← All Articles

July 18, 2026

Backup Requirements for Cyber Insurance: What Carriers Look For

Alongside MFA and EDR, backups round out the trio of controls that cyber insurance carriers scrutinize most. The reason is simple: when ransomware succeeds, your backups determine whether the incident is a bad week or an existential event — and whether the carrier is looking at a contained claim or a catastrophic one.

But “we have backups” means very different things at different businesses, and questionnaires have gotten specific about the difference.

What carriers typically ask about

Modern questionnaires tend to probe four dimensions:

  • Coverage — Are you backing up the data that actually matters? Business files, line-of-business databases, email, and cloud data — not just whatever happens to sit in one folder.
  • Separation — Are backups isolated from the systems they protect? Attackers deliberately seek out and encrypt or delete backups they can reach. A backup drive permanently connected to the same network is exactly what they hope to find. Carriers look for offline, offsite, or immutable copies.
  • Encryption — Are backup copies encrypted, both in transit and where they’re stored?
  • Testing — Have you actually restored from backup recently? An untested backup is a hope, not a control, and “when did you last test a restore?” is now a common question.

The pattern that fails questionnaires

The most common small-business setup — an external drive or network share receiving nightly copies, never tested, always connected — technically counts as “having backups” and fails almost every dimension above. It’s worth being honest with yourself about which setup you have before a claims adjuster is the one evaluating it.

A practical checklist

  1. Inventory what would hurt to lose — files, databases, email, cloud application data.
  2. Follow a 3-2-1 pattern — multiple copies, multiple media, at least one offsite or immutable.
  3. Verify separation — at least one copy that ransomware on your network could not reach.
  4. Test a restore — quarterly is a reasonable cadence for most small businesses; document that it happened.
  5. Keep evidence — backup logs and a note of your last successful restore test belong with your application records.

How this connects to endpoint security

Backups and endpoint security answer different questions. Backups answer “how do we recover?” Endpoint detection and response answers “how do we catch it early enough that recovery stays small?” Carriers ask about both because they work together: managed EDR with 24/7 monitoring can help contain an incident to one machine instead of every machine — which is also the difference between restoring one endpoint and restoring the company.

PC Vax provides the endpoint side — managed EDR, continuous monitoring, and managed response — and our readiness reviews help identify whether backups are one of the areas needing attention before your renewal.

Read more in our Cyber Insurance Readiness overview, or see what MFA requirements actually mean.

PC Vax provides cybersecurity services, not insurance advice. Requirements vary by carrier, policy, and applicant, and PC Vax does not guarantee insurance eligibility, approval, coverage, or premiums.


Professional Cybersecurity. Made Simple.

Get Protected