Why Backups Alone No Longer Satisfy Insurers or Clients

Rodney Hall, COO

A sealed steel vault door beside a toppled stack of cardboard boxes spilling papers on a concrete floor.

Backup and BCDR operations changed in 2026 because two separate audiences started asking the same question: can you prove recovery, not just claim it. Cyber insurers now underwrite on tested restores, and ransomware crews now target the backup itself, so "we have backups" stopped being an answer either group accepts.

What Actually Changed in Backup Operations This Year?

The shift is from having backups to proving they work under pressure. Omdia's 2026 survey of 700 IT decision makers across the US, UK, Ireland, France, and the DACH region found that 93 percent call absolute immutability critical to ransomware protection, yet only 16 percent actually have it in place. That gap between what operators know they need and what they have deployed is the story of the year.

The same survey found 83 percent of organizations suffered a successful ransomware attack in the past two years, up from 66 percent in 2024. Recovery outcomes moved the wrong direction too. Only 39 percent of affected organizations recovered at least 75 percent of their data, down from 57 percent in 2024. Attacks are climbing and recoveries are getting worse at the same time, which means whatever most environments were doing to prepare is losing ground against how attackers now operate.

For an MSP, that trend line is a direct margin threat, not an abstract industry statistic. A client whose recovery falls short after an incident does not blame the ransomware operator first. They call the provider who told them backups were handled, and the conversation that follows determines whether that account stays, downgrades, or leaves entirely once the contract renews.

Why Is Recovery Getting Harder Even With More Backup Tools on the Market?

Recovery is getting harder because attackers now treat the backup as the primary target, not an afterthought. Ransomware operators actively hunt for backup repositories, delete snapshots, and try to corrupt retention chains before they ever trigger the encryption payload. A backup that can be altered or deleted by an attacker with elevated access is not a backup, it is a delayed liability.

That is why immutability, true write-once-read-many storage that no credential can overwrite, has moved from a nice-to-have to the baseline conversation with every client. An MSP running conventional replicated storage without an immutable layer is defending the same attack surface it was defending five years ago, against an adversary that has specifically adapted to beat it.

The cost of getting this wrong is not evenly distributed either. NIST's federal continuity standard, SP 800-34, sets a benchmark of restoring mission-essential functions within 12 hours and full systems within 30 days. Few small business clients hold themselves to a federal bar, but the gap between that standard and what most SMB environments actually rehearse is a useful gut check. If your team cannot say, with a tested number, how long a full recovery would take for a client's core file server or line-of-business application, you do not have a recovery time objective. You have a hope.

Backup and Recovery Is Still Your Most Universal Managed Service

Kaseya's 2026 State of the MSP Report, based on responses from more than 1,000 MSPs worldwide, found that 79 percent of providers offer backup and recovery as a managed service, making it the single most universally delivered capability in the industry. Half of MSPs reported year-over-year revenue growth in business continuity and disaster recovery specifically, trailing only cybersecurity's 71 percent growth rate.

That combination matters operationally. Backup is close to universal, which means most of your client base is already paying for it, but the bar for what counts as adequate delivery keeps rising underneath that existing revenue. Clients are not asking you to sell them backup for the first time. They are asking, increasingly through their insurance broker, whether the backup you already sold them actually works.

That distinction changes how you should evaluate your own stack. A platform that reports a completed backup job every night can still leave you exposed if it cannot produce a documented restore test or an immutable copy on demand. Reviewing your current product lineup against what insurers and clients now expect is a faster path to closing the gap than adding another monitoring layer on top of a foundation that was never rebuilt for this threat model.

What Are Cyber Insurers Actually Requiring Now?

Insurers are requiring documented proof of tested recovery, not a statement that backups exist. Underwriters have shifted from checkbox questionnaires to evidence-based validation, and most MSP-related cyber insurance applications now concentrate on five control areas: multifactor authentication on email, remote access, and admin accounts, endpoint detection on every device, tested offline or immutable backups, a written incident response plan, and completed security awareness training.

The backup control specifically now expects a demonstrated restore test cadence with documented outcomes, commonly quarterly for the systems a client cannot operate without. A client's broker can reasonably ask an MSP: when was the last restore test performed, and can you produce the record. If the honest answer is that backups run nightly but nobody has restored from one in a year, that gap is now underwriting risk, not just an operational shortcut.

What used to satisfy a client or insurerWhat satisfies them in 2026
Backup jobs completing on scheduleImmutable storage the backup vendor's own credentials cannot alter
A monitoring dashboard showing green checkmarksA documented restore test with a recorded outcome
A general statement that data is backed upA defined recovery time and recovery point per system tier

Building This Into the Operational Model, Not the Sales Pitch

The practical fix is operational before it is commercial. Recovery testing needs to be a scheduled, staffed activity with a named owner, not something a technician does when a client specifically requests proof. Tier your clients' systems by how fast they need to come back, document the actual recovery time you hit in the last test against that target, and keep that record somewhere you can hand to a broker or an auditor without a scramble.

This is a staffing and skills question as much as a tooling one. A technician who understands immutable storage architecture, retention chain integrity, and how to run a clean restore test under time pressure is a different asset than one who only knows how to confirm a backup job status. Building that bench through structured training, rather than hoping it gets absorbed on the job, is how you close the gap between the 93 percent who know immutability matters and the 16 percent who have actually operationalized it. Forge University exists for exactly that kind of skills gap, turning backup and recovery competence into something you can certify and staff against rather than something you hope survives a technician's departure.

Pricing the Reality, Not the Legacy Line Item

Backup has historically been priced as a commodity add-on because it used to be one. It no longer fits that model once immutable storage, documented restore testing, and insurer-facing reporting are part of the deliverable. Providers who keep pricing backup like a $10-a-seat afterthought while quietly absorbing the labor cost of quarterly restore tests are giving away the exact work that would justify a package upgrade.

Auditing what your current stack actually delivers against what clients and their insurers now expect is the starting point. A stack built around clear tooling choices makes it easier to see where your BCDR delivery has real gaps versus where it is simply under-documented, which is often the cheaper problem to fix.

Backup and BCDR are not becoming a bigger part of the managed services conversation because vendors are pushing new features. They are becoming a bigger part of the conversation because the two parties checking your work, attackers and underwriters, both got more specific about what "recovered" actually means. See the full stack to see how the pieces fit together for your own delivery model.

Sources: Object First-sponsored Omdia research on immutable backup adoption | Kaseya 2026 State of the MSP Report.

Why Backups Alone No Longer Satisfy Insurers or Clients | Actiforge Blog