- Job title
- Accounting clerk
- Sector
- Media and publishing
- Organization type
- two-branch business
- Joined
- Dec 2024
- Message
- 113
We are an industrial parts distributor in New Jersey with 22 employees. Our annual revenue is around $4 million. Our order management, accounting, and warehouse inventory systems run on two on-prem physical servers and a local NAS unit in our office.
Our cyber liability insurance policy, which we've maintained for three years, is up for renewal this month. Our broker sent over an exhaustive 12-page questionnaire. We used to just tick 'yes' to 'do you back up your data' and move on. This time, they are explicitly demanding a formal, written ransomware recovery plan. They said if we can't provide this document along with restore test logs from the last six months, our annual premium will jump from $3,500 to $9,000, or they might exclude ransomware coverage altogether.
We currently run nightly cloud backups and take weekly backups to an external hard drive, but we don't have an official, documented recovery plan. What are the bare minimum components this document needs to satisfy the underwriters? How can a small team put this together from scratch?