Incident response and claims history

Does the Applicant have a written Incident Response plan?

The plan matters most in the first two hours, when nobody is thinking clearly and several irreversible decisions get made.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether a written plan exists that defines who decides, who is called, and in what order, when a security incident occurs. It expects roles, contact details, escalation criteria, and external parties including counsel, forensics, and the carrier itself.

Why it is underwritten

The first hours determine the cost of the whole event. Preserving evidence, isolating rather than rebuilding, engaging counsel early enough for privilege, and notifying the carrier within the policy window are all decisions made before anyone has a full picture. A plan is what makes those decisions the right ones by default.

Where the answer lives in Microsoft 365, Entra ID, and Azure

The plan is a document, so this is attested. Several of its dependencies are measurable, and the plan is only as good as the access it assumes.

PlatformWhere the setting livesWhat has to be true
Plan documentRoles, decision authority, escalation criteria, and contact listNamed individuals with current contact details, plus deputies. Attested
Plan documentCarrier notification step with the policy notice requirementThe carrier and the breach hotline appear in the plan, since late notice can prejudice cover
Plan documentCounsel engagement before forensicsLegal engaged first so the investigation runs under privilege where the jurisdiction allows it
Microsoft 365Whether the logging the plan relies on actually exists and is retainedConsistency between the investigative steps the plan assumes and the telemetry available
Plan documentOut-of-band communication methodA way to coordinate when mail and chat are unavailable or untrusted, which is the condition you will be in
Notify the carrier early

Policies require notice within a defined period and often require consent before engaging vendors. Organisations that appoint their own forensics firm and notify the carrier a week later can find those costs disputed. The plan should name the carrier hotline as an early step, not a closing one.

What a defensible yes requires

  • The plan names individuals and deputies with current contact details.
  • It defines who has authority to disconnect, to engage vendors, and to communicate externally.
  • It includes carrier notification and counsel engagement as early steps.
  • It specifies an out-of-band communication channel.
  • It has been read by the people named in it within the last year.

How this answer goes wrong

The plan exists and depends on a colleague who left, a phone number that changed, and a mailbox that will be unavailable in the exact scenario it addresses. The second failure is scope: a plan written for an outage rather than for a compromise, which tells people to restore quickly when the correct first action is to preserve and contain.

Frequently asked

How long should it be?

Short enough to use under pressure. A concise plan with a one-page call tree and clear authority beats a long document that nobody opens during an incident.

Should we name a forensics firm in advance?

Yes, and check whether your carrier has a panel. Using a panel firm avoids a dispute about consent at the worst moment.

What if we use a managed provider?

The plan should define what they do and what you do, including who has authority to isolate systems. That boundary is where incident response most often stalls.

Does the plan need to be offline?

A copy must be reachable when your systems are not. The separate question about plan storage exists for exactly this reason.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture