HyperBUNKER
Physically isolated recovery for critical operations
Guides

What cyber insurers now ask about recovery

Cyber underwriters learned the hard way that "we have backups" predicts nothing about a claim. Insureds with copies still paid ransoms, because the copies died with the network or the restore took longer than the business could survive. So the questions changed.

The old question and the new ones

The old question: do you have copies of critical data? Everyone answered yes.

The new questions sound different. Could an attacker who controls your network reach your recovery copies? Could stolen administrator credentials unlock them? When did you last run a full restore, and how long did it take? Who performed it? These are answerable only with specifics, which is the point. An underwriter pricing extortion cover is pricing exactly one scenario: everything encrypted, attacker holding the keys, and the insured's ability to restart without paying.

What a good answer looks like

The strong answer names a mechanism, not a policy. A copy with no network path from production. Nothing in the domain that unlocks it. Immutability enforced by hardware rather than a setting. A restore the on-shift team rehearsed this quarter, timed in hours. That answer changes the scenario the underwriter is pricing: extortion leverage collapses when the insured can restart from a copy the attacker never touched.

The five questions, shared

The Restart Copy Test puts the underwriter's concern into five yes/no questions an insured can self-assess before the renewal conversation: path, credentials, physics, people, rehearsal. Some carriers are beginning to structure the conversation around exactly this shape; a documented pass is the difference between asserting resilience and demonstrating it.

If your renewal is coming and your honest score is under five, you have found this year's project.

Take the Restart Copy Test →

HyperBUNKER · Physically isolated recovery for critical operations · hyperbunker.com