Team protected by digital shield from disaster outside, celebrating secure cloud data backup and IT safety.

What Should Be Included in a Disaster Recovery Plan for an Insurance Agency?

July 29, 2026

How Should an Insurance Agency Prepare for an IT Disaster?

An insurance agency’s disaster recovery plan should define how the business will restore its people, systems, applications, communications, and data after a cyberattack, hardware failure, internet outage, natural disaster, or human error.

For an agency with 25–50 employees, the plan should identify its most critical services, establish acceptable recovery times, assign responsibilities, protect backup copies, document alternative work procedures, and test the recovery process at least annually.

A complete plan should answer two measurable questions for every important system:

  • Recovery Time Objective: How long can the system remain unavailable?
  • Recovery Point Objective: How much recent data can the agency afford to lose?

For example, an agency may decide that email should be restored within four hours with no more than one hour of data loss, while a less critical archive may tolerate a 24-hour recovery period.

The goal is not to eliminate every interruption. The goal is to reduce confusion, protect client information, maintain essential services, and restore normal operations within a timeframe the agency has already approved.

The 8-Part Disaster Recovery Framework

  1. Identify critical business services and systems.
  2. Set recovery time and data-loss targets.
  3. Document technology, vendors, and dependencies.
  4. Implement protected and monitored backups.
  5. Create recovery procedures for each major scenario.
  6. Assign roles and communication responsibilities.
  7. Establish temporary business-continuity procedures.
  8. Test, measure, and update the plan.

Each part supports the others. Backups are essential, but backups alone do not tell employees where to work, how to contact clients, who can approve emergency purchases, or which system should be restored first.

1. Identify the Agency’s Critical Business Services

Start by identifying the activities that must continue for the agency to serve clients and protect the business.

Critical insurance agency functions may include:

  • Receiving and responding to client calls
  • Accessing policy and account information
  • Processing endorsements and renewals
  • Supporting claims communication
  • Communicating with carriers
  • Sending and receiving email
  • Accessing shared documents
  • Processing payments and accounting transactions
  • Obtaining quotes
  • Supporting remote employees
  • Maintaining regulatory and business records

Rank these functions by business impact. The agency should restore the systems supporting urgent client service before restoring tools used only for occasional administrative work.

Use a Business Impact Assessment

For each business function, document:

  • The employees who perform it
  • The technology required
  • The vendors involved
  • The information needed
  • The effect of a 2-hour outage
  • The effect of an 8-hour outage
  • The effect of a 24-hour outage
  • The effect of a multi-day outage
  • Any legal, contractual, or client obligations
  • Available temporary workarounds

This assessment turns a general goal such as “restore everything quickly” into a prioritized recovery sequence.

2. Establish Recovery Time and Data-Loss Targets

Every important system should have an approved recovery target. Without those targets, an IT provider cannot design the appropriate backup, availability, and recovery solution.

Recovery Time Objective

The recovery time objective, or RTO, is the maximum acceptable period that a system can remain unavailable after an interruption.

Example recovery targets might include:

System or Service Example Recovery Time Objective
Microsoft 365 email 1–4 hours
Agency-management system access 1–4 hours
Internet connectivity 1–4 hours with a temporary alternative
VoIP phone service 1–4 hours with call forwarding
Shared documents 4–8 hours
Accounting systems 4–24 hours
Historical archives 24–72 hours

These are planning examples, not universal requirements. Each agency should establish targets based on business needs, technical design, budget, and risk.

Recovery Point Objective

The recovery point objective, or RPO, defines the maximum acceptable amount of recent data loss, measured in time.

For example:

  • An RPO of 15 minutes means the recovery process should lose no more than approximately 15 minutes of recent data.
  • An RPO of four hours means work completed since the most recent four-hour backup may need to be recreated.
  • An RPO of 24 hours may be appropriate only for information that changes infrequently.

More aggressive recovery targets generally require more frequent backups, additional infrastructure, cloud replication, or specialized recovery technology.

Balance Recovery Expectations With Cost

Restoring every system within minutes may be technically possible, but it may not be financially practical. The agency should reserve the fastest and most resilient recovery methods for the systems that create the greatest business impact.

3. Document Systems, Vendors, and Dependencies

A recovery plan is unreliable when it depends on information stored only inside the unavailable system. Maintain current documentation in a protected location that authorized decision-makers can access during an outage.

Technology Inventory

Document:

  • Desktop computers and laptops
  • Servers and virtual systems
  • Firewalls, switches, and wireless equipment
  • Internet connections
  • Telephone and VoIP systems
  • Printers and scanners
  • Backup appliances
  • Remote-access systems
  • Mobile devices used for business

Application Inventory

Include:

  • Microsoft 365
  • Exchange Online
  • SharePoint
  • OneDrive
  • Microsoft Teams
  • Applied Epic
  • AMS360
  • HawkSoft
  • EZLynx
  • Vertafore applications
  • Carrier portals
  • Accounting and payment systems
  • Document-management platforms
  • Electronic signature services
  • Client communication tools
  • Website and domain services

Dependency Mapping

A business application may depend on several supporting services. For example, employees may be unable to use a cloud-based agency platform if the office internet, Microsoft 365 identity, multi-factor authentication, DNS, or firewall is unavailable.

For each critical service, identify dependencies such as:

  • Internet connectivity
  • Electrical power
  • Microsoft 365 authentication
  • Domain and DNS services
  • Firewall and network access
  • Vendor availability
  • Local servers
  • Remote-access platforms
  • Employee devices
  • Telephone service

Vendor Contact Information

Maintain current contact details for:

  • The managed IT provider
  • The cyber insurance carrier or breach hotline
  • The insurance broker
  • Legal counsel
  • Internet providers
  • VoIP provider
  • Agency-management software vendors
  • Microsoft licensing provider
  • Backup provider
  • Website and domain provider
  • Hardware vendors
  • Building management
  • Electric utility

Store important account numbers, support procedures, and authorized contacts with this information.

4. Implement Protected and Monitored Backups

Backup is the foundation of disaster recovery, but the agency must know what is protected, how frequently it is copied, who monitors failures, and whether restoration has been tested.

What Should Be Backed Up?

Review protection for:

  • Servers
  • Shared file systems
  • Microsoft 365 email
  • SharePoint
  • OneDrive
  • Microsoft Teams data supported by the backup platform
  • Agency-management data where appropriate
  • Accounting information
  • Critical workstation files
  • Network and firewall configurations
  • Website files and databases
  • Important cloud applications

Do not assume a cloud application automatically provides the retention and restoration capability the agency requires. Each cloud vendor should be evaluated separately.

Use Multiple Backup Layers

A resilient backup strategy commonly includes:

  • A primary production copy
  • A separate backup copy
  • An offsite or cloud-based copy
  • A copy protected from routine modification or deletion

The specific design depends on the system, but the agency should avoid keeping every recovery copy connected to the same accounts, network, and administrative credentials.

Protect Backups From Ransomware

Ransomware operators may attempt to delete or encrypt backup data before attacking production systems. Backup security should include:

  • Separate administrative credentials
  • Multi-factor authentication
  • Restricted access
  • Encryption
  • Protected or immutable retention where appropriate
  • Alerting for unusual deletion or configuration changes
  • Independent monitoring
  • Documented recovery procedures

Monitor Every Backup Job

A failed backup should create an alert that is reviewed and resolved. The monitoring process should identify:

  • Missed backup jobs
  • Incomplete backups
  • Storage capacity issues
  • Offline devices
  • Authentication failures
  • Corrupted data
  • Unexpected retention changes

Review backup and recovery options through 911 IT’s business continuity services.

5. Create Recovery Procedures for Major Disaster Scenarios

A single generic recovery checklist is not sufficient because different incidents require different decisions, technical actions, and communication.

At minimum, create procedures for the following scenarios.

Ransomware or Cyberattack

  1. Report the incident immediately.
  2. Disconnect or isolate affected devices.
  3. Preserve logs and evidence.
  4. Contact the cyber insurance carrier according to the policy.
  5. Notify legal counsel and agency leadership.
  6. Determine which accounts, systems, and data are affected.
  7. Contain unauthorized access.
  8. Validate that backups are clean and available.
  9. Prioritize system recovery.
  10. Reset credentials and strengthen access controls.
  11. Monitor for continued attacker activity.
  12. Document actions and decisions.

Do not begin deleting files, rebuilding systems, or contacting an attacker without coordinating with authorized technical, legal, insurance, and leadership resources.

Microsoft 365 Account Compromise

  1. Disable or block the affected account.
  2. Revoke active sessions.
  3. Reset the password through a verified process.
  4. Review registered MFA methods.
  5. Inspect mailbox forwarding and inbox rules.
  6. Review delegated mailbox access.
  7. Examine sign-in and audit logs.
  8. Identify messages sent by the attacker.
  9. Search for related phishing messages in other mailboxes.
  10. Determine whether sensitive information was accessed.
  11. Notify appropriate parties.

Server or Hardware Failure

  1. Confirm the failed component and business impact.
  2. Determine whether repair, replacement, or failover is fastest.
  3. Verify the latest usable backup.
  4. Restore the most critical services first.
  5. Test application access and permissions.
  6. Confirm that backup protection resumes after restoration.
  7. Document replacement and warranty information.

Internet Outage

The continuity plan may use:

  • A secondary internet connection
  • Mobile hotspots
  • Remote work from approved locations
  • Call forwarding
  • Cloud applications accessed from another location
  • Temporary use of agency-managed laptops

The plan should identify which employees receive priority access when temporary bandwidth is limited.

Power Outage

Document:

  • Battery backup capacity
  • Safe server and network shutdown procedures
  • Building access restrictions
  • Remote-work activation procedures
  • Employee communication methods
  • Equipment restart order
  • Testing after power is restored

Office Inaccessibility

A fire, flood, weather event, building problem, or public-safety restriction may prevent employees from entering the office even when cloud systems remain available.

The plan should identify:

  • Which employees can work remotely
  • Whether employees have agency-owned laptops
  • How phone calls will be redirected
  • How mail and physical documents will be handled
  • Where leadership will coordinate operations
  • How employees will receive status updates

Loss of a Cloud Application

Cloud vendors can experience outages. For each critical cloud application, document:

  • The vendor’s support process
  • How the agency verifies the outage
  • Whether data can be exported
  • Whether an offline workflow exists
  • How client requests will be recorded temporarily
  • How temporary records will be entered after service returns

6. Assign Recovery Roles and Decision Authority

Employees should know who has authority to make decisions during an incident. Waiting for an unavailable executive can delay containment, recovery, and communication.

Suggested Recovery Roles

Role Primary Responsibilities
Executive incident leader Approves major business decisions, spending, shutdowns, and external communication.
Technical recovery lead Coordinates containment, restoration, testing, and vendor activity.
Operations coordinator Manages employee assignments, temporary processes, and business priorities.
Communication lead Provides approved updates to employees, clients, carriers, and vendors.
Legal and insurance coordinator Works with counsel, the insurance carrier, the broker, and required outside parties.
Documentation coordinator Records decisions, actions, timing, expenses, and recovery results.

Small agencies may assign several roles to one person. Each role should still have a named backup in case the primary person is unavailable.

Define Approval Limits

The plan should state who may authorize:

  • Emergency hardware purchases
  • Temporary cloud services
  • After-hours technical work
  • Office closure
  • Remote-work activation
  • Client notifications
  • Vendor and legal engagement
  • Cyber insurance claims

7. Establish Temporary Business-Continuity Procedures

Disaster recovery focuses on restoring technology. Business continuity focuses on maintaining essential operations while restoration is underway.

Temporary Communication

The agency should have alternatives for:

  • Employee alerts
  • Leadership coordination
  • Client calls
  • Carrier communication
  • Vendor support
  • Emergency status updates

Do not rely entirely on Microsoft 365 email to distribute instructions during a Microsoft 365 outage.

Temporary Client-Service Procedures

When the agency-management system or shared files are unavailable, employees may need an approved method to record:

  • Client names and contact details
  • The time of the request
  • The requested policy or claim action
  • Any commitments made
  • The employee responsible for follow-up
  • The information that must be entered after recovery

Temporary records must be protected appropriately and entered into the normal system after service is restored.

Remote-Work Readiness

A remote-work continuity plan should confirm:

  • Employees have suitable computers
  • Devices are encrypted and managed
  • Multi-factor authentication is active
  • Employees can access approved cloud applications
  • Phone calls can be redirected
  • Home internet limitations are understood
  • Employees know how to request support
  • Confidential information can be handled privately

Manual Workarounds

Some business functions may continue temporarily through controlled manual procedures. Document which procedures are permitted, who approves them, how records will be protected, and how the information will be reconciled later.

8. Test the Disaster Recovery Plan

A plan that has never been tested is a collection of assumptions. Testing reveals missing passwords, outdated contacts, undocumented systems, inaccessible backups, unclear responsibilities, and unrealistic recovery targets.

Four Types of Recovery Testing

  1. Documentation review: Confirm that contacts, systems, vendors, and procedures remain current.
  2. Tabletop exercise: Walk decision-makers through a realistic incident.
  3. Component restoration test: Restore a file, mailbox, database, server, or application.
  4. Full recovery exercise: Simulate the loss of a major system or location and validate end-to-end recovery.

What to Measure

For each test, record:

  • The system or scenario tested
  • The test date
  • The people involved
  • The backup or recovery method used
  • The time required to begin recovery
  • The time required to restore service
  • The amount of data recovered
  • Any errors or missing information
  • Whether the RTO and RPO were achieved
  • Required corrective actions
  • The person responsible for each correction

Test More Than the Backup

A server may restore successfully but remain unusable because DNS, authentication, firewall rules, application licenses, or vendor connections are missing. Recovery testing should validate the complete business service, not only the raw data.

How Often Should an Insurance Agency Test Recovery?

The testing schedule should match the importance and rate of change of each system.

Recovery Activity Suggested Planning Frequency
Backup-job monitoring Daily
File or mailbox restoration Monthly or quarterly
Critical server or application recovery At least annually
Incident response tabletop exercise At least annually
Contact and vendor-list review Quarterly
Employee remote-work readiness review At least annually and after major staffing changes
Full disaster recovery plan review Annually and after major technology changes

An agency with aggressive recovery targets, frequent system changes, or elevated risk may require more frequent testing.

Disaster Recovery Versus Business Continuity

Area Disaster Recovery Business Continuity
Primary focus Restoring technology and data Maintaining essential business operations
Typical questions How will systems be recovered? How will employees serve clients during the interruption?
Key activities Backup restoration, rebuilding systems, recovering applications Remote work, call forwarding, manual procedures, client communication
Primary participants IT provider, technical teams, vendors Leadership, operations, employees, IT, legal, communications
Success measure Systems meet recovery targets Critical services continue at an acceptable level

A complete resilience program requires both. Restoring technology quickly is valuable, but the agency must also know how to operate while recovery work is still underway.

Common Disaster Recovery Mistakes

Mistake Potential Result
Assuming cloud services do not need backup Deleted, corrupted, or altered information may not be recoverable as expected.
Keeping every backup under the same credentials An attacker may compromise production data and recovery copies.
Monitoring backup completion without testing restoration The agency may discover recovery failures during an actual emergency.
Setting no recovery priorities Technical teams may restore less important systems before critical services.
Storing the only plan on the main server The plan may be inaccessible during the incident.
Leaving responsibilities undefined Decisions and communication may be delayed.
Ignoring phone and internet continuity Employees may recover applications but remain unable to communicate.
Forgetting remote employees Remote devices and workflows may not be included in recovery testing.
Failing to update the plan Outdated vendors, systems, accounts, and contacts may slow recovery.
Testing only technical restoration Employees may not know how to continue business operations.

A Practical Recovery Scenario for a 40-Person Insurance Agency

Consider a 40-person independent insurance agency using Microsoft 365, a cloud-based agency-management system, VoIP phones, one local file server, and a combination of office and remote employees.

The agency identifies the following priorities:

  • Email must be available within four hours.
  • The agency-management system must be accessible within two hours.
  • Client phone calls must be redirected within one hour.
  • Shared files must be restored within eight hours.
  • Accounting can tolerate a 24-hour interruption.

During a recovery assessment, the agency discovers:

  • The file server is backed up, but no recent full restoration test has been completed.
  • Microsoft 365 data is not covered by a separate backup system.
  • The VoIP call-forwarding process is undocumented.
  • Three remote employees do not have agency-owned laptops.
  • The incident contact list contains outdated information.
  • The disaster recovery plan is stored only on the file server.

The agency creates a 60-day improvement plan:

  1. Perform a full file-server recovery test.
  2. Add appropriate Microsoft 365 data protection.
  3. Document VoIP call-routing procedures.
  4. Issue managed laptops to critical remote employees.
  5. Update vendor and emergency contacts.
  6. Store protected copies of the recovery plan in multiple locations.
  7. Conduct a ransomware tabletop exercise.
  8. Measure the results against the approved recovery targets.

The agency now has a tested recovery process instead of relying on assumptions about its backups and vendors.

Questions to Ask an IT Provider About Disaster Recovery

  1. Which systems and cloud services are currently backed up?
  2. How frequently does each backup run?
  3. How long is data retained?
  4. Where are backup copies stored?
  5. How are backups protected from ransomware?
  6. Who monitors backup failures?
  7. When was the last successful restoration test?
  8. Can you restore one file, one mailbox, one server, and an entire environment?
  9. What are our current recovery time objectives?
  10. What are our current recovery point objectives?
  11. Which systems would be restored first?
  12. Who has authority to approve a disaster declaration?
  13. How would employees work if the office were unavailable?
  14. How would telephone calls be redirected?
  15. What happens during a Microsoft 365 outage?
  16. How do you coordinate with our cyber insurance carrier?
  17. Where is our recovery documentation stored?
  18. How often do you conduct tabletop exercises?
  19. Which recovery services are included in our monthly agreement?
  20. Which recovery events or projects may create additional charges?

Insurance Agency Disaster Recovery Checklist

  • Critical business functions have been ranked.
  • Every critical system has an approved recovery time objective.
  • Every critical data source has an approved recovery point objective.
  • Technology, applications, and vendors are documented.
  • System dependencies have been mapped.
  • Servers and shared files are backed up.
  • Microsoft 365 recovery needs have been evaluated.
  • Important cloud applications have been reviewed.
  • Backup failures are actively monitored.
  • Backup credentials are protected separately.
  • Recovery copies are protected from ransomware.
  • File, mailbox, and system restoration have been tested.
  • Ransomware response procedures are documented.
  • Internet and telephone alternatives are documented.
  • Remote-work procedures have been tested.
  • Recovery roles and backup personnel are assigned.
  • Vendor and emergency contacts are current.
  • The plan is available outside the primary network.
  • A tabletop exercise has been completed within the last year.
  • Corrective actions from the latest test have been completed.

Frequently Asked Questions

What is the difference between backup and disaster recovery?

Backup creates recoverable copies of data. Disaster recovery is the complete process for restoring systems, applications, access, and operations after an interruption.

What is a recovery time objective?

A recovery time objective is the maximum acceptable period that a system can remain unavailable. It helps determine the technology, staffing, and cost required for recovery.

What is a recovery point objective?

A recovery point objective is the maximum acceptable amount of recent data loss, expressed as time. It determines how frequently information should be protected.

Does Microsoft 365 need a separate backup?

Microsoft provides availability and retention capabilities, but those features may not meet every agency’s recovery requirements. The agency should evaluate separate protection for Exchange Online, SharePoint, OneDrive, and Teams data.

How often should backups run?

The schedule should match the agency’s recovery point objectives. Critical data may require protection every few minutes or hours, while less frequently changed information may be backed up daily.

How often should recovery be tested?

File and mailbox recovery may be tested monthly or quarterly, while critical server and full disaster recovery exercises should generally occur at least annually. Higher-risk systems may require more frequent testing.

Can an agency rely entirely on cloud systems for disaster recovery?

Cloud systems can improve resilience, but they still depend on internet access, user identities, vendor availability, configurations, and data-protection settings. The agency should document recovery and continuity procedures for each service.

What happens if the office loses internet service?

The continuity plan may use a secondary internet connection, mobile hotspots, approved remote work, call forwarding, or access from another location. The agency should test these alternatives before an outage.

Should the disaster recovery plan include cyber insurance?

Yes. The plan should include the insurer’s breach hotline, policy number, reporting requirements, broker contact, and procedures for coordinating technical response with legal and insurance resources.

Who should own the disaster recovery plan?

Agency leadership should own the business decisions and recovery priorities. A qualified IT provider should design, operate, document, and test the technical recovery process.

How much does disaster recovery cost?

Cost depends on the number of systems, data volume, backup frequency, retention, recovery targets, required availability, cloud services, testing, and support. Faster recovery and lower acceptable data loss generally require greater investment.

Can disaster recovery prevent all downtime?

No. Disaster recovery reduces the duration and impact of an interruption. Business continuity procedures help the agency continue essential operations while systems are being restored.

Build Recovery Around Measurable Business Priorities

A dependable disaster recovery plan should do more than confirm that backup software is installed. It should establish which services matter most, how quickly each one must return, how much data loss is acceptable, who makes decisions, and how employees will continue serving clients during the interruption.

Use the eight-part framework:

  1. Identify critical business services.
  2. Set measurable recovery targets.
  3. Document systems and dependencies.
  4. Protect and monitor backups.
  5. Create scenario-specific procedures.
  6. Assign roles and decision authority.
  7. Establish temporary operating procedures.
  8. Test and improve the plan.

Review the plan whenever the agency adds a location, changes IT providers, adopts a new application, replaces a server, changes telephone systems, completes an acquisition, or prepares for cyber insurance renewal.

911 IT provides business continuity and disaster recovery services, managed IT services, cybersecurity services, and cloud services for organizations that need dependable backup, recovery, monitoring, and technology support.

Not sure whether your agency could recover from ransomware, server failure, or a prolonged outage? Schedule a discovery call with 911 IT to review your backups, recovery targets, Microsoft 365 protection, continuity procedures, and testing schedule.