Risk Attribute

Backup Strategy and Offline Copy

Expert-reviewed Updated: 2026-09-03 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

Backup strategy and offline copy records how frequently an organisation backs up critical data and whether at least one copy is kept offline, air-gapped or immutable, a decisive control against ransomware queried in cyber proposal forms.

Category
IT/Cyber
Data type
Enumeration
Risk drivers
Severity, Frequency
Underwriting impact
Premium, Deductible, Sublimit, Condition/Warranty

Typical proposal-form questions

  • How frequently are critical systems and data backed up, and is backup coverage complete across all business-critical applications?
  • Is at least one backup copy kept offline, air-gapped or immutable so that it cannot be reached or encrypted from the production network?
  • When was the restore process from backup last tested, and what recovery time was achieved?

Evidence

  • Backup and recovery policy
  • Backup system configuration or architecture diagram
  • Restore test report or business continuity test log

Why it matters for underwriting

Backup quality is one of the strongest predictors of eventual ransomware claim severity, because a viable, unencrypted, restorable copy of critical data is what turns a potentially existential extortion event into a recoverable business interruption loss. Modern ransomware operators actively search connected networks for backup servers and network shares to encrypt or delete them before deploying the payload, specifically to remove the victim’s ability to recover without paying. Underwriters use this attribute to gauge how quickly an insured could realistically resume operations after an attack, which drives both the expected business interruption period and the insured’s negotiating leverage against extortion demands. Backup strategy is therefore treated as a primary severity driver rather than a secondary control, and is scrutinised closely for accounts with high revenue dependency on IT systems.

Capturing the attribute and evidence

Proposal forms ask about backup frequency by data criticality tier, total backup coverage across business-critical applications, and, most importantly, whether at least one copy is kept offline, air-gapped, on immutable storage, or otherwise logically and physically separated from the production network and its administrator credentials. Underwriters request the backup and recovery policy, an architecture diagram or configuration summary showing how the offline or immutable copy is technically achieved, and the most recent restore test report demonstrating that data was actually recoverable within a defined time. A stated backup regime that has never been test-restored is treated with scepticism, since untested backups frequently fail or prove incomplete precisely when needed.

Effect on coverage, premium and conditions

Frequent, comprehensive backups with a verified offline or immutable copy support favourable premium rates, higher business interruption sublimits and shorter waiting periods. Backup regimes limited to online, network-connected storage without any offline or immutable component are a common trigger for ransomware sublimits, coinsurance requirements or premium loadings, reflecting the materially higher probability that backups would be destroyed alongside production data in an attack. Absence of any tested backup and recovery capability, or backups covering only a fraction of critical systems, can result in exclusion of ransomware-related business interruption or outright declinature depending on the insurer’s risk appetite.

Mitigation measures

Insurers and IT security advisors typically recommend the 3-2-1 backup principle: at least three copies of critical data, on two different media types, with one copy kept offline, air-gapped or immutable and therefore unreachable from a compromised production network. Regular restore testing, ideally quarterly for the most critical systems, is recommended to confirm actual recoverability and to measure achievable recovery time objectives. Segregating backup infrastructure administratively from production, using separate credentials and, where feasible, a separate identity domain, further reduces the chance that an attacker who compromises production systems can also reach and destroy the backups.