Backup Strategy and Offline Copy
Backup strategy and offline copy records how frequently an organisation backs up critical data and whether at least one copy is kept offline, air-gapped or immutable, a decisive control against ransomware queried in cyber proposal forms.
- Category
- IT/Cyber
- Data type
- Enumeration
- Risk drivers
- Severity, Frequency
- Underwriting impact
- Premium, Deductible, Sublimit, Condition/Warranty
Typical proposal-form questions
- How frequently are critical systems and data backed up, and is backup coverage complete across all business-critical applications?
- Is at least one backup copy kept offline, air-gapped or immutable so that it cannot be reached or encrypted from the production network?
- When was the restore process from backup last tested, and what recovery time was achieved?
Evidence
- Backup and recovery policy
- Backup system configuration or architecture diagram
- Restore test report or business continuity test log
Why it matters for underwriting
Backup quality is one of the strongest predictors of eventual ransomware claim severity, because a viable, unencrypted, restorable copy of critical data is what turns a potentially existential extortion event into a recoverable business interruption loss. Modern ransomware operators actively search connected networks for backup servers and network shares to encrypt or delete them before deploying the payload, specifically to remove the victim’s ability to recover without paying. Underwriters use this attribute to gauge how quickly an insured could realistically resume operations after an attack, which drives both the expected business interruption period and the insured’s negotiating leverage against extortion demands. Backup strategy is therefore treated as a primary severity driver rather than a secondary control, and is scrutinised closely for accounts with high revenue dependency on IT systems.
Capturing the attribute and evidence
Proposal forms ask about backup frequency by data criticality tier, total backup coverage across business-critical applications, and, most importantly, whether at least one copy is kept offline, air-gapped, on immutable storage, or otherwise logically and physically separated from the production network and its administrator credentials. Underwriters request the backup and recovery policy, an architecture diagram or configuration summary showing how the offline or immutable copy is technically achieved, and the most recent restore test report demonstrating that data was actually recoverable within a defined time. A stated backup regime that has never been test-restored is treated with scepticism, since untested backups frequently fail or prove incomplete precisely when needed.
Effect on coverage, premium and conditions
Frequent, comprehensive backups with a verified offline or immutable copy support favourable premium rates, higher business interruption sublimits and shorter waiting periods. Backup regimes limited to online, network-connected storage without any offline or immutable component are a common trigger for ransomware sublimits, coinsurance requirements or premium loadings, reflecting the materially higher probability that backups would be destroyed alongside production data in an attack. Absence of any tested backup and recovery capability, or backups covering only a fraction of critical systems, can result in exclusion of ransomware-related business interruption or outright declinature depending on the insurer’s risk appetite.
Mitigation measures
Insurers and IT security advisors typically recommend the 3-2-1 backup principle: at least three copies of critical data, on two different media types, with one copy kept offline, air-gapped or immutable and therefore unreachable from a compromised production network. Regular restore testing, ideally quarterly for the most critical systems, is recommended to confirm actual recoverability and to measure achievable recovery time objectives. Segregating backup infrastructure administratively from production, using separate credentials and, where feasible, a separate identity domain, further reduces the chance that an attacker who compromises production systems can also reach and destroy the backups.