The Conventional Wisdom
Your security team invests in endpoint detection, network segmentation, and phishing training because these controls stop attacks. Backups, however, are only used when something goes wrong. They’re for recovery, not prevention.
So when underwriters ask detailed questions about your backup architecture during renewal, it can feel like overreach. You're buying cyber insurance to transfer risk, not to be graded on disaster recovery. If your policy covers ransomware extortion and business interruption, shouldn't the carrier worry about backups only after a claim?
That's the logic many incident response teams express every renewal season. On the surface, it makes sense.
Why Insurers Care
Backups don't stop breaches. But they determine whether a breach becomes a total loss.
In 2024, ransomware appeared in roughly 44% of data breaches. The deciding factor in claim severity wasn't detection speed or containment tactics. It was whether the victim could restore operations without paying the ransom or enduring weeks of downtime while rebuilding from scratch.
Carriers aren't underwriting your ability to prevent incidents. They're underwriting your ability to survive them without filing a catastrophic claim. That's why your backup strategy appears in the underwriting questionnaire alongside MFA and patch management. It's not just an IT concern; it's a financial control that directly affects loss severity.
Consider what happens when backups fail. Your team can't restore encrypted systems. Business interruption stretches from days to weeks. You're negotiating with threat actors or paying forensic vendors to manually rebuild databases. The claim balloons. One report noted that nearly one in five SMBs would be forced to close after a successful cyber attack, and a third would shut down even if the financial impact was less than $10,000. These aren't technology failures. They're recovery failures.
The global cost of cybercrime is projected to reach $13.82 trillion by 2028, much of which reflects extended downtime and reconstruction costs that strong backup practices could have reduced. IBM found the average breach cost reached $4.88 million in 2024, with much of it tied to downtime and recovery. Insurers see that data. They know which controls correlate with survivable incidents versus total losses.
The Evidence
Look at how underwriters price risk. A client with immutable cloud backups, documented recovery time objectives, and quarterly restore tests will see better terms than one relying on local NAS devices connected to the production network. The difference isn't academic. It affects premium, sublimits, and whether the carrier offers full cyber extortion coverage or requires co-insurance.
Why? Because the first client can restore operations within hours after a ransomware event. The second client faces a choice: pay the ransom or stay offline while rebuilding. Both scenarios trigger claims. One is manageable. The other isn't.
Carriers also track which backup configurations attackers compromise during intrusions. Local backups that remain network-accessible get encrypted alongside production systems. Cloud backups without versioning get overwritten with corrupted data before anyone notices. These aren't hypothetical risks. They're documented claim drivers.
When underwriters ask whether your backups use immutable storage or geographic separation, they're testing whether your recovery plan can withstand a determined attacker. If it can't, your business interruption claim will reflect every hour you spend offline negotiating or rebuilding.
What to Do Instead
Stop treating backup questions as compliance theater. Treat them as financial controls that reduce your total cost of risk.
Your incident response plan should document specific recovery time objectives for critical systems, and your backup architecture should support those targets. If you need email and file shares restored within four hours, your backups need to support point-in-time recovery with that granularity. If they don't, adjust the architecture or adjust the RTO. Don't leave the gap unaddressed.
Test your restore process quarterly, not annually. Run actual restores in a segmented environment and measure how long it takes to bring systems online. Document the results. Share them with your broker before renewal. Underwriters will ask for proof, and "we assume it works" isn't proof.
Verify that your backups can't be altered or deleted by attackers who compromise your network. That means immutable storage, offline copies, or cloud configurations that prevent modification during the retention period. If your current setup doesn't meet that standard, fix it before renewal. The premium difference will justify the investment.
Review backup retention policies with your legal and compliance teams. Ransomware that encrypts systems today might have been lurking in your environment for weeks. If your backups only retain seven days of history, you might restore infected copies. Extend retention for critical systems and verify that you can roll back to a known-good state before the intrusion began.
When the Conventional Wisdom Is Right
Backups won't stop sophisticated attackers from gaining initial access. They won't prevent credential theft or lateral movement. If your security budget forces a choice between funding backups and detection capabilities, fund detection first.
But most organizations aren't making that choice. They're deciding whether to treat backups as a compliance formality or as a financial safeguard that directly affects claim outcomes. If you're in the second category, the conventional wisdom breaks down.
Underwriters care about backups because they've seen what happens when they fail. You should care for the same reason. When ransomware encrypts your environment and your team can't restore operations, the policy will pay the claim. But the claim will be large, your renewal will be painful, and your business might not survive the downtime.
Backups don't prevent breaches. They prevent total losses. That's why insurers care, and that's why you should too.





