Insurers Now Reward Tested Backups, Not Just Backups

Rodney Hall, COO

A lighthouse beam cutting through fog toward a small boat, one clear path visible across dark water.

Backup and recovery is now one of the fastest-growing service lines for MSPs, but insurers are the ones proving why testing cadence matters more than backup existence. Ransomware losses fell sharply for businesses with tested, verified recovery capability in 2025, while most organizations still test disaster recovery only monthly or less. Closing that gap is now an operational job, not a checkbox.

What do the 2026 numbers actually show about BCDR?

Backup and recovery has become a core growth line inside MSP service catalogs, not a commodity add-on. According to Kaseya's 2026 State of the MSP Report, 79 percent of MSPs now offer backup and recovery as a managed service. The same report found that 41 percent identify it as a core revenue source, and half of MSPs offering it reported year-over-year revenue growth in the category, second only to cybersecurity services.

At the same time, Datto's State of BCDR Report 2025 surveyed more than 3,000 IT professionals about their backup and recovery practices. More than 60 percent of organizations believed they could recover from an incident in under a day, but only 35 percent actually did. Testing frequency tells a similar story: daily verification of both backup jobs and full disaster recovery capability is the exception rather than the norm, and a meaningful share of organizations test on a monthly cadence or less.

Put those two data sets together and the operational picture is clear. Revenue and client demand for BCDR are climbing faster than actual test discipline is improving. That gap is exactly where an MSP's operational maturity now gets priced, by clients and increasingly by insurers.

The baseline for what counts as adequate is not a guess. CISA's #StopRansomware Guide recommends maintaining offline, encrypted backups and testing the availability and integrity of those backups regularly in a disaster recovery scenario. The guide treats regular recovery testing as a required control, not an optional add-on, which puts the weak Datto testing-frequency findings above in a harsher light than a vendor survey alone would.

Why are insurers now the ones enforcing backup discipline?

Because claims data is showing them it works. Coalition's 2026 Cyber Claims Report found that initial ransom demands surged 47 percent year over year in 2025, yet a record 86 percent of businesses refused to pay, and 64 percent of closed claims were resolved with no out-of-pocket loss to the policyholder. Coalition attributes that resistance directly to improved backups and tested incident response plans, alongside insurer-supported negotiation, even as ransomware remained its most expensive claim type at an average loss of $269,000 per incident.

That is a direct, dollar-denominated signal that tested recovery capability changes claim outcomes, not just downtime. Underwriters are responding by asking harder questions before binding or renewing a policy: not just whether backups exist, but when they were last restored successfully and whether that restore was documented. An MSP that can hand a client dated, evidence-backed restore logs on renewal day is doing something that directly affects the client's premium and coverage terms, which makes it a service worth pricing on its own line item.

This also changes who the MSP is really answering to on backup and recovery. It used to be enough to satisfy the client. Now the client's insurance broker and underwriter are effectively a second audience, one that wants dated evidence rather than a verbal assurance that everything is fine. An MSP that has not adjusted its BCDR reporting for that second audience is leaving a renewal conversation to chance that a documented testing program would have settled in advance.

How should this change the way MSPs structure BCDR as a service?

Treat testing cadence as the deliverable, not backup software as the deliverable. Clients already assume backups exist. What they cannot assume, and what the Datto findings show most MSPs are not yet proving, is that a restore actually works within the timeframe the client's risk tolerance requires.

That means building a standing operational cadence, not a one-time setup: scheduled restore tests tied to each client's tier, a dated log of pass or fail outcomes, and a documented escalation path when a test fails. This is process work, closer to what a good onboarding or provisioning workflow requires than what a backup vendor's dashboard hands you by default. Standardizing that cadence across a client base is the same operational discipline MSPs already apply to onboarding checklists, which is why tools built for repeatable operational workflows, like Actiforge's Catalyst, are a natural fit for turning ad hoc backup checks into a documented, repeatable, billable process rather than something a technician remembers to do when time allows.

What should a client actually see for their money?

A client paying for managed BCDR should receive three things on a predictable cycle: a test date, a pass or fail result tied to their agreed recovery time objective, and a plain explanation of what changes if the result was a fail. Anything less than that is selling backup software, not managed recovery.

What clients often getWhat tested BCDR should include
A backup exists confirmation emailA dated restore test result against their RTO
Annual disaster recovery reviewMonthly or quarterly restore tests by tier
Vendor dashboard accessA documented remediation step after any failed test

This is not about running every client through daily full-environment restores, which is not realistic for most books of business. It is about matching test frequency to the tier of risk a client is actually carrying, and being able to show, not just claim, that the match holds.

Does this actually move the revenue needle, or just reduce risk?

Both, based on where the market is already moving. The Kaseya findings above show BCDR revenue growing faster than most other service lines already, which means the demand side of this is not something MSPs need to create. What is missing, per the Datto testing-frequency numbers, is proof of delivery on the recovery promise clients are already paying for.

MSPs that can show insurers and clients a documented testing cadence are positioned to charge for BCDR as a distinct managed line rather than bundling it invisibly into a flat-rate contract. That distinction matters at renewal time for both the client's cyber policy and the MSP's own services agreement, since both now hinge on the same evidence: can you prove the restore worked, and when.

There is also a retention argument underneath the revenue one. A client who receives a dated restore-test report every quarter has tangible proof of value each time it lands, in a way a line item on an invoice never delivers on its own. That report is also the easiest artifact to point to when a competing MSP tries to win the account on price alone, since price comparisons get harder once a client has evidence their current provider's recovery promise actually holds up under test conditions.

Where to start if your testing cadence is not there yet

Start with an honest inventory of your current client base against the Datto testing-frequency benchmarks above. Most MSPs will find some clients on a real cadence and others running on assumptions inherited from years-old contracts. Fixing that gap client by client, with a documented schedule and a place to log every result, is the operational work that turns backup and recovery from a line item clients tolerate into one they renew specifically because of.

A tool like Actiforge's Stack Builder can help you map where BCDR testing cadence fits alongside your existing onboarding and operations tooling, and where a white-labeled operational layer would close the gap faster than building the tracking yourself. From there, the full Actiforge product catalog shows the pieces that support that kind of standardized, repeatable service delivery across a whole client book.

If your BCDR line is growing revenue but you cannot hand a client a dated restore log on demand, that is the operational gap worth closing first. See the full stack to find the tooling that makes tested recovery a documented, repeatable part of how you run the business, not a promise you hope holds up.