Incident response and claims history

Are copies of BCP/DR/IR plans stored so accessible if the Applicant's network is unavailable?

A plan stored only in the environment it is meant to recover is unavailable in precisely the scenario it was written for.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking whether your plans, contact lists, and recovery procedures can be reached when your systems cannot. It is a small question with a specific and repeated failure behind it.

Why it is underwritten

In a ransomware event, file shares are encrypted, the collaboration platform may be inaccessible, and mail may be untrusted. Organisations have lost hours reconstructing contact details from memory. The carrier funds those hours.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Where the plans live is partly observable, and the useful test is whether someone can retrieve them without the corporate environment.

PlatformWhere the setting livesWhat has to be true
Plan storagePrinted copies held by key personnel and at an off-site locationCurrent printed copies, including the contact list. Attested
Microsoft 365Whether the only copy sits in SharePoint or a file shareA copy outside the primary tenant, since a tenant-level compromise removes access to everything in it
Separate tenant or providerA copy in an independent location with its own authenticationAccessible with credentials that do not depend on the compromised directory
Out-of-band communicationThe channel named in the plan and whether it is provisionedProvisioned in advance, since standing up a communication channel during an incident is slow and error-prone
CurrencyVersion and date of the offline copiesRefreshed when the plan changes, since a stale offline copy is worse than none if people trust it
Contact details are the part you will actually need

The procedures can be improvised by competent people. The phone numbers cannot. If nothing else is offline, the call tree, the carrier hotline, the forensics firm, and counsel should be, and they should be current.

What a defensible yes requires

  • A current copy exists outside the primary environment.
  • It is reachable with credentials that do not depend on the corporate directory.
  • The contact list is included and current.
  • The out-of-band communication channel is provisioned in advance.
  • Offline copies are refreshed when the plan changes.

How this answer goes wrong

The plan is in a SharePoint site described as highly available, which is true for infrastructure failure and untrue for a tenant compromise. Or printed copies exist and date from two reorganisations ago, so half the named people have left and the numbers are wrong.

Frequently asked

Is a personal cloud account acceptable?

It is better than nothing and creates its own exposure, since the plan contains sensitive detail. A separate managed tenant or a controlled physical copy is preferable.

How often should offline copies be refreshed?

Whenever the plan or the contact list changes, and at least annually. Fold it into the exercise so the copies are checked as part of the test.

What should the out-of-band channel be?

Something independent of your identity provider and mail. Provision it and tell people it exists before you need it.

Do carriers actually check this?

It rarely comes up at underwriting and it comes up immediately during a real incident, when the response either starts in ten minutes or in two hours.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture