Back to articles
Technology Insight

Securing Corporate Data: Implementing Immutable Backups Against Ransomware Using Kopia and Backblaze B2 Object Lock from a VPS

June 4, 2026

The Escalating Threat of Ransomware and the Imperative of Immutability

In the contemporary digital landscape, data has emerged as an organization's most valuable asset. Concurrently, ransomware tactics have evolved exponentially. Modern malicious actors no longer merely encrypt live production systems; they actively target, delete, or corrupt traditional backup repositories to eliminate any possibility of recovery without paying a ransom. Consequently, standard automated backup strategies are no longer sufficient to guarantee business continuity.

To mitigate this systemic risk, enterprises must adopt the principle of data immutability. An immutable backup refers to data that, once written, cannot be modified, overwritten, or deleted by any user—including system administrators or compromised root credentials—for a strictly defined retention period. By architecting an immutable backup infrastructure using open-source utilities like Kopia and enterprise-grade cloud storage such as Backblaze B2 with Object Lock, organizations can establish a robust, cost-effective, and cryptographically secure recovery point directly from their Virtual Private Servers (VPS).

Understanding the Architectural Components: Kopia and Backblaze B2

Building a resilient defense-in-depth backup strategy requires a synergy between efficient backup software and a compliant storage provider. Let us analyze the distinct advantages each tool brings to this architecture:

1. Kopia: Advanced Open-Source Backup Engine

Kopia is a modern, fast, and secure open-source backup tool designed for end-to-end encryption and deduplication. Key operational benefits include:

  • Client-Side Encryption: Data is encrypted before it ever leaves the VPS source environment, utilizing robust algorithms such as AES-256-GCM or ChaCha20-Poly1305.
  • Content-Defined Deduplication: Kopia breaks data streams into dynamic chunks to eliminate duplicate files and blocks, significantly reducing network bandwidth and destination storage requirements.
  • Native Object Lock Integration: Kopia natively understands cloud provider immutability API calls, ensuring metadata and data blocks are properly locked upon upload.

2. Backblaze B2 and Object Lock Technology

Backblaze B2 provides enterprise-class, S3-compatible cloud object storage at a fraction of the cost of legacy providers. Crucially, its Object Lock capability delivers compliance-grade immutability. When Object Lock is enabled in Compliance Mode, the storage layer strictly enforces the retention policy at the API level, completely neutralizing any malicious deletion attempts from a compromised VPS.

Core Concept: Even if an attacker gains root access to your production VPS and acquires your Backblaze API keys, they cannot delete the locked backup objects. The storage provider will reject all delete requests until the retention duration expires.
---

Step-by-Step Implementation Guide

Executing this deployment involves preparing the storage bucket, configuring the Kopia environment on your VPS, initializing the repository with Object Lock, and automating the scheduling sequence.

Step 1: Provisioning the Backblaze B2 Bucket with Object Lock

Before executing command-line operations on your VPS, you must properly configure the storage destination:

  1. Log in to your Backblaze B2 administrator console.
  2. Navigate to Buckets and select Create a Bucket.
  3. Assign a unique bucket name and ensure the bucket type is set to Private.
  4. Locate the Object Lock setting and toggle it to Enable. Note: Object Lock must be enabled during bucket creation; it cannot be retroactively applied to an existing standard bucket.
  5. Generate a new set of Application Keys with read, write, and delete permissions restricted exclusively to this bucket. Securely store the keyID and applicationKey.

Step 2: Installing Kopia on the Production VPS

Connect to your VPS via SSH and install the Kopia Command Line Interface (CLI). For a standard Linux environment (such as Ubuntu/Debian), utilize the official repository:

curl -s [https://kopia.io/signing-key](https://kopia.io/signing-key) | sudo gpg --dearmor -o /usr/share/keyrings/kopia-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/kopia-keyring.gpg] [https://kopia.io/apt](https://kopia.io/apt) stable main" | sudo tee /etc/apt/sources.list.d/kopia.list
sudo apt-get update
sudo apt-get install kopia

Verify the installation by running kopia --version to ensure the binary is globally accessible.

Step 3: Initializing the Immutable Kopia Repository

With the prerequisites established, connect Kopia to Backblaze B2 and initialize the repository with an explicit immutability retention period. Execute the following command, replacing the placeholders with your infrastructure credentials:

kopia repository create b2 \
  --bucket= \
  --key-id= \
  --key= \
  --password= \
  --retention-mode=COMPLIANCE \
  --retention-period=30d

In this architecture, we have defined a 30-day Compliance Mode retention period. This guarantees that every individual snapshot block uploaded will remain completely un-deletable for exactly 30 days from its creation timestamp.

Step 4: Executing the First Secure Snapshot

To capture your initial backup, define a specific source directory on your VPS (e.g., your web application root or database dump folder):

kopia snapshot create /var/www/html

During this process, Kopia localizes the data, chunks it, applies deduplication, encrypts it with your unique repository passphrase, and uploads it to Backblaze B2, subsequently stamping each object with the Object Lock expiration metadata.

---

Automation and Retention Policy Management

To transition this setup into an enterprise-grade automated system, you must establish an automation loop using a cron job or systemd timer. Create a secure shell script located at /usr/local/bin/run-backup.sh:

#!/bin/bash
# Set repository passphrase environment variable
export KOPIA_PASSWORD=""

# Connect to the repository
kopia repository connect b2 --bucket= --key-id= --key=

# Execute backup
kopia snapshot create /var/www/html

# Maintenance and Pruning
kopia maintenance run --full

Ensure proper security posture by restricting access to this script using chmod 700. Schedule the script via cron to run daily at an off-peak hour:

0 2 * * * /usr/local/bin/run-backup.sh >> /var/log/kopia-backup.log 2>&1

Strategic Considerations and Best Practices

While an immutable architecture provides an unprecedented layer of data resilience, it requires strict adherence to administrative hygiene:

  • Passphrase Redundancy: Because Kopia applies client-side encryption, losing your repository passphrase means total data loss. It cannot be recovered by Backblaze or reset via any administrative override. Store this passphrase in an offsite, offline physical safe or hardware-backed enterprise password manager.
  • Storage Cost Planning: Deduplication optimizes space, but compliance-mode object locking dictates that even historical, deleted files will continue to consume storage quotas until their specified lock duration expires. Monitor your Backblaze B2 billing dashboard to account for this lifecycle retention lag.
  • Periodic Restore Simulations: A backup strategy is only as good as its recovery velocity. Regularly simulate full-scale server destructions and practice restoring data onto an isolated testing VPS to validate your recovery workflows.

Conclusion

Ransomware mitigation requires a paradigm shift from passive prevention to active resilience. By combining the local encryption and deduplication efficiencies of Kopia with the cloud-level immutability enforcement of Backblaze B2 Object Lock, you create an impenetrable barrier around your corporate assets. Even in a worst-case scenario where a production VPS is completely compromised, your baseline backup architecture remains untouchable, granting your organization the leverage to recover quickly without financial capitulation to threat actors.