Best Practices for Cyber Resilience

Insurers now view clean, tested backups as essential proof of cyber resilience and a key factor in coverage eligibility.

 Clean, Tested Backups Are the Key To More Affordable Cyber Insurance

When insurers assess a company’s cyber readiness, they aren’t just looking for firewalls and multi-factor authentication (MFA). They want evidence that an organization can get back on its feet quickly after an incident. That’s where backups come in. A reliable, well-tested backup strategy can make the difference between a short disruption and a multimillion-dollar loss.

A Simple, But Effective, Best Practice

The 3-2-1 rule remains one of the simplest ways to build the resilience insurers need to see. It calls for keeping three copies of data, stored on two types of media, with one copy encrypted and offline or offsite. This encrypted copy helps ensure that if it is lost or stolen, sensitive data is not exposed. U.S. cybersecurity authorities such as CISA and NIST endorse this approach because it limits data loss when a cyber incident takes place.

Encryption, too, is gaining traction. Apricorn’s 2024 Annual Survey of IT Decision Makers found that 35% of organizations encrypt stored data and 39% encrypt data in transit. That helps protect backups from unauthorized use if they are lost, stolen, or mishandled. Meanwhile, isolating backups from the network is what prevents attackers from tampering with them during a ransomware event.

A Wake-Up Call for the Cyber Insurance Industry

This heightened focus on resilience is no coincidence. Only a few years ago, the cyber insurance market was reeling from massive ransomware losses. Premiums soared, coverage narrowed, and some carriers withdrew entirely. The 2021 Colonial Pipeline breach, where a $4.4 million ransom was paid within hours, underscored how exposed U.S. infrastructure had become.

According to Swiss Re, global cyber insurance premiums doubled between 2017 and 2020, and doubled again by 2022. By 2023, about one in five insurers had dropped ransomware coverage altogether. The market has since cooled slightly, with premiums falling around 6% over the last three quarters of 2024, but the message from underwriters is clear: coverage depends on proof of preparedness.

What Insurers Are Looking For

Today, insurers expect detailed evidence that clients can respond effectively when an attack hits. That includes documentation of incident response plans, MFA implementation, and vulnerability testing. But clean, tested backups are often what determine whether a company can get coverage, or afford it.

In Apricorn’s 2024 survey, 46% of respondents said that a robust backup policy is the single most important factor in meeting cyber insurance requirements, up from 28% the prior year. That jump reflects how deeply insurers now view backups as a measure of operational and financial resilience.

When Backups Fail, So Does Recovery

Unfortunately, not all backup strategies are created equal. Apricorn’s research shows that half of IT decision-makers had to restore from backups in the last year. Of those, 25% recovered only part of their data, and 8% couldn’t recover at all. Attackers know this, which is why 89% of organizations had their backup repositories targeted in 2025, according to the Ransomware Report.

Poorly designed or untested backups don’t just slow recovery. They can void coverage or drive premiums higher. Insurers increasingly require regular backup testing and isolation controls to confirm recoverability, along with encryption and even multi-factor authentication on backup systems to confirm their integrity. These controls give underwriters confidence that the company won’t suffer a total loss, which directly affects payout risk and pricing.

The Financial Logic of Resilience

For insurers, backups are an actuarial consideration as much as a technical one. Every minute of downtime adds to potential claims, so a proven recovery process can drastically reduce financial exposure. For businesses, that translates into leverage: companies that can show resilience often qualify for better terms and lower premiums.

On the flip side, weak or outdated backup strategies leave companies paying more for less coverage. Worse, paying a ransom doesn’t guarantee success: a 2025 report found that 26.5% of companies that paid attackers never got their data back. That statistic alone makes the case for self-sufficiency through strong backups.

Looking Ahead

Cyber insurers are not just risk absorbers; they’re risk auditors. They want to see measurable proof that insureds can bounce back, not just stay safe. A multilayered backup system that includes offsite and offline copies, routine testing to verify recoverability, and encryption to protect sensitive data provides the proof they need to see. It demonstrates diligence, limits losses, and reinforces a company’s credibility in renewal discussions.

Cyberattacks will continue to evolve, but recovery is one area where businesses can stay ahead. The best time to test your backups is now, not after an attack. In the eyes of both underwriters and attackers, a verified, offline copy of your data may be the most valuable asset you have.


Kurt Markley

Profile picture for user KurtMarkley

Kurt Markley

Kurt Markley is managing director at Apricorn, which develops and provides software-free, hardware-encrypted storage platforms. 

He is a 20-year technology veteran.


 

Read More