On-premises object storage for backups
S3-native object storage solution built for Veeam that enforces Zero Access, ensuring nobody can alter or delete backup data—even with admin credentials.
S3-native object storage solution built for Veeam that enforces Zero Access, ensuring nobody can alter or delete backup data—even with admin credentials.

In most ransomware attacks, attackers don't just encrypt your data; they target backup systems first, aiming to force ransom payments by destroying your ability to recover.
To survive these attacks, you need absolutely immutable backups—so even the most privileged admin or attacker with access to backup storage cannot modify or delete data. For backup appliances and storage systems, S3 object storage is the only way to achieve this.
Combined with cloud backups, on-premises storage is an important part of a hybrid strategy that follows the 3-2-1-1-0 rule: at least three copies of data, on two media types, with one off-site, one offline or immutable, and zero recovery errors confirmed by testing. Multiple immutable copies in multiple locations mean a single attack cannot eliminate all your backups.
Object storage is an architecture that organizes data as discrete objects, each with unique metadata and identifiers, rather than as files in folders or blocks on a disk. Each object is stored in a flat namespace and accessed via an API.
On-premises object storage brings this architecture into your data center, under your control. It runs on physical hardware you manage, typically using the S3 API standard for compatibility with Veeam and other backup software. Unlike file or block storage, it combines the scalability and data immutability capabilities needed for effective, secure backup storage.
Object storage stores backup data as objects consisting of the data itself, metadata, and a unique identifier. Because each object is managed independently, storage systems can apply policies directly at the object level. For backup protection, this enables capabilities such as object-level retention controls and highly scalable repositories.
First, it enforces immutability through S3 Object Lock in Compliance Mode. This mechanism creates retention rules at the object level: once written, data stays locked for a specified period. Compliance Mode enforces a non-erasable, non-rewritable state at the protocol layer rather than through operating system permissions. Because protocol-level controls cannot be overridden without violating the S3 specification, this provides strong protection from modification or deletion—though not all S3 immutability systems deliver the level of protection needed to protect against ransomware attacks. The difference lies in how immutability is implemented and verified.
Second, the flat namespace architecture allows object storage repositories to scale efficiently to petabytes of data without the file and directory limitations of traditional storage systems. Recent backups can remain on-premises for fast recovery, while long-term copies can be replicated to cloud object storage as part of a hybrid retention strategy.
Object storage is becoming the preferred repository for backup data because it delivers capabilities that traditional file and block storage struggle to match.
For organizations running Veeam, on-premises object storage addresses three competing demands at once: fast local recovery when incidents occur, immutable protection that ransomware cannot bypass, and greater control over backup data location, helping support compliance and governance frameworks such as GDPR, DORA, and NIS2.
S3 Object Lock in Compliance Mode prevents stored objects from being modified or deleted for a defined retention period, even if credentials are compromised. Versioning, when used with Object Lock, preserves multiple immutable recovery points.
Because Compliance Mode is enforced at the object storage layer, retention settings cannot be overwritten by administrators, backup operators, or attackers.
S3 backup data can be encrypted with rotating keys the moment it is created, so even if bucket credentials are compromised, it cannot be read or exfiltrated.
Built on an open, fully documented protocol, S3 object storage allows independent testing and verification by security researchers and auditors, unlike proprietary, black-box systems.
Repositories can scale to petabytes by adding nodes, with no file or block limits.
Every object carries customizable metadata that powers search, automation, and lifecycle and retention policies.
Organizations adopt on-premises object storage for different reasons, but most use cases center on three priorities: protecting backups from ransomware, accelerating recovery after incidents, and supporting compliance and governance requirements.
When ransomware hits, backups stored in object storage with S3 Object Lock in Compliance Mode remain protected from modification or deletion until their retention period expires. No credential can override the retention lock, and no attacker can delete or corrupt the data. Many organizations use this as the foundation of a ransomware resilience strategy, enabling recovery without paying a ransom.
The 3-2-1-1-0 backup rule was developed as a framework for building resilient backup strategies that can withstand ransomware attacks, system failures, and site-level disasters. To achieve both fast recovery and off-site protection, many organizations adopt a hybrid backup strategy that combines on-premises and cloud storage.
Here's how each component works:
On-premises storage stores data locally on physical infrastructure you control, typically purpose-built appliances, SAN or NAS arrays, or object storage systems. Recovery happens fast across local networks, and no external provider can alter or throttle the data. However, on-premises systems require hardware management, ongoing maintenance and physical protection. A local copy alone cannot survive fire, theft, or site loss, so it must be paired with an off-site copy.
Cloud backup storage runs on remote servers – most commonly from public cloud providers like AWS, Azure, or Google Cloud, offering elastic scalability and instant geographic redundancy. Yet, restoring terabytes can be slow, especially when bandwidth limits apply. Control is also shared; uptime, encryption, and retention depend on the provider.
Hybrid backup storage combines local performance with cloud scalability. Recent or mission-critical data stays on-premises for fast recovery, while older or immutable copies go to the cloud for off-site protection. This layered approach pairs low-latency restores for everyday incidents with cloud-based isolation for ransomware defense.
Absolute Immutability in your on-premises backup layer greatly increases the security of the hybrid backup strategy by ensuring attackers cannot modify or delete on-prem backup data.
66% of organizations reported at least one ransomware attack in the last two years [1], and 96% of those attacks targeted backups to prevent recovery and force ransom payments. [2]
To protect against ransomware, backup data must be immutable to ensure it cannot be altered or deleted once recorded.
But not all object storage solutions that claim to offer immutability really deliver it. If "immutable" data can be overwritten by a backup or storage admin, a vendor, or an attacker, then it cannot be considered an absolutely immutable storage solution.
The only guaranteed path to recovery after a ransomware attack is having backup storage with Absolute Immutability. This means no one, not even the most privileged admin or attacker with access to backup storage, can modify or delete data.
Absolute Immutability can only be achieved using a backup storage system that is "secure-by-design," with Zero Access to perform destructive actions, and this Zero Access must be verified through third-party testing. For backup appliances and storage systems, S3 object storage is the only way to achieve this.
When—not if—ransomware strikes, the future of your business, reputation, and career are on the line.
Object First delivers Zero Trust, S3-native, absolutely immutable storage—optimized for unbeatable backup and recovery.
Create secure backups with Zero Access to perform destructive actions
Deploy in 15 minutes with no security expertise required
Supercharge Veeam Instant Recovery
:quality(75))
[1] ESG. "2025 Recommended Backup Strategies." Object First. https://objectfirst.com/blog/esgs-2025-recommended-backup-strategies/
[2] Veeam. "Ransomware Encryption and Backup Data." https://www.veeam.com/blog/ransomware-encryption.html