This technical report details the security assessment conducted by NCC Group for the Ootbi physical appliance server, which is designed for use with Veeam Backup & Replication (VBR) v12. The assessment aimed to ensure that data stored on the server remains immutable and secure from unauthorized modifications or deletions. The evaluation involved 40 person-days of testing in December 2023, followed by an additional 14 person-days in mid-2024 to verify the resolution of previously identified issues. The assessment uncovered 20 flaws, with critical vulnerabilities including OS command injection and weak default credentials. The retest confirmed that 16 critical and high-risk issues were fully resolved, while some medium and low-risk findings remained partially fixed. The report also provides strategic recommendations for improving system security, including credential rotation, privilege separation, and enhanced documentation of API differences. Overall, the findings and recommendations aim to strengthen the security posture of the Ootbi appliance.