Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Cybersecurity whitepaper | Insurance

Incident Response Planning for Insurance Agencies

A practical plan for the first hours after a cyber incident at your agency

  • Published September 25, 2026
  • 4 min read

Any agency can face a security incident, from a hijacked mailbox to a locked server. Incident response planning decides whether that day becomes a short disruption or a long crisis. This guide walks through a plan that fits a small or midsize agency.

Why incident response planning matters for agencies

Agencies carry unique obligations when something goes wrong. For example, you may owe notices to clients, carriers, and your state insurance department. Also, your cyber policy likely has rules about who you call first.

Without a plan, people improvise under stress. They may wipe a laptop that held key evidence, or email clients before counsel reviews the facts. A written plan replaces guesswork with clear steps.

In addition, many state insurance data security laws based on the NAIC model require licensees to keep a written incident response plan. Confirm the details for your states with counsel.

Carriers you represent may have expectations too. Some agency agreements require you to tell the carrier promptly when its policyholder data is involved, so check those contracts before you need them.

Build your response team

Name the people who will act, along with a backup for each role. Small agencies can combine roles, but every task needs an owner.

  • Incident lead. Usually the principal or operations manager, who makes final decisions.
  • IT contact. Your internal IT person or managed IT provider, who contains and investigates.
  • Insurance contact. The person who reports the claim to your cyber carrier.
  • Legal counsel. Often a breach coach assigned through your cyber policy.
  • Communications lead. The person who handles staff, client, and carrier messages once counsel approves.

Keep this contact list on paper and on a personal phone, too. If email goes down, you still need to reach everyone.

Know your first calls

The first hour sets the tone. Therefore, your plan should list the exact order of calls, with phone numbers.

First, call your cyber insurance carrier’s claims hotline. Many policies require prompt notice and expect you to use their panel vendors for forensics and legal help. Hiring your own firm first could create coverage problems, so read your policy now.

Next, bring in your IT provider to contain the problem. Then, with guidance from counsel, decide on notices to carriers, regulators, and clients. Some states set short deadlines to notify the insurance commissioner, so the clock matters.

Write playbooks for likely scenarios

A general plan helps, but short playbooks for common incidents help even more. Each one should fit on a page or two.

  1. Compromised mailbox. Reset the password, revoke sessions, remove malicious inbox rules, and review what the attacker saw.
  2. Ransomware. Disconnect affected devices from the network, but do not power them off or wipe them.
  3. Lost or stolen laptop. Confirm encryption, lock or wipe it remotely, and reset the user’s credentials.
  4. Fraudulent payment request. Call the bank right away, then preserve the emails for investigators.
  5. Vendor breach. Get details from the vendor, identify affected clients, and review your contract terms.

Preserve evidence and document everything

Investigators need logs, emails, and system images to learn what happened. However, those records disappear fast if someone cleans up too early. So instruct staff to report problems and leave systems alone until IT arrives.

Keep a simple incident log from the first minute. Record who noticed what, when each call happened, and every decision you made. This log helps with insurance claims, regulator questions, and your own review later.

Also, check that your systems keep logs long enough to matter. Microsoft 365 audit logs, firewall logs, and endpoint alerts all help investigators rebuild the timeline.

Test the plan with a tabletop exercise

A plan that sits in a drawer will not hold up under pressure. Instead, run a tabletop exercise at least once a year. Walk your team through a realistic scenario, such as a CSR’s mailbox sending fake invoices to clients.

During the exercise, ask practical questions. Who calls the carrier, and where is the policy number? How do you reach staff if Teams is down?

Each gap you find becomes an action item. Then update the plan and share the new version with the whole team.

How WEBIT helps

WEBIT helps agencies write practical incident response plans and run tabletop exercises with the whole team. When an incident happens, our help desk and security team work alongside your carrier’s forensic and legal partners. Every managed device also runs Zero Trust EDR, which helps contain threats early.

For deeper visibility, our managed SIEM add-on collects and keeps the logs that investigators need. Explore our cybersecurity services or contact us to review your current plan.

Key takeaways

  • Incident response planning turns a chaotic day into a set of known steps.
  • Call your cyber carrier first and follow your policy’s vendor requirements.
  • Write short playbooks for mailbox takeover, ransomware, lost devices, and payment fraud.
  • Preserve evidence, keep an incident log, and test the plan every year.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Insurance IT services

See how WEBIT supports insurance organizations across Chicagoland.

Explore Insurance IT →

More Insurance whitepapers

Browse the full library of guides for your industry.

All Insurance whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.