5. September 2026 · Cybersecurity

Read the Guarantee, Not the Promise

Abstract editorial header: a luminous glass shield above a dark grid, fractured and dissolving into particles at its lower edge

What four ransomware recovery guarantees actually pay, and what has to be true first

Executive Summary

Strategic context

Situation. Ransomware recovery guarantees are now offered by security vendors and backup vendors alike, with advertised ceilings from 50,000 to 10 million US dollars. They are marketed as confidence in the product and increasingly read as risk transfer.

Complication. The advertised ceiling is in every examined case a conditional maximum, and the conditions are published separately from the number, when they are published at all. Two of the four vendors examined make the actual agreement public. Two do not.

Question. What do these guarantees pay, to whom, under what conditions, and what should a buyer verify before treating one as a mitigating control?

Key findings

1. The advertised maximum is a function of spend, not of damage. Druva publishes its cap table: the advertised 10 million dollars requires annual subscription fees of at least one million dollars. A customer paying 100,000 dollars a year is capped at 750,000. So what? The number that reaches the risk register is a factor of 13 above the number in the contract for a mid-market buyer. The correct figure is knowable, and it is not the one in the headline.

2. All four reimburse expenses, not loss. Halcyon covers “recovery services”, Rubrik “expenses related to the recovery and restoration of data”, Druva “solely (and to the exclusion of all other fees, expenses, losses, settlements and damages) the reasonable and necessary fees and expenses to restore, recover, or recreate Customer Data”. So what? Business interruption, lost revenue, regulatory fines, legal fees and third-party consultants stay with the company. Those are the line items that make a ransomware incident expensive.

3. Eligibility depends on operational discipline maintained continuously, and verified only after the incident. NetApp requires the latest patch “within 60 days of availability” and AutoSupport enabled throughout. Druva requires multi-factor authentication on all accounts, IP whitelisting, a Health Check passed within 90 days, a restore target “free of any malware, bugs, back-doors”, and notification “within twenty-four (24) hours of the Discovery Time”. So what? These are conditions that lapse quietly during normal operations. Nobody discovers the lapse until the claim, which is the worst possible moment.

4. Transparency runs opposite to the strength of the claim. NetApp makes the boldest promise, “NO DATA LOSS – GUARANTEED”, and is the only vendor that publishes the sentence contradicting it: “The Guarantee is not a commitment by NetApp that Customer will experience zero data loss.” Rubrik advertises the largest number and does not publish the agreement that would let a buyer calculate their own. So what? Published terms make a vendor auditable. Unpublished terms are not a verdict against the vendor, but they are a question that must be asked before signature rather than after an incident.

5. None of these instruments is insurance, and two say so explicitly. Halcyon draws the distinction itself; NetApp’s terms state the guarantee “does not constitute insurance or an insurance contract, and does not take the place of insurance”. So what? Recording a guarantee as risk transfer overstates the residual position. It reduces neither the premium nor the exposure.

Critical recommendations

Priority Recommendation Effort Timeline
High Request the warranty agreement itself before signature; treat the product page as marketing Low Immediate
High Calculate your own cap from the published schedule instead of adopting the headline Low Immediate
High Record the guarantee as a service commitment, not as risk transfer, and quantify the remaining gap Low Next risk review
Medium Convert the eligibility conditions into monitored operational controls with named owners Medium One quarter
Medium Reconcile the guarantee with your cyber insurance policy to avoid assuming cover twice Medium Next renewal

Bottom line

These guarantees are not worthless, and the vendors are not misrepresenting them. They are service commitments with ceilings, conditions and exclusions, and they are useful when recorded as such. The ten minutes it takes to read the terms page is the highest return available anywhere in the procurement process.

Market Overview

Four vendors, four instruments, one shared shape.

Vendor Advertised maximum What it actually covers Contract public?
Halcyon 50,000 USD Recovery services, scoped to Halcyon-protected systems No
NetApp 5,000,000 USD liability ceiling Recovery of snapshots in validated SnapLock Compliance volumes Yes
Rubrik 10,000,000 USD Expenses related to recovery and restoration No
Druva 10,000,000 USD Recovery and security incident expenses, capped by spend tier Yes

The spread looks like a market with meaningfully different offers. Read against the underlying documents, the differences narrow considerably, because three of the four numbers are ceilings that most customers cannot reach and all four instruments reimburse the same narrow category of cost.

Comparing vendors on the headline figure compares marketing decisions, not coverage. The comparable quantity is the cap that applies to your own spend and configuration, and for two of these four it cannot be determined from public documents at all.

Finding 1: The number is a function of what you spend

Druva is the only vendor in the set that publishes the arithmetic. Section 4 of the Data Resiliency Guarantee Agreement (V.3, 21 February 2023) sets the payment cap by annualised subscription fees:

Annual subscription fees Payment cap
25,000 to 49,999 USD 100,000 USD
50,000 to 99,999 USD 250,000 USD
100,000 to 249,999 USD 750,000 USD
250,000 to 499,999 USD 2,000,000 USD
500,000 to 999,999 USD 4,500,000 USD
1,000,000 USD and above 10,000,000 USD

The advertised maximum requires the customer to be spending a million dollars a year. There is also a floor: below 25,000 dollars annually there is no guarantee at all, and the subscription must run at least 36 months.

Rubrik states the same principle without the numbers. Its page carries “$10M” in display type and, in small type beneath, “Maximum warranty available dependent on volume of data protected. Refer to warranty agreement for more information.” The agreement is not published. A buyer cannot calculate their own figure from anything Rubrik makes public.

That asymmetry deserves care rather than accusation. Rubrik’s real figure is not knowable from outside, which is precisely why it should be asked for in writing. It should not be assumed to be low.

For any guarantee, the question “what is our cap” has a specific numeric answer that depends on our contract. If the vendor cannot produce it before signature, that is the answer.

Finding 2: Expenses, not loss

The scope language is remarkably consistent across all four, and it is narrower than the marketing implies.

Druva is the most explicit, and the exclusion list is the useful part. Recovery Incident Expenses cover “the reasonable and necessary fees and expenses to restore, recover, or recreate Customer Data”, and explicitly not: any ransom payment, third-party restoration attempts on a Druva platform, the cost of recreating environments not replicated to Druva, attorney’s fees, or third-party consultant or expert fees.

There is a further procedural condition that is easy to miss and hard to satisfy under incident conditions: expenses qualify only if “incurred by Customer after obtaining Druva’s prior written approval to procure such services” and paid to a third party “pre-approved in writing by Druva”.

In the hours after an incident, an organisation calls the responders it has on retainer. Under this clause, doing so without written pre-approval can put the expense outside the guarantee. That is a runbook change, not a contract detail.

Finding 3: The conditions are continuous, and tested only at claim time

NetApp’s terms make eligibility contingent on patch discipline (“within 60 days of availability”), AutoSupport being enabled at all times, and operation strictly in accordance with the documentation. Any lapse voids the guarantee. The term itself runs twelve months from a validation date, and each further year requires a new paid professional services engagement.

Druva’s Requirements section reads like a control baseline: multi-factor authentication on all user accounts, SSH key-based CLI authentication with passphrase-protected keys, least-privilege roles, encryption at rest and in transit, IP whitelisting limiting connections to customer-owned networks, data lock enabled in customer policies, and a Health Check completed and passed within the first 90 days. The customer must also warrant that the systems being restored to are “free of any malware, bugs, back-doors or other malicious code”.

Then the clock: notification “within twenty-four (24) hours of the Discovery Time” via a specific incident report form, and a reimbursement request within two months of confirmation.

Every one of these is a condition that can lapse without anyone noticing: an MFA exception granted for a service account, a patch deferred through a change freeze, a firewall rule widened during a migration. The guarantee is not tested when it lapses. It is tested during the worst week the organisation has had in years.

Finding 4: The most transparent vendor makes the boldest claim

NetApp headlines “NO DATA LOSS – GUARANTEED”. Its published terms state: “The Guarantee is not a commitment by NetApp that Customer will experience zero data loss.”

Both sentences are NetApp’s. The second is not hidden; it is in a public document linked from the first. The same document discloses that only newly purchased arrays qualify (“Eligible Arrays do not include Customer’s existing systems or arrays”), that SAN workloads are excluded from qualifying workloads entirely, and that recovery “does not guarantee that data within the Snapshot may not be corrupted or encrypted prior to being vaulted”.

That last exclusion is the one that matters technically. Ransomware operators routinely dwell in an environment for weeks before triggering encryption. A guarantee that the snapshot can be restored, without any assurance about what is inside it, addresses the mechanism of recovery and not its outcome.

Publication is the differentiator worth rewarding in a vendor evaluation. NetApp’s claim is the most overstated of the four and its disclosure is the most complete, which means it can be assessed. That combination is preferable to a modest claim with no published terms.

Finding 5: Not insurance, and two vendors say so

Halcyon draws the line itself: “Cyber insurance policies provide financial protection against a wide range of cyber risks through complex underwriting and claims processes. The Halcyon Ransomware Warranty is different.”

NetApp’s terms are equally direct: the guarantee “is not intended to constitute an offer to insure, does not constitute insurance or an insurance contract, and does not take the place of insurance obtained or obtainable by the Customer”.

Druva’s agreement makes no insurance claim, and it does not disclaim one either. The absence should not be read in either direction.

A guarantee recorded in the risk register as transferred risk overstates the position. It belongs there as a service commitment with a known ceiling, alongside an explicitly quantified remaining exposure.

Implications for Executives

Three consequences follow, and none of them is “avoid vendors who offer guarantees”.

The guarantee is a procurement artefact, not a security control. It changes who pays for part of the recovery effort. It does not change the probability of an incident or the time to recover from one. Evaluating the product and evaluating the guarantee are separate exercises and should not be run together.

The conditions are an operating burden that someone has to own. Continuous MFA coverage, patch windows, a passed health check and a 24-hour notification path are real obligations. If nobody owns them, the guarantee quietly stops applying, and the first evidence of that is a declined claim.

The residual exposure has a number, and it should be written down. Take the applicable cap, subtract it from a realistic incident cost including business interruption and legal, and record the difference. That figure is the honest content of the slide that currently says “recovery guaranteed”.

Recommendations

Recommendation Rationale Owner Effort
Request the warranty agreement before signature and read the cap clause Two of four vendors do not publish it; the marketing page cannot answer the question Procurement Low
Calculate the cap that applies to your own spend tier Druva’s schedule shows a factor-of-13 gap between headline and mid-market reality Finance and CISO Low
Record the instrument as a service commitment, and quantify the remaining exposure Neither instrument is insurance and two vendors say so Risk Low
Turn eligibility conditions into monitored controls with named owners Conditions lapse silently and are verified only at claim time Security operations Medium
Add the pre-approval clause to the incident runbook Calling your own responders first can put the cost outside the guarantee Incident response Low
Reconcile the guarantee against the cyber policy before renewal Avoids assuming the same exposure is covered twice Risk and insurance Medium

Executive Dashboard

Question Answer from the documents Confidence
Is the advertised figure the figure we would receive? No, in every examined case it is a conditional maximum High
Can we calculate our own figure? Only for Druva and NetApp; not from public Rubrik or Halcyon documents High
Does it cover business interruption or fines? No, all four reimburse recovery expenses only High
Does it cover ransom payment? No, explicitly excluded where the contract is published High
Is it insurance? No; two vendors state this explicitly High
Can it lapse without us noticing? Yes, all published conditions are continuous obligations High
What is the typical real cap? Determinable only per contract; Druva’s schedule is the only public arithmetic Medium

Appendix: Methodology

Research type. Primary document analysis of four vendor guarantee offerings.

Frameworks applied. SCQA for framing; a comparative document analysis across four vendors, using the vendor’s own contractual language as the unit of evidence.

Frameworks considered and not applied. Porter’s Five Forces, BCG Growth-Share Matrix, Value Chain Analysis and PESTEL were all considered and rejected. This study examines the content of contractual instruments, not industry structure, portfolio allocation, cost structure or macro-environment. Applying them would have produced sections with no evidentiary basis. Technology Adoption Curve was rejected for the same reason: adoption rates for these guarantees are not published by any of the four vendors and could not be sourced.

Sources and quality. Six documents, all retrieved directly on 5 September 2026 and all A-tier in the sense that matters here: they are the primary instruments themselves, not descriptions of them. Interest is not neutral in any case, since all six are vendor publications. That is the point of the method: each finding rests on a vendor’s own words against that vendor’s own headline, which requires no third-party corroboration.

netapp.com, docs.netapp.com and rubrik.com all answer automated retrieval with HTTP 403, so those pages were opened in a browser session. Druva’s agreement was retrieved as PDF and read in full.

Confidence by section. Findings 1 through 5: high, each rests on verbatim contractual language. Market overview: medium, because two of four contracts are not public and the comparison is therefore incomplete by construction.

Limitations.

  1. Four vendors are not the market. AvePoint, Dell, Veeam, Commvault and others offer comparable instruments that were not examined.
  2. NetApp’s terms document is dated May 2024 and Druva’s agreement is V.3 dated 21 February 2023, while both marketing pages are current. Newer versions may exist that are not published at the examined URLs.
  3. Halcyon’s and Rubrik’s contractual mechanics could not be assessed at all, because neither publishes the agreement.
  4. All figures are US dollars and subject to currency conversion, which matters for a European buyer.

What could not be answered. Whether any of these guarantees has ever paid out, at what value, and how often claims are declined. No vendor publishes claims data, and none of the four documents requires them to. Any assessment of practical value rather than contractual scope would require that data.

One figure deliberately not used. Halcyon’s page opens with “an average of 22 days to restore operations after a ransomware attack” and names no study, sample or date. It may well be accurate. It is not evidence until the source is read, and repeating it would reproduce the error this article is about. For the same reason, secondary reporting suggesting a per-terabyte sliding scale for Rubrik is recorded as a research lead only and is not used.

Update trigger. Re-examine when any vendor revises its terms document, and extend to the vendors listed under limitation 1.

Frequently Asked Questions

Does this mean the guarantees are worthless?

No. A guaranteed incident response team inside 120 minutes has real value, and so does a contractually reviewed, validated recovery configuration. The error is in the accounting, not in the product. Record it as a service commitment with a ceiling, not as risk transfer.

Our vendor is not among the four. Does the finding still apply?

The mechanism does: an advertised maximum, conditions published elsewhere, and reimbursement scoped to recovery expenses. Whether the specific numbers apply can only be answered from that vendor’s own agreement, which is exactly the point of the article.

Why were Porter’s Five Forces, a BCG Matrix or a PESTEL analysis not used?

Because they answer questions this study does not ask. Porter describes industry structure, BCG portfolio allocation, PESTEL the macro-environment. This is an analysis of the content of contractual instruments. Applying those frameworks would have produced sections with no evidentiary basis, which the method used here explicitly avoids.

Why only four vendors?

Because four could be examined against primary documents in the available time. AvePoint, Dell, Veeam, Commvault and others offer comparable instruments and were not examined. This is stated as a limitation rather than hidden.

Can we simply ask the vendor for our cap?

Yes, and that is recommendation one. Ask in writing, before signature, for the warranty agreement and the payout schedule that applies to your contract value. Two of the four vendors here publish it. If a vendor will not, that answer is itself informative.

Does a recovery guarantee replace cyber insurance?

No, and two of the four vendors say so in their own words. NetApp’s terms state the guarantee “does not constitute insurance or an insurance contract”, and Halcyon draws the distinction on its own page.

What is the single most useful action after reading this?

Take your applicable cap, subtract it from a realistic incident cost including business interruption and legal fees, and write the difference into the risk register. That number is the honest content of the slide that currently reads “recovery guaranteed”.

Sources

  1. NetApp, Ransomware Recovery Guarantee marketing page. Retrieved 5 September 2026.
  2. NetApp, Ransomware Recovery Guarantee Terms and Conditions, dated May 2024. Retrieved 5 September 2026.
  3. NetApp, ONTAP Autonomous Ransomware Protection documentation. Retrieved 5 September 2026.
  4. Halcyon, platform warranty page. Retrieved 5 September 2026.
  5. Rubrik, Ransomware Recovery Warranty page. Retrieved 5 September 2026.
  6. Druva, Data Resiliency Guarantee Agreement, V.3, 21 February 2023. Retrieved 5 September 2026.