, rather than sold as a standalone premium line item — so the first question for any UK buyer should be where in the stack the cost is already hidden, not whether to pay extra for it.
The stronger business case is built from what's already documented: ransomware attempts increasingly target the backup repository itself (66% of US organisations, per IBM-cited 2026 research), recovery from backups fails more often than assumed (only 54% success per Sophos), and buyer education gaps around "real" immutability (37% unaware, per Rubrik) create audit and insurer risk that's separate from any ransom payment. Framing the investment against avoided downtime, failed-restore risk, and smoother insurance renewal — rather than a single headline ROI percentage — is the more defensible way to present this internally.
Architecture Choices, and What Comes Next Beyond 2026
Across the market, buyers are broadly choosing between four approaches: cloud-native object storage with Object Lock, purpose-built on-premises appliances with hardened OS-level WORM, a software-defined policy layer added on top of existing storage, and offline or air-gapped copies held physically or logically separate from the network. None of the cited data favours one architecture outright — the Acronis-cited UK figures show air-gapping (72%) currently more widely deployed than immutability (59%), suggesting many organisations are layering both rather than picking one. This is precisely the direction the evolving 3-2-1-1-0 backup framework pushes buyers toward — which typically includes one immutable or air-gapped copy, in addition to zero errors on verified restores. Many organisations are now layering both immutable and air-gapped copies for enhanced resilience.
Looking beyond 2026, the clearest signal in the data isn't a new technology trend but an operational maturity gap that needs closing: configuration numbers (846,000 tenants) vastly outstrip actual enabled protection (253,000, then 170,000 in active use), and stated recovery ambitions (two-thirds wanting instant recovery) outstrip delivered capability (34%). Expect scrutiny to shift from "do you have immutable backup" toward "can you prove it's enforcement-grade, enabled, and recoverable within your stated RTO" — a bar that will separate genuinely resilient organisations from those that simply ticked a setting.
Methodology
This study compiles figures published between January 2025 and April 2026 from a mix of vendor platform telemetry (Acronis), independent-format IT-leader surveys distributed via newswire (PR Newswire), analyst-style vendor research reports (Rubrik, IBM-cited Market Reports World data), trade press coverage of vendor financial results (StorageReview on Object First), and third-party ransomware research referenced within those reports (Sophos, cited by Acronis). Each figure is attributed to its original source and dated to the survey or reporting period specified in that source, rather than restated as a single current-year average.
Verification consisted of tracing every statistic back to its named publisher and confirming the reported population, sample size (where disclosed, such as Rubrik's 150-person UK/EU sample), and question wording before including it here, so that figures measuring different things — for example, tenants with immutability configured versus tenants with it actively enabled — are presented as distinct data points rather than merged into one adoption rate. Where the underlying sources did not provide UK-specific GBP pricing or a single authoritative UK insurance mandate figure, that gap is stated explicitly rather than estimated.
Sources
Every figure in this article traces to the sources below.
- •StorageReview — Object First Q1 2026 bookings growth of 118% YoY
- •IBM — 41% of critical infrastructure facilities using immutable backups; 66% of US organisations facing backup-targeted ransomware
- •Acronis — UK immutable (59%) and air-gapped (72%) adoption, Sophos 54% restore-success figure, and 2026 platform telemetry
- •PR Newswire — 94% global and 85% UK IT leaders using/planning immutable storage, vs 98% US and 96% France
- •Rubrik — UK/EU survey of 150 IT leaders on ransomware defence, instant recovery, and vendor immutability awareness
View the data behind this chart
| Control type | Enforcement… | Bypass risk | |
|---|---|---|---|
| Hardware/OS-level WORM | Storage firmware/OS | Very low (physical) | Needs physical access |
| Object Lock (complianc… | Storage platform API | Low (API-enforced) | Can't be shortened |
| Policy-based /… | Backup software layer | Higher risk | Admin credential misuse |
| Air-gapped offline… | Physical/network gap | Low (needs breach) | Requires physical entry |
The 18 verified data points behind this study are free to download and reuse with attribution (CC BY 4.0).
Cite as: Servnet Research, “Immutable Backup Adoption 2026: UK Data Study”, servnetuk.com, 2026.
