Cyber Insurance Is Getting Harder to Get: How Air-Gapped Backups Lower Your Risk

Cyber insurance is still available. But getting meaningful coverage at an affordable price is no longer automatic.

For New York business owners, insurers are asking harder questions:

  • Can your business restore critical systems after ransomware?
  • Are your backups isolated from your production network?
  • Can a compromised administrator delete or encrypt them?
  • When did you last test a full recovery?
  • Can you prove your controls with reports, policies, and test results?

If your answers are uncertain, your renewal may become more expensive: or your ransomware coverage may be restricted.

An air gapped backup strategy can help change that conversation. It gives your business a recovery copy that attackers cannot reach through the same network they have compromised. Just as importantly, it gives insurers evidence that your business can withstand a serious incident.

The cyber insurance market is changing: and your controls are under review

The market is not simply becoming more expensive across the board. In fact, the National Association of Insurance Commissioners reported that U.S. cyber insurance direct written premium fell by approximately 7% in 2024, while average rates declined in the fourth quarter.

That does not mean underwriting has become easier.

Insurers are becoming more selective about which businesses qualify, what controls they maintain, and whether policy conditions are satisfied during a claim. The NAIC also reported nearly 50,000 cyber claims in 2024, an increase of almost 40%.

The financial exposure remains substantial. The 2025 Verizon Data Breach Investigations Report found that ransomware was present in 44% of confirmed breaches. Coalition’s 2025 Cyber Claims Report recorded an average ransomware demand of $1.1 million among its policyholders in 2024.

Insurers are responding rationally. They do not want to cover a business whose only recovery plan is a connected backup that an attacker can destroy in minutes.

Your application is now a technical assessment: not a paperwork exercise.

Next step: Before your next renewal, ask your IT provider or managed service provider to map every backup copy, its network connection, its credentials, its retention settings, and its latest successful restore test.

Why connected backups are no longer enough

A traditional backup may run every night and still leave you exposed.

If the backup server is connected to your domain, reachable through the same administrator credentials, or managed from the same compromised environment, ransomware can target it. Attackers increasingly search for backup systems before encrypting production data because destroying your recovery options increases their leverage.

A typical attack might look like this:

  1. An employee’s credentials are stolen through phishing.
  2. The attacker enters your network quietly.
  3. They escalate privileges and identify servers, cloud consoles, and backup repositories.
  4. They delete backup snapshots or change retention settings.
  5. They copy sensitive data.
  6. They encrypt production systems: or threaten to publish the stolen information.
  7. Your team discovers that the “backup” is missing, corrupted, or unreachable.

The problem is not necessarily that your backup failed to run. The problem is that it was available to the attacker.

Encryption helps protect data while it is stored or transmitted. It does not automatically stop an attacker with valid credentials from deleting an online backup. For a deeper look at this distinction, read Beyond Encryption: Why Air-Gapped Backups Are Your Best Defense Against Data Exfiltration.

Ransomware blocked from reaching an isolated air-gap backup vault

What is an air gapped backup?

An air gapped backup is a copy of your data that is physically or logically separated from your production environment.

“Air gap” does not always mean a literal server with a cable disconnected by hand. It can include carefully designed controls such as:

  • Offline backup media
  • Separate storage accounts and tenants
  • Network segmentation
  • One-way backup workflows
  • Immutable object storage
  • Separate administrative credentials
  • Multi-factor authentication for backup access
  • Delayed or controlled access for restoration

The goal is straightforward: your production network must not have a direct path to destroy every recovery copy.

An air gap backup is often combined with immutability. Immutable storage uses write protection: such as object lock or WORM, meaning “write once, read many”: to prevent data from being altered or deleted during a defined retention period.

These controls solve different problems:

Control What it protects against
Encryption Unauthorized reading of backup data
Immutability Modification or deletion of stored backup data
Air gap isolation Network-based access to the backup environment
Credential separation Compromise of production administrator accounts
Restore testing The risk that a backup cannot actually be recovered

You need layers. No single backup feature is a complete disaster recovery strategy.

Why insurers value air-gapped recovery

An insurer wants to know more than whether you own backup software. It wants to understand whether your business can recover after an attacker reaches your systems.

A well-designed air gapped backup supports several underwriting priorities:

1. It reduces the chance of total backup compromise

If ransomware cannot directly access an isolated repository, it cannot simply encrypt or delete that copy through the production network.

That does not eliminate every threat. Physical security, identity management, vendor risk, and operational mistakes still matter. But it removes one of the attacker’s most valuable shortcuts.

2. It demonstrates recovery maturity

A secure backup is only useful if you can restore from it. Insurers increasingly ask for documented recovery tests, often including test dates, results, recovery time objectives, and recovery point objectives.

  • RTO means how quickly you need a system back online.
  • RPO means how much recent data you can afford to lose.

A quarterly restoration test for your critical systems is far more persuasive than a statement that says, “Backups are configured.”

3. It supports the 3-2-1-1-0 model

Many businesses know the 3-2-1 rule:

  • 3 copies of your data
  • On 2 different types of media
  • With 1 copy stored off-site

The stricter 3-2-1-1-0 approach adds:

  • 1 offline or immutable copy
  • 0 errors on your latest recovery verification

This model aligns your technical controls with the questions appearing in modern cyber insurance applications.

4. It strengthens your claim position

Your policy wording controls your coverage. Some policies include conditions related to secure, segregated, and tested backups. If your business cannot demonstrate that it followed those conditions, a claim may become more difficult.

An air gapped backup does not guarantee that an insurer will approve a claim or reduce your premium. It can, however, help you demonstrate that you took reasonable, measurable steps to protect your systems.

A practical New York scenario

Imagine a 60-person professional services firm in Westchester County. It stores client contracts, tax records, employee information, and financial documents on a central file server.

The firm has a cloud backup. However:

  • The backup console uses the same identity provider as production.
  • Administrators can delete retention policies from their normal accounts.
  • No full restore has been tested in the past year.
  • The firm cannot show its insurer which systems are covered or how long recovery would take.

At renewal, the insurer requests more information and adds a ransomware sublimit. The firm’s premium rises, but its effective protection falls.

The firm then works with a disaster recovery specialist to implement:

  • A separate, isolated air gap backup
  • Immutable retention for critical data
  • Dedicated backup administrator accounts
  • MFA and network segmentation
  • Quarterly restore testing
  • A documented ransomware recovery plan

At the next renewal, the firm can provide evidence: not assurances. Its broker can present test results, architecture diagrams, retention policies, and recovery objectives to the underwriter.

That is the difference between saying “we have backups” and proving “we can recover.”

Cyber insurance readiness checklist with immutable backup, MFA, and restore testing controls

What to prepare before your next cyber insurance application

Use this checklist now:

  • Identify your most critical applications and data.
  • Document your RTO and RPO for each critical system.
  • Confirm that at least one backup copy is offline, isolated, or immutable.
  • Separate backup administrator credentials from production credentials.
  • Require MFA for backup and cloud administration.
  • Review whether compromised domain administrators could delete backups.
  • Test restoration of files, databases, applications, and entire servers.
  • Record test dates, results, errors, and corrective actions.
  • Confirm backup retention meets your operational and policy requirements.
  • Give your broker current evidence before completing the application.

Do not wait until an attack: or a renewal deadline: to discover that your recovery plan is incomplete.

Build an insurable recovery strategy with Ron Klink

A secure air gap backup must fit your business. A law firm, manufacturer, healthcare organization, and retailer do not have the same systems, recovery priorities, compliance pressures, or budget.

Ron Klink – Disaster Recovery Solutions helps New York businesses design resilient infrastructure around their actual risks. Our approach can include cloud migration, business continuity planning, backup isolation, restore validation, and disaster recovery using platforms such as Azure Site Recovery, AWS Elastic Disaster Recovery, and IBM i Cloud Disaster Recovery.

We help you move from disconnected tools to a recovery strategy that is:

  • Designed around your critical operations
  • Protected from ransomware and credential compromise
  • Tested instead of assumed
  • Documented for internal leadership and insurers
  • Built to minimize downtime

Review our disaster recovery solutions or explore our services and products. You can also contact Ron Klink to discuss your current backup architecture and insurance requirements.

Resilient New York business infrastructure with isolated backups and cloud recovery paths

Your backup strategy now affects your insurability

Cyber insurance is not a substitute for strong security. It is a financial layer that works best when your business has practical defenses and a proven recovery plan behind it.

An air gapped backup lowers ransomware risk by protecting your last line of recovery. It can also help you answer the questions insurers are asking now: Is your data isolated? Is it immutable? Are your credentials separated? Have you tested the restore?

Your business cannot control every attack. You can control whether one compromised account becomes a total operational shutdown.

Build the air gap before you need it.

Other articles you may like