Home/Questions/Backup and recovery/Ransomware recovery time
Backup and recovery

Estimated time to restore essential functions in widespread ransomware attack?

This number feeds directly into the business interruption calculation, so it is one of the few answers on the form with an immediate price attached.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking how long it would take to restore essential functions if a substantial part of the estate were encrypted at once. Not one server. The realistic, simultaneous, everything-at-once case, including the time to establish a clean recovery point, rebuild infrastructure, and validate before reconnecting.

Why it is underwritten

Business interruption is frequently the largest component of a ransomware claim, and it is calculated from the outage duration. The carrier uses your estimate to size the waiting period and the limit. An estimate that is optimistic by a factor of three does not reduce your loss; it means the policy was structured around a scenario that did not happen.

Where the answer lives in Microsoft 365, Entra ID, and Azure

This is an estimate, and the way to make it defensible is to derive it from measurements rather than from confidence. Insurance Posture does not measure recovery time, so this is attested.

PlatformWhere the setting livesWhat has to be true
Test recordsMeasured elapsed time from your restore testsActual durations per system class, which is the only grounded input to the estimate
Recovery planThe order of restoration and its dependenciesIdentity and directory services first, then core infrastructure, then applications. A plan that restores applications before their dependencies produces serial rework
CapacityRestore throughput of your storage and network pathTotal data volume divided by achievable throughput, which usually dominates the estimate and is often overlooked
Recovery planStaffing assumptions, including the case where the incident begins on a Friday nightWho does the work, and whether the plan assumes people who may be unavailable
Retained servicesIncident response retainer and its response timeTime to engage forensics, since you generally cannot restore before scope is understood
The estimate people give is usually the single-server time

Restoring one server takes hours. Restoring an estate takes days, because throughput is shared, dependencies serialise, and nothing starts until forensics has established a clean point. A defensible answer accounts for all three.

What a defensible yes requires

  • The number is derived from measured restore times rather than from an impression.
  • It includes time to establish a clean recovery point, not only time to copy data.
  • It accounts for shared throughput when many systems restore at once.
  • Dependencies are ordered, so identity and core services come first.
  • The figure is reviewed after each restore test, so it tracks the estate rather than the plan.

How this answer goes wrong

Optimism dominates, and it is rarely dishonest. The estimate is built from the time to restore one system, multiplied loosely, without the forensic hold at the start or the validation at the end. Organisations that have lived through a real event report durations several times their pre-event estimate, and the gap is almost always in those two bookends.

Frequently asked

Does a longer estimate hurt our submission?

It affects the business interruption structure and it does not, by itself, make you uninsurable. An honest longer number that leads to correctly sized cover is better than a short one that leaves you underinsured at the moment of loss.

What is essential functions?

Define it yourself, on the form. Name the systems and the service level you mean. Underwriters read a defined scope as a sign the number came from analysis.

Should we include the forensic hold?

Yes. You generally cannot restore into production before the scope of compromise is understood, and that hold is real elapsed time in every recovery.

How does this relate to our recovery objective?

The objective is the target and this answer is the realistic measurement. Where they differ, the difference is the work to be done, and stating both is a strong position.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture