Business Continuity & Cyber Resilience: Preparing to Recover, Not Just Prevent

Business Continuity & Cyber Resilience: Preparing to Recover, Not Just Prevent

Craig Hangartner

NavaJeevan Rajaiah

Every security program is built to prevent incidents, but preparation for prevention isn't the same as preparation for recovery. In P&C insurance, where claims processing and policy servicing can't simply pause during a disruption, the ability to recover quickly from a ransomware attack, system failure, or other cyber incident has become as important as the controls meant to stop one from happening in the first place.

For CISOs, business continuity and cyber resilience require a different mindset than prevention-focused security. The core question shifts from "how do we stop this" to "when this happens, how fast can we recover, and how do we know our recovery plan actually works." Immutable backups, disaster recovery automation, cyber recovery testing, and well-rehearsed incident response playbooks are what separate a carrier that recovers in hours from one that's still reconstructing systems weeks later.

Why Recovery Planning Deserves Equal Weight to Prevention

A few realities make recovery preparedness a distinct, necessary focus alongside prevention:

No prevention program is airtight. Even mature security programs experience incidents. Planning as though prevention will always succeed leaves an organization unprepared for the recovery phase when it inevitably doesn't.

Ransomware specifically targets backups. Modern ransomware attacks increasingly attempt to identify and encrypt or delete backup systems before executing the primary attack, meaning traditional backups aren't a guaranteed fallback unless they're specifically protected against this tactic.

Recovery time directly affects business impact. In insurance, claims processing, policy issuance, and customer service can't tolerate extended downtime without real financial and reputational consequences. Recovery speed is itself a business continuity metric, not just a technical one.

Untested recovery plans often fail when actually needed. A disaster recovery plan that hasn't been tested under realistic conditions frequently reveals gaps, missing dependencies, outdated procedures, unavailable personnel, only when it's actually invoked during a real incident.

Legacy systems complicate recovery. Older core systems may not have modern backup and recovery tooling built in, requiring recovery planning to account for systems that weren't designed with current resilience practices in mind.

Why Immutable Backups Matter Specifically Against Ransomware

Traditional backups assume that if primary systems are compromised, the backup remains a safe, unaffected copy to restore from. Modern ransomware attacks specifically challenge this assumption by targeting backup infrastructure directly, attempting to encrypt, delete, or otherwise render backups unusable before the ransom demand is made.

Immutable backups address this by making backup data unchangeable and undeletable for a defined retention period, even by administrators with otherwise privileged access. This means that even if an attacker compromises credentials with broad access, the immutable backup remains intact and restorable, closing the gap that standard backup approaches leave open.

What Cyber Resilience Actually Requires

Four practices need to work together to build genuine cyber resilience, not just a documented disaster recovery plan:

Immutable backups. Backup data protected against modification or deletion for a defined period, specifically designed to withstand an attacker who has already gained privileged access to the environment.

Disaster recovery automation. Automated failover and recovery processes that reduce recovery time and eliminate the risk of manual errors during the high-pressure conditions of an actual incident, when speed and accuracy both matter.

Cyber recovery testing. Regular, realistic testing of recovery procedures, not just confirming backups exist, but actually executing a recovery process to validate that it works within the expected timeframe and produces a usable, correct result.

Incident response playbooks. Documented, specific procedures for different incident types, ransomware, data breach, system failure, that guide the response team through clear steps rather than requiring the process to be figured out in real time during an active incident.

Testing deserves particular emphasis here. A backup strategy that's never been tested through an actual recovery exercise is a plan with unknown reliability. Organizations that discover gaps in their recovery process during a real incident, rather than during a planned test, pay for that discovery in extended downtime and increased impact.

Why Legacy Modernization Intersects With Resilience Planning

Legacy systems often carry resilience gaps that aren't obvious until a recovery is actually attempted. Older core systems may lack modern backup integration, have poorly documented dependencies, or require specialized institutional knowledge to restore correctly, knowledge that's increasingly concentrated in a shrinking group of experienced staff.

This means legacy modernization projects are a meaningful opportunity to improve cyber resilience alongside their other goals. Data migrated to a modern platform can be brought under current backup, immutability, and recovery testing practices in ways that may not have been feasible on the original legacy system. Conversely, modernization projects that don't specifically address resilience requirements can end up carrying forward the same recovery gaps into a newer, but not necessarily more resilient, environment.

How InsOps Helps

InsOps is not a backup, disaster recovery, or incident response platform, and CISOs building cyber resilience capability should look to dedicated backup and DR tooling for that core function.

Where InsOps connects to this challenge is specifically in legacy data migration projects, moments where a carrier has the opportunity to bring data and systems that previously lacked strong resilience practices onto a modern platform with better native backup and recovery support. InsOps's migration of 40+ years of AS/400 claims data into Guidewire ClaimCenter Cloud, achieved at 99%+ accuracy, illustrates the kind of transition that can meaningfully improve an organization's underlying resilience posture, moving sensitive claims data off a legacy system with limited modern recovery tooling and onto a cloud-based platform built with contemporary resilience capabilities in mind.

Because InsOps operates inside the insurer's own controlled environment, with every migration and integration output validated through human review, the migration process itself doesn't introduce a new, separately managed system that would need its own independent resilience and recovery planning.

This is a supporting consideration tied specifically to modernization projects, not a resilience solution on its own. Immutable backups, disaster recovery automation, cyber recovery testing, and incident response playbooks remain the dedicated, essential practices for building genuine business continuity and cyber resilience.

FAQ

Why do modern ransomware attacks specifically target backup systems? Because traditional backups are the fallback organizations rely on to avoid paying a ransom. If an attacker can encrypt or delete backups before executing the primary attack, they remove that fallback option, increasing pressure on the organization to pay. This is why standard backups alone are no longer considered sufficient protection.

What makes a backup "immutable," and why does that matter? An immutable backup can't be modified or deleted for a defined retention period, even by an administrator with otherwise privileged access. This protects the backup even if an attacker has compromised credentials with broad permissions, ensuring a clean, restorable copy remains available regardless of what happens elsewhere in the environment.

Why is testing a disaster recovery plan as important as having one? An untested plan often contains gaps, missing dependencies, outdated procedures, unavailable personnel or documentation, that only become apparent when the plan is actually executed. Regular, realistic testing surfaces these issues in a controlled setting rather than during an actual incident, when there's no room for the recovery process itself to fail.

How does disaster recovery automation reduce risk compared to manual recovery processes? Automation reduces the chance of human error during the high-pressure conditions of an actual incident and typically achieves faster recovery times than manual processes, both of which directly reduce the business impact of downtime.

Why are legacy systems often a specific challenge for cyber resilience planning? Older core systems may lack modern backup integration, have poorly documented dependencies, or require specialized institutional knowledge to restore correctly. That knowledge is often concentrated in a small group of experienced staff, creating risk if recovery depends on their availability during an actual incident.

Does InsOps provide backup, disaster recovery, or incident response capabilities? No. InsOps focuses on legacy data migration and system integration. Its connection to cyber resilience is specific to modernization projects, moving data from legacy systems with limited resilience tooling onto modern platforms with stronger native backup and recovery capabilities, but dedicated backup, DR automation, and incident response tools remain necessary for a complete cyber resilience program.

Craig Hangartner

NavaJeevan Rajaiah