Incident response and claims history

Does the Applicant have a written Business Continuity Plan / Disaster Recovery Plan, tested annually?

Incident response handles the attack. Continuity handles the business while the attack is being handled, and carriers ask about both because they fund both.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether written continuity and recovery plans exist and are tested annually. Continuity covers how the business keeps operating without its systems; disaster recovery covers how the systems come back. They are related and separate, and organisations frequently have one.

Why it is underwritten

Business interruption cover pays for the period when operations are degraded. How long that lasts, and how much can continue manually, is determined by continuity planning. An insured that can process orders on paper for three days has a materially smaller claim than one that stops entirely.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Plans and test records are attested. The recovery objectives they state should be grounded in measurements from restore testing.

PlatformWhere the setting livesWhat has to be true
Plan documentsBusiness impact analysis identifying critical processes and their toleranceProcesses ranked by impact over time, which is what makes recovery order defensible
Plan documentsRecovery time and recovery point objectives per systemObjectives grounded in measured restore times rather than aspirations
Plan documentsManual workarounds for critical processesDocumented alternatives for operating without systems, which is the continuity half
Test recordsAnnual test, its scope, and findingsA dated test that exercised something meaningful. Attested
DependenciesThird-party and supply chain dependencies in the planVendor outages included, since a critical provider failing is as disruptive as your own systems failing
Objectives without measurements are wishes

A stated four-hour recovery time objective is a target. The restore test tells you the actual figure. When the two differ by a factor of five, the plan is describing an outcome the infrastructure cannot deliver, and the gap surfaces during the event rather than before it.

What a defensible yes requires

  • Both continuity and recovery are addressed, not one standing for both.
  • A business impact analysis identifies critical processes and their tolerance for downtime.
  • Objectives are grounded in measured recovery times.
  • Manual workarounds exist for the processes that cannot stop.
  • An annual test has taken place with a record and findings.

How this answer goes wrong

The disaster recovery plan is detailed and the continuity plan does not exist, so there is no answer to how the business operates during the outage. Or the plans assume a data centre failure while the realistic scenario is encryption across the estate, where the recovery site is encrypted too because it replicated faithfully.

Frequently asked

Is one combined document acceptable?

Yes, provided both dimensions are covered. Carriers care about the content rather than the document count.

How does ransomware change the plan?

Substantially. Traditional disaster recovery assumes the primary site failed and the replica is good. Ransomware compromises both, which is why recovery from immutable backup, not failover, is the relevant path.

What counts as a test?

Anything that exercises the plan against a scenario with the people involved. A full failover is ideal and a tabletop with a documented outcome is acceptable.

Should suppliers be included?

Yes. A critical vendor outage is a continuity event you do not control, and it is increasingly the scenario that materialises.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture