Why Operational Resilience Is Reshaping Insurance IT Support

200+ Articles published
5 IT topics covered
20+ Years of IT expertise
CE+ Cyber Essentials Plus
Share
In This Article
    Speedster IT
    Need IT Support in London?

    Unlimited, proactive IT support from a team who answers the phone.

    Explore IT Support

    Why Operational Resilience Is Now One of the Biggest Challenges Facing Insurance Firms

    Operational Resilience in Insurance at a Glance

    • Required of insurers by FCA and PRA rules.
    • Focuses on important business services, such as claims and renewals.
    • Uses impact tolerances to set the maximum acceptable disruption.
    • Depends heavily on IT systems and cyber security.
    • Requires testing under severe but plausible scenarios.
    • Includes managing the risk from third-party suppliers.
    • Is supported by incident response and recovery planning.
    • Becomes even more important with new incident reporting rules from March 2027.

    Regulators Are Watching More Closely

    The deadline for insurers to stay within their impact tolerances passed on 31 March 2025. The FCA has since published its observations on how firms are meeting the rules, and supervisors now expect resilience to be tested and evidenced, not just documented.

    From 18 March 2027, new rules on operational incident and third-party reporting add another layer of scrutiny.

    Cyber, Cloud and Supplier Risks Are Rising

    Cyber attacks on financial services firms continue to grow in number and sophistication. At the same time, most insurers now rely on cloud platforms and specialist suppliers for core services. A problem at one provider can stop claims or renewals across the whole firm.

    Customers Expect Services to Keep Running

    Policyholders expect to make a claim, renew cover or get help at any time, especially after a storm, flood or accident. When services fail at those moments, the harm to customers and to the firm’s reputation is immediate.

    Why This Matters for IT Support Now

    Almost every impact tolerance depends on technology recovering in time. That puts IT support on the critical path for regulatory compliance. Insurers increasingly need insurance IT support that understands resilience, not just a helpdesk that fixes faults.

    The same pressures apply across the wider sector, which is why our IT support for financial services is built around regulatory obligations. We covered the day-to-day impact on support teams in why operational resilience is now the biggest insurance IT support challenge. This article looks at the framework itself and what to expect from a provider.

    What Operational Resilience Means for Insurance Firms

    What is operational resilience in insurance?

    Operational resilience is the ability of an insurance firm to keep delivering important business services during disruption. That includes cyber attacks, technology failures and supplier outages. It also covers how quickly the firm can recover when things go wrong.

    Regulatory Expectations

    For UK insurers, operational resilience is now a regulatory requirement, not just good practice.

    The FCA’s rules (PS21/3) and the PRA’s supervisory statement (SS1/21) apply to insurers. Firms had until 31 March 2025 to show they could stay within their impact tolerances for every important business service. Supervisors now expect that capability to be maintained, tested and evidenced.

    Why is operational resilience important for insurance companies?

    Regulators expect insurers to identify their critical services, assess the risks to them and show they can recover quickly from disruption. Customers expect the same. A claims system that goes down after a storm or a cyber attack causes real harm to policyholders.

    Is operational resilience the same as business continuity?

    No. Business continuity is one part of operational resilience. Operational resilience focuses on keeping important business services running within defined impact tolerances, even during severe disruption. It also covers mapping, testing, third-party risk and governance.

    Who is responsible for operational resilience in an insurance firm?

    Ultimate responsibility sits with senior management and the board. In practice, resilience depends on compliance, operations, risk management, IT and third-party suppliers working together. Outsourcing a service does not outsource the responsibility.

    The Five Pillars of Operational Resilience in Insurance

    Important Business Services

    An important business service is one that would cause intolerable harm to customers, or threaten market stability, if it failed. For an insurer, that often includes:

    • Making a claim and receiving a pay-out.
    • Buying or renewing a policy.
    • Making changes to cover.
    • Accessing policy documents and customer support.

    Firms must map the people, processes, technology, data and suppliers behind each service. In practice, most of that map is IT.

    What is an important business service for an insurer?

    It is a service delivered to customers or the market where disruption could cause serious harm. Claims handling and policy administration are typical examples. Internal systems such as payroll usually are not, unless their failure would stop a customer-facing service.

    Impact Tolerances

    An impact tolerance is the maximum level of disruption a firm can accept for each important business service. It is usually set as a time limit, such as how long customers can go without being able to make a claim.

    Firms must test whether they can stay within these limits under severe but plausible scenarios. A major cyber attack, a cloud outage or a supplier failure are all common test cases.

    What is an impact tolerance?

    It is the point at which disruption to a service becomes intolerable. Unlike a recovery time objective, which focuses on getting a system back online, an impact tolerance is measured by the harm to customers. It is set from the customer’s point of view, not the IT team’s.

    Mapping and Dependencies

    Firms must map everything each important business service relies on. That includes people, processes, technology, facilities, data and suppliers.

    Mapping shows where a single point of failure could break a service. A claims platform might depend on one cloud provider, one integration and one person who knows how to restore it.

    Scenario Testing

    Scenario testing checks whether a firm can stay within its impact tolerances during severe but plausible disruption. Common scenarios include ransomware, a cloud outage, a data centre failure or the loss of a key supplier.

    Tests can range from tabletop exercises to live recovery of systems. The aim is to find weaknesses before a real incident does.

    How often should insurers test their resilience?

    Firms must review their important business services, impact tolerances and self-assessment at least once a year, and after any significant change. Scenario testing should be regular and proportionate. Many firms also test backups and recovery processes more often, such as quarterly.

    Continuous Improvement

    Resilience is never finished. Firms must fix the vulnerabilities their testing reveals, record what changed and test again.

    A written self-assessment, approved by the board and kept up to date, brings this together and gives supervisors the evidence they expect.

    The Growing Role of IT Support in Insurance

    How does IT support contribute to operational resilience?

    IT support keeps systems available, manages incidents, strengthens cyber security and supports business continuity planning. In short, it turns resilience plans into something that works on the day.

    Incident Response and Recovery

    When something breaks, the clock on your impact tolerance starts ticking. Your IT support provider needs to:

    • Spot the problem quickly through monitoring.
    • Assess whether an important business service is affected.
    • Escalate to the right people straight away.
    • Keep a clear record of what happened and when.

    A tested plan makes this far easier, as we cover in could your business survive a cyber attack tomorrow?

    That record matters more than ever. The FCA, PRA and Bank of England published new rules on operational incident and third-party reporting (PS26/2) in March 2026. They apply from 18 March 2027 and set out what must be reported and how quickly.

    Example: How a Cyber Attack Could Affect a Claims Service

    Imagine ransomware takes down an insurer’s claims platform during a major weather event, just as claims volumes peak. The insurer must:

    • Identify the incident quickly.
    • Decide whether an important business service is affected.
    • Activate its recovery procedures.
    • Restore the claims service, or a workaround, before the impact tolerance is breached.
    • Record every decision and timeline.
    • Meet its regulatory and data protection reporting obligations.

    Each step depends on technology, people and suppliers working together under pressure. That is why testing scenarios like this in advance matters so much.

    What changes for insurers in March 2027?

    From 18 March 2027, firms must report qualifying operational incidents to their regulators using a standard process. They must also keep information on material third-party arrangements. IT support logs, timelines and incident records will be central to meeting these requirements.

    How can IT support improve incident response times?

    Proactive monitoring spots problems early. Clear escalation procedures get the right people involved quickly. Well-defined recovery processes, tested in advance, mean less time is lost working out what to do.

    Cybersecurity and Compliance

    Cyber attacks are one of the most likely causes of a breach of impact tolerance. Insurers hold large amounts of personal and financial data, which makes them an attractive target.

    Strong security reduces the chance of disruption in the first place. For most insurers that starts with Microsoft 365, where we regularly find the Microsoft 365 security mistakes that attackers exploit. That includes continuous monitoring through MDR services, regular penetration testing and a Cyber Essentials Plus baseline.

    How does cyber security affect operational resilience?

    Cyber incidents can stop critical business functions, such as claims handling or policy administration. That makes strong security controls a fundamental part of operational resilience, not a separate topic.

    Is Cyber Essentials enough for operational resilience?

    Cyber Essentials is a valuable baseline, and Cyber Essentials Plus adds independent testing. But it does not cover impact tolerances, scenario testing or recovery planning. Insurers should treat it as one building block, not the whole answer. The scheme has also tightened recently, as covered in Cyber Essentials changes every UK business needs to know.

    Business Continuity Planning

    Business continuity plans set out how the firm keeps working during a disruption. Disaster recovery is the IT side of that plan, and it is often the most underrated IT investment. It covers backups, failover systems and how quickly data can be restored.

    Both need regular testing. A plan that has never been tried is a hope, not a control. Our disaster recovery services are designed to be tested, documented and improved over time.

    What role does business continuity play in operational resilience?

    Business continuity planning helps firms keep key services running, or restore them quickly, during unexpected events. It is where impact tolerances become practical plans, with clear owners, workarounds and recovery steps.

    Work With Speedster IT

    Want IT support that actually works?

    Talk to us about how your IT is supported today, and what a managed IT partner should be taking off your plate.

    Talk to Our Team

    Why Traditional IT Support Is No Longer Enough for Insurers

    Helpdesk Support Does Not Equal Operational Resilience

    A traditional helpdesk fixes problems as they are reported. That is still important, but it does not show a regulator that your important business services can stay within their impact tolerances.

    Resilience needs support that understands which systems matter most, how quickly they must recover and how to prove it.

    Why are insurers investing more in specialist IT support?

    Insurance firms need technical expertise that fits resilience frameworks, compliance requirements and complex business operations. A general helpdesk can fix faults, but it may not understand impact tolerances or how to produce evidence for a regulator.

    Why Insurers Need Proactive Monitoring

    Waiting for a user to report a fault wastes valuable time on the impact tolerance clock. Proactive monitoring spots failing systems, unusual sign-ins and suspicious activity early, often before staff or customers notice. A managed security services provider can add round-the-clock security monitoring on top.

    The Importance of Recovery Testing

    Backups are only useful if they can be restored in time. Regular recovery tests show how long it really takes to bring each critical system back, which feeds directly into your impact tolerances and scenario testing.

    Supporting Regulatory Reporting Requirements

    The March 2027 rules mean incident records will be used as regulatory evidence. Your IT support provider should keep accurate timelines, clear categorisation and a record of decisions, so reports can be produced quickly and with confidence.

    Operational Resilience Challenges Facing Insurance Firms

    What are the biggest operational resilience challenges facing insurers?

    The most common challenges are cyber threats, ageing infrastructure, dependence on third parties and complex regulatory requirements. Each is covered below.

    Legacy Infrastructure

    Many insurers still rely on older policy and claims systems. These can be hard to patch, hard to back up and hard to recover quickly. Some depend on unsupported operating systems, which also creates a security risk.

    If an older server sits behind a claims process, its recovery time may set the limit for your whole impact tolerance. Our guide to Windows Server 2016 end of support covers one deadline many firms now face.

    Increasing Cyber Threats

    Ransomware, phishing and business email compromise all target the insurance market. Attackers also use the types of social engineering attacks that trick staff into handing over access. A successful attack can take systems offline for days. It can also expose customer data and trigger reporting obligations to the ICO as well as financial regulators.

    Newer risks add to the pressure. Staff pasting policyholder data into unapproved AI tools creates the problems described in Shadow AI and GDPR. Underwriters and claims teams working from home also widen the attack surface, which is why remote and hybrid workforce security matters for insurers too.

    How do cyber criminals target insurers?

    Attackers often start with a phishing email or a stolen login. Once inside, they look for policyholder data, payment processes and backups. Ransomware groups often target backups, so a firm cannot recover without paying. Phishing-resistant sign-in, such as passkeys for business, removes many of the stolen-login routes attackers rely on.

    Third-Party Service Risks

    Insurers depend on cloud platforms, software vendors, outsourced claims handlers and IT providers. The regulators are clear that the firm stays responsible for its impact tolerances, even when a third party delivers part of the service. The 2024 CrowdStrike outage showed how one supplier’s faulty update can disrupt thousands of firms at once, as we covered in what’s your business’s disaster recovery plan post-CrowdStrike?

    The UK’s critical third parties regime adds oversight of the largest providers to the financial sector. But most suppliers will not be covered by it, so your own due diligence still matters. Our guide to third party cyber security explains what to check.

    Common Third-Party Risks for Insurance Firms

    Every supplier behind an important business service is a possible point of failure. Typical examples include:

    Provider typeExample risk
    Cloud providerRegional outage
    Claims platformApplication failure
    Managed service provider (MSP)Delayed incident response
    Software vendorFaulty software update
    Email security providerService disruption
    Data providerMissing or delayed policy data

    Each of these should appear in your mapping, with a plan for what happens if that supplier fails.

    Does operational resilience depend on cloud providers?

    Yes. Most insurance firms rely on cloud-based applications and infrastructure. Firms must understand how resilient those providers are and assess how an outage could affect their important business services.

    Can a cloud outage cause an impact tolerance breach?

    Potentially, yes. If a cloud service supports a critical business process, a prolonged outage could stop the firm staying within its impact tolerance. That is why cloud outages are a common scenario in resilience testing.

    Does DORA apply to UK insurers?

    DORA is an EU regulation. It applies directly to insurers based in the EU, not to UK-only firms. However, UK insurers with EU entities, or those supplying services to EU firms, may find DORA requirements passed down to them through contracts.

    What to Look for in an Insurance IT Support Provider

    Industry Experience

    Look for a provider who understands how insurance works. They should know the difference between a claims system outage and a minor internal fault. They should also understand the London market, including the extra standards that apply to firms working in the Lloyd’s market.

    Good habits matter as much as technical skill. We explored why in the most dangerous person in insurance IT is the well-meaning engineer.

    Resilience-Focused Support Services

    Your provider should support the whole resilience lifecycle, not just fix problems. Useful questions to ask include:

    • Can you help map our technology to our important business services?
    • Do you monitor our systems around the clock?
    • How do you log and timestamp incidents?
    • Can you take part in our scenario testing?
    • How quickly can you restore our critical systems?

    What should an insurance IT support contract include?

    It should cover response and resolution targets, monitoring, backup and recovery testing, and clear incident reporting. It should also give you the right to audit, explain how the provider will support regulatory requests, and set out what happens if the contract ends.

    Regulatory Knowledge

    Your provider does not need to be a compliance consultant. But they should understand FCA and PRA expectations well enough to support your evidence. That means clear documentation, change records and test results you can show to the board or a supervisor.

    What should insurers look for in an IT support provider?

    Look for experience within financial services, strong cyber security expertise, the ability to support resilience planning and testing, and a working understanding of regulatory requirements.

    Do smaller insurance brokers need to worry about operational resilience?

    Many smaller brokers are not directly in scope of the full operational resilience rules. But the new incident reporting rules from March 2027 apply far more widely across FCA-regulated firms. And every broker benefits from reliable systems, tested backups and strong security.

    Building a More Resilient Insurance Business

    How can insurance firms improve operational resilience?

    Most improvements come from stronger cyber security, tested recovery plans, resilient infrastructure and expert IT support. The practical steps below are a good place to start.

    Start With Your Important Business Services

    If you have not reviewed your mapping recently, start there. Check that every system, supplier and data flow behind each service is still accurate. Technology changes quickly, and maps go out of date.

    Close the Gaps You Find

    Scenario testing often reveals weak points, such as a single supplier, an untested backup or an ageing server. Prioritise the fixes that bring each service back within its impact tolerance. Keep a record of what you changed and why.

    Prepare Now for March 2027

    Review how incidents are logged today. Make sure your IT support processes can produce the timelines and detail the new reporting rules will need. It is far easier to build this in now than to reconstruct it during a live incident.

    Can operational resilience become a competitive advantage?

    Yes. Firms with strong resilience recover faster, minimise disruption for customers and show stronger governance to clients, brokers, regulators and partners. In a market built on trust, that reputation counts.

    What are the most common operational resilience mistakes?

    Common mistakes include treating resilience as a paper exercise, letting service maps go out of date, never testing backups and overlooking suppliers. Another is assuming an outsourced provider carries the responsibility. It stays with the firm.

    What happens if an insurance firm fails an operational resilience review?

    Regulators may require remediation plans, additional testing, governance improvements or further evidence that critical services can stay within impact tolerances. Customers may also be harmed if a real disruption exposes the same weaknesses. In serious cases, supervisors may take further action. It is far better to find and close gaps through testing than during a real incident.

    Operational Resilience Is No Longer Just a Compliance Exercise

    What the Most Resilient Insurers Have in Common

    The firms that perform best during disruption tend to have three things in common:

    • Resilient technology.
    • Tested recovery plans.
    • IT support providers who understand insurance regulation.

    A Board-Level Priority for 2027

    For insurers preparing for the March 2027 reporting requirements, operational resilience is becoming a board-level priority rather than an IT project. The work you do now on mapping, testing and incident records will shape how confidently you can respond to both disruption and regulators.

    Talk to Speedster IT About Insurance IT Resilience

    Operational resilience is now a core part of insurance IT support. If you would like help reviewing your recovery plans, testing your backups or preparing for the March 2027 reporting rules, our team can help.

    Call us on 0204 511 9111, email hello@speedster-it.com or get in touch online to book an operational resilience review.

    Ready to Talk?

    Let’s fix this properly.

    Book a free consultation with one of our engineers and find out what better IT support actually looks like.

    Get In Touch