Insurers ask because modern ransomware attacks often target backups first. If attackers can delete your backups using stolen administrator credentials, they can encrypt your systems and leave you with little option but to pay the ransom.
We also will cover which backup methods don't qualify, what to ask your IT provider before completing your renewal, and what to do if the answer is no.
An immutable backup cannot be altered or deleted for a fixed period, even by your IT provider or someone using stolen administrator credentials. This protection is enforced by the backup platform itself, often using technologies such as Object Lock or Write Once, Read Many (WORM) storage. While terminology varies between vendors, the principle is the same: once written, the backup cannot be changed until the retention period expires.
A NAS or permanently connected external drive can usually be accessed using the same network credentials as the rest of your environment. If ransomware reaches your network, it can often encrypt or delete these backups too.
Microsoft 365 retention policies are not a replacement for a dedicated backup. An attacker with Global Administrator access may still be able to remove data or compromise your recovery options. If you rely solely on Microsoft's built-in retention features, the honest answer to the insurance question is usually no.
Many cloud backup platforms support immutability, but it isn't always enabled by default. Simply using a reputable backup provider doesn't mean your backups are immutable—you need to verify the feature has been configured correctly.
Before completing your renewal, ask:
An untested backup should never be assumed to work when it's needed most.
In many cases, immutability can be enabled on your existing backup platform without replacing the software. If your IT provider can't clearly explain how your backups are protected or answer the questions above, it's worth investigating before your next renewal. Whatever you do, don't tick Yes unless you're certain your backups meet the requirements. Cyber insurance applications form part of your policy, and inaccurate information could allow an insurer to reject or invalidate a future claim.
Paying a slightly higher premium is far less costly than discovering your policy won't pay out after a ransomware attack.

























