Earlier quoted context omitted.
Did the business follow best security practices? Did it do its due diligence to harden against attacks? Why should insurers pay, when businesses have no incentive to do this?
If you follow security best practices, you have append-only backups that you can use to restore the encrypted data and don't need insurance at all...
Maybe go two weeks' back and you'll get a clean instance, but that's two weeks' data loss, I've seen (non-tech) institutions hit where an hour of data loss is worth paying a ransom for.