You are reading Part 8 of our 12-part Insurance Agency Authority Series.
Insurance agencies should prepare for ransomware and disaster recovery by defining recovery priorities, maintaining protected backups, testing restoration, documenting response roles, and separating basic backup from true business continuity planning. For agencies with 15 to 30 employees, a practical plan should identify which systems must return first, how long the agency can tolerate downtime, who contacts the cyber insurance carrier, and how employees will work during recovery. Backups should be monitored continuously and tested on a defined schedule. A backup that has never been restored is not a complete recovery strategy.
The 6-Part Ransomware and Recovery Framework
A complete plan should address:
- Risk assessment
- Recovery priorities
- Backup design
- Business continuity
- Incident response
- Testing and documentation
Each area supports a different part of the recovery process.
1. Identify the Agency’s Most Critical Systems
The agency should list the systems required to operate.
Common priorities include:
- Agency management system
- Microsoft 365
- Client documents
- Shared files
- Carrier portals
- Internet access
- Phone systems
- Accounting software
- Scanning and document management
- Remote access
- Identity systems
Leadership should classify each system based on business impact.
For example:
Tier 1 – Immediate Priority
Systems required to communicate, access client records, and continue core service.
Tier 2 – High Priority
Systems needed within the same business day.
Tier 3 – Important but Delayed
Systems that may be restored after critical operations stabilize.
This prioritization gives the provider a clear recovery sequence.
2. Define Recovery Time and Recovery Point Goals
Recovery Time Objective
How quickly a system should be restored after an outage.
Recovery Point Objective
How much recent data the business can afford to lose.
For example:
- A four-hour recovery time objective means the agency wants the system operational within four hours.
- A one-hour recovery point objective means the agency can tolerate losing no more than one hour of data.
These goals influence backup frequency, technology choices, cost, and recovery design.
An agency that can tolerate two days of downtime needs a different solution from one that must resume operations within two hours.
3. Build Protected, Monitored Backups
A strong backup strategy should include:
- Automated backup
- Monitoring
- Encryption
- Separate storage
- Retention policies
- Protection from ransomware
- Recovery testing
- Clear ownership
The agency should know:
- Which systems are backed up
- How often backups run
- How failures are handled
- Where copies are stored
- How long data is retained
- Who receives alerts
- When the last successful recovery test occurred
Unified device backup and Datto SaaS Protection may address parts of the environment.
The agency should also determine whether Microsoft 365 data requires separate protection rather than relying only on Microsoft platform availability.
4. Understand the Difference Between Backup and BCDR
Backup preserves data.
Business Continuity and Disaster Recovery is designed to restore operations.
BCDR may include:
- Faster recovery
- Local and cloud copies
- Image-based backup
- Virtualization
- Recovery orchestration
- Business continuity planning
- Regular testing
- Defined recovery procedures
BCDR is available as an a la carte service and should be explicitly accepted or declined.
If declined, leadership should acknowledge the operational risk.
A basic backup may be acceptable for some systems. Critical systems may require a more advanced approach.
5. Create a Ransomware Incident Response Plan
A ransomware plan should identify:
- Who declares an incident
- Who contacts the IT provider
- Who notifies leadership
- Who contacts the cyber insurance carrier
- Who coordinates legal counsel
- Who communicates with employees
- Who communicates with clients
- Who preserves evidence
- Who approves restoration
- Who documents decisions
The first technical steps may include:
- Isolate affected systems
- Disable compromised accounts
- Preserve logs and evidence
- Determine the scope
- Contact the carrier when appropriate
- Confirm backup status
- Establish recovery priorities
- Restore systems safely
- Monitor for reinfection
- Document the event
The agency should not improvise these roles during a crisis.
6. Test the Plan
A recovery plan should be tested.
Testing may include:
- File restoration
- Mailbox restoration
- Server image recovery
- Application validation
- Tabletop exercises
- Communication drills
- Vendor contact reviews
- Recovery time measurement
- Documentation updates
A test should answer:
- Did the backup work?
- Was the data complete?
- How long did recovery take?
- Were credentials available?
- Did employees know what to do?
- Were vendor contacts current?
- Did recovery meet the business objective?
Ransomware Prevention Still Matters
Recovery planning does not replace prevention.
Insurance agencies should also maintain:
- EDR
- Patch management
- Email security
- Security awareness training
- MFA
- Conditional access
- Administrative account separation
- Monitoring
- Dark web credential monitoring
- Microsoft 365 management
A modern cybersecurity stack reduces the likelihood that ransomware reaches critical systems and improves visibility when suspicious activity occurs.
Cyber Insurance Requirements
Cyber insurance applications often ask about:
- MFA
- EDR
- Backups
- Recovery testing
- Incident response
- Employee training
- Patch management
- Administrative access
- Business continuity
The agency should answer accurately and preserve evidence.
Cyber insurance renewal preparation should include documented backup, recovery, and incident response controls.
How Much Downtime Can an Agency Tolerate?
Leadership should estimate the impact of downtime on:
- Client communication
- Policy servicing
- New business
- Claims support
- Employee productivity
- Carrier relationships
- Revenue
- Reputation
- Regulatory obligations
Consider a 25-employee agency where each employee loses eight productive hours.
That equals:
- 200 lost employee-hours
- Delayed client service
- Interrupted sales activity
- Potential overtime during recovery
- Additional technical and vendor costs
The true cost is usually greater than the direct labor loss.
Example – Ransomware Readiness for a 29-Employee Agency
A 29-employee agency in Midland relies on:
- Microsoft 365
- A cloud agency management platform
- Local shared files
- One physical server
- Remote employees
- Scanning systems
The agency has backups but no documented recovery priorities.
A readiness project identifies:
- The local server is critical to document access
- Microsoft 365 data needs separate protection
- No recent restoration test exists
- Incident contacts are outdated
- Employees do not know how to report suspicious activity
- The cyber insurance carrier contact is not documented
The improvement plan includes:
- Define Tier 1 systems
- Set recovery objectives
- Improve backup monitoring
- Test restoration
- Review BCDR
- Update the incident response plan
- Train employees
- Conduct a tabletop exercise
The agency gains a clearer path to recovery and better cyber insurance readiness.
Regulatory Compliance and Recovery
Regulatory compliance may require the agency to protect data availability, integrity, and confidentiality.
Recovery planning can support this by providing:
- Documented backups
- Access controls
- Retention standards
- Incident records
- Recovery procedures
- Vendor information
- Testing evidence
- Leadership review
Recovery capability should be aligned with legal, contractual, and insurance requirements.
What Happens When BCDR Is Declined?
A client may choose not to purchase BCDR.
The business should understand the consequences, which may include:
- Longer downtime
- Slower server recovery
- Limited recovery options
- Greater dependence on hardware replacement
- Higher operational risk
- Potential gaps in insurance expectations
- Greater productivity loss
Declining the service may be a valid business decision, but the risk should be acknowledged.
Questions to Ask an IT Provider
Ask:
- Which systems are backed up?
- How often do backups run?
- Who monitors failures?
- Where are copies stored?
- Are backups isolated from ransomware?
- When was the last restoration test?
- What is the estimated recovery time?
- What does BCDR add?
- Who contacts the cyber insurance carrier?
- How are incidents documented?
- What recovery work is included?
- Which services are optional?
Recovery and the Five-Year Technology Strategy
Recovery requirements should be reviewed as the agency grows.
New employees, locations, applications, and data volumes can change
- Backup capacity
- Recovery time
- Storage needs
- Network requirements
- Security controls
- Vendor dependencies
- Business continuity priorities
A growing insurance agency should include disaster recovery and business continuity in its five-year technology strategy.
Ransomware and Recovery Checklist
Confirm:
- Critical systems are identified
- Recovery priorities are documented
- Backup frequency is appropriate
- Backup failures create alerts
- Copies are protected from ransomware
- Microsoft 365 data is addressed
- Recovery testing is documented
- BCDR has been evaluated
- Incident roles are assigned
- Carrier contact information is current
- Employees know how to report suspicious activity
- Legal and compliance contacts are identified
- Recovery objectives are reviewed annually
Conclusion
Insurance agencies should prepare for ransomware by combining prevention, protected backups, business continuity planning, incident response, and regular testing. The agency should know which systems must return first, how much downtime it can tolerate, and who makes decisions during recovery.
For agencies in Midland, Odessa, Fort Stockton, and the surrounding Permian Basin, a tested recovery plan can reduce confusion, limit downtime, and protect client service during a serious incident.
Explore managed services that combine proactive security, backup monitoring, recovery planning, and technology alignment.


