IT & Microsoft cloud for insurance
Regulated data protection, secure communications and resilient IT for insurers and brokers.
Checked 4 October 2026. Built from the full sector page.
In short: FCA operational resilience, premium diversion, and the archive a broker is expected to be able to produce. Work from the questionnaire your insurers and network partners already send you: it is the clearest statement you will get of what you are being judged on.
What changes in this sector
Insurance is one of the most heavily regulated sectors an SME can operate in. Brokers and insurers process personal and often special-category data at volume, they handle client money, and they run on email, quotes, claims correspondence, renewals and insurer communication, which makes them a standing target for business email compromise and premium-diversion fraud.
What we would do
Work from the questionnaire your insurers and network partners already send you. It is the clearest statement of what you will be judged on, and premium diversion through business email compromise is the loss the whole sector is actually exposed to.
- If FCA operational resilience is the driver, the important work is evidencing recovery rather than adding controls: what you would do, in what order, and how you would prove it afterwards.
- If archiving is the gap, treat it separately from backup. They are different jobs and a product that is good at one is usually poor at the other.
When we are not the answer: If you already hold Cyber Essentials Plus, archive independently and test your recovery, you are ahead of most of the sector and do not need a review. We would rather say that than sell you one.
What we do for insurance
- Layered cyber security (Managed Firewall, EDR, XDR) with 24/7 monitoring available, mapped to the important business services your resilience plan depends on
- Advanced email security and impersonation protection against BEC, phishing and premium-diversion fraud
- Compliant, searchable, independent email archiving and retention so client and insurer communications are retrievable for the regulator, complaints and DSARs
- Preparation for Cyber Essentials and Cyber Essentials Plus, assessed independently
- Operational resilience you can evidence: monitored, tested backup, disaster recovery and defined recovery times against your impact tolerances
- Secure, Intune-managed Microsoft 365 and devices for office and hybrid teams, with identity locked down by MFA and Conditional Access
What the last 12 months looked like
Three questions people ask
How do you support FCA operational resilience requirements?
First, check whether they apply: the SYSC 15A rules bind Solvency II insurers and certain other firm types, not most small brokers, although every FCA-authorised firm must report serious operational incidents from 18 March 2027.
How do you defend against business email compromise and premium diversion?
With advanced anti-phishing and impersonation protection in front of mailboxes, correctly configured SPF, DKIM and DMARC so your domain can't be spoofed, MFA and Conditional Access on identity, and staff awareness.
Can you keep a compliant, retrievable record of client communications?
Yes. Independent, tamper-proof email archiving keeps a complete, searchable record of every message for as long as your retention obligations require, held separately from the live mailbox so it survives deletion or a compromised account.
Ready to talk about your insurance IT?
A short call about how your IT works today and what your sector asks of it. We will tell you plainly where we would start.
Prefer to talk now? Call us on +44 (0)1482 770583.
