adesso Blog

Monday morning, 7.45 am. The systems have ground to a halt. Ransomware. Policy management, claims management, the customer portal, email, telephony via Teams – nothing is working. Claims are going nowhere, benefit payments are stalling, and brokers and customers are receiving no information. And with every hour that passes, the costs, the damage to reputation and the pressure on everyone involved mount. For insurers, there is an additional complication: regulatory reporting deadlines are already ticking away, whilst the very infrastructure they need to use for reporting and coordination can no longer be accessed. Anyone who has ever looked inside a company dealing with a serious cyber incident will recognise the scene: chaos, stress, high emotions. It is precisely in this state that people find it most difficult to proceed with implementation in a structured manner. Experience from incident response shows that large companies often need a week or more before they can move into the execution phase in a truly coordinated manner. A lost week – in an emergency, the most expensive week of the year.

A well-thought-out Business Continuity Management (BCM) system is the insurance against this standstill – a scenario the industry knows better than any other. But plans that sit printed out in drawers won’t save anyone. In an emergency, what counts is how quickly and in a coordinated manner an organisation can respond. This is precisely where the Panic Button comes in: a cyber resilience platform that provides a complete, clean emergency environment at the touch of a button – within an hour rather than a week.

Why insurers are a particular focus

Insurers are an attractive target for attackers: they manage highly sensitive health, financial and contractual data belonging to millions of customers; they operate legacy application landscapes with numerous interfaces to brokers, service providers and underwriters; and their business model is based on trust. A prolonged outage therefore affects not only operations but also the industry’s core promise: to be there reliably for customers in an emergency. If, of all times, no one is available when a claim is made and benefits cannot be paid out, this results in reputational damage that extends far beyond the immediate incident.

The problem: when your own infrastructure becomes the enemy

In the event of a serious security incident, three patterns recur. Firstly: people under stress cannot organise themselves. Secondly: there is no secure platform for crisis communication and recovery. The organisation’s own infrastructure is compromised or must be treated as such – and anyone who then falls back on private Gmail accounts and shadow IT is shifting sensitive customer and contract data to unsecured channels, which the attacker may well be monitoring. For a company handling data requiring special protection, this is not an option. Thirdly: the necessary information is unavailable. Incident response plans, playbooks, network diagrams and communication matrices – if they exist at all – are stored in different versions in different locations or on systems that nobody can access anymore.

A secure platform, structure and information: the Panic Button was developed to address these three requirements.

The Core Layer: From chaos to structure in an hour

When the Panic Button is triggered, Infrastructure as Code creates a completely new, clean Microsoft 365 and Azure environment on a separate domain – on average in around 22 minutes, guaranteed within an hour. This environment is deliberately not connected to the insurer’s infrastructure: no connection to the production network, no synchronisation with Active Directory. This rules out lateral movement by attackers by design.

The new environment is not an empty space, but is already fully pre-configured:

  • War Rooms by discipline: In Microsoft Teams, an IT, a communications and a management war room are immediately available – staffed with the relevant internal and external personnel, such as the IT service provider or cyber resilience partner. Of particular relevance to insurers: compliance, data protection and legal matters can also be pre-configured as separate war rooms, so that notifications to the regulator and affected parties can be coordinated in a timely manner.
  • Scheduled crisis meetings: Meeting structures are derived in advance from the insurer’s incident response plans and pre-scheduled for the first 24 to 72 hours. When an incident is triggered, the calendars are automatically populated – no one needs to organise themselves first.
  • The right information in the right room: Incident response plans, communication matrices, reporting channels and architectural diagrams are systematically fed into each war room. Everyone starts with the same level of information.
  • Onboarding via SMS: All relevant staff members receive a text message containing a link and an initial password – via SMS because the compromised company email account must no longer be used. A small detail illustrates just how well thought-out the implementation is: characters that can be easily confused, such as O, 0, I and l, have been removed from the initial passwords, as people make typing errors when under stress.

Because the platform is based on Microsoft 365, there is also no learning curve: virtually everyone is familiar with Teams, Outlook and SharePoint – a crucial factor when nerves are on edge.

Minimum Viable Insurer: Less is more

Beyond the Core Layer, the focus is on business continuity – and thus on the central conceptual question: what does an insurer really need when everything fails? If you ask customers, the first answer is always ‘everything’. But ‘everything’ is not possible, not affordable and not maintainable. The Minimum Viable Company approach identifies the processes, data and applications that are actually critical – and deliberately omits what the company can do without for eight to ten weeks without suffering any existential damage. For an insurer, the focus is typically on claims intake and settlement, the payment of benefits and pensions, accessibility for customers and sales partners, and regulatory reporting channels – whilst processes such as new business or campaign management can be put on hold for a while. This discussion is not always comfortable internally, but it is at the heart of any viable continuity strategy. And it is classic consultancy work: business impact analysis, criticality assessment, and RTO and RPO assessments.

Five modules for business continuity

Based on the Minimum Viable Company concept, the solution can be built up in a modular fashion:

  • Essential Data Continuity: Business-critical base data such as contract and policy data, SLAs, commission, planning and CRM data are replicated as validated flat files into a Secure Data Container and are immediately available in SharePoint in the event of an emergency. This enables claims processing and customer service to continue providing information, even if the core systems are down.
  • SaaS Continuity: If the identity provider fails or is isolated as part of a forensic investigation, single sign-on will no longer function. The Panic Button temporarily takes over the role of security provider for critical SaaS applications – including user mapping – so that staff can continue working with their usual profiles.
  • On-Premise Continuity: Critical on-premises systems – often legacy inventory management and host environments that have evolved over time at insurance companies – are protected by dedicated security hardware nodes; in the event of a crisis, they are completely isolated from the network and securely restored via a separate 5G APN connection.
  • OT Continuity: In combination with military-grade intrusion detection and prevention hardware, operational technology (OT) assets can also be monitored, isolated and kept operational using simple control commands – relevant, for example, for data centre and building infrastructure. Even air-gapped environments can be integrated via secure wireless connections.
  • Specialist Workplaces: Virtual desktops with specialist software – such as actuarial applications or fat clients for legacy systems in claims and benefits processing – are provisioned at the touch of a button.

An example from the Netherlands illustrates just how effective this approach is in the financial and insurance sectors: a large pension fund with over a million beneficiaries would, according to its own analysis, have needed eight to ten weeks for a full recovery – which is incompatible with DORA regulations. Today, in the event of a crisis, it can resume making payments within an hour via a pre-configured, offline SWIFT environment hosted in Azure. This is a scenario that can be directly applied to pension and benefit payments by insurers.

Security by Design

An emergency platform is only as good as its own security concept. The Panic Button therefore consistently focuses on minimising the attack surface: The fallback environment simply does not exist during normal operation – what does not exist cannot be attacked. Only the Secure Data Container is permanently available, hosted on a private endpoint with no direct internet connection, containing encrypted data – using the customer’s own keys on request, as is frequently required by DORA-regulated financial and insurance companies. The associated tenant contains exactly one account, the password and MFA factor for which are stored separately within the organisation. Data transfers take place exclusively via a verification path known as a ‘cleaning room’, which only permits flat files and scans them multiple times for malicious code. The environment created in the event of an emergency legally belongs to the customer – once set up, not even the manufacturer has access to it. And for insurers with sovereignty requirements, the Secure Data Container can be operated in a private cloud.

No one can guarantee 100 per cent security – that is part of being honest. But the architecture consistently reduces risks precisely where attackers typically strike.

Regulatory framework: DORA makes responsiveness mandatory

Hardly any other sector is under such regulatory scrutiny as the insurance industry. With DORA, a directly applicable legal framework for insurers and reinsurers has been in force since January 2025, replacing the previous supervisory IT requirements – and one that demands not only documented contingency plans, but also verifiably tested digital operational resilience:

ranging from ICT risk management and strict reporting deadlines for serious incidents to regular tests of response and recovery capabilities. This is precisely where the Panic Button pays off twice over: insurers can run through their emergency procedures twice a year in a separate test environment – as a tabletop exercise or a live simulation by actually pressing the button. These exercises provide the evidence that auditors and regulators want to see, and regularly uncover gaps: it is only during the simulation that many participants realise what information they would have been missing in a real-life emergency. With the Crisis Command Centre, announced for the end of 2026, crisis management templates, mass communication via SMS with two-way status enquiries (keyword: duty of care) and audit-proof logging will also be introduced.

The second perspective: insurers as risk bearers

For insurers, cyber resilience is doubly relevant – not only for their own operations, but also in underwriting. Anyone who underwrites cyber policies knows that the amount of the claim in the event of a ransomware attack is largely determined by the duration of the business interruption. A platform that reduces the time between an incident and a coordinated response from weeks to one hour significantly alters a policyholder’s risk profile. Proven continuity capabilities thus become a key criterion in risk assessment – and, for companies, a key factor in their insurability. It is therefore worthwhile for cyber insurers to consider solutions such as the Panik Button from the perspective of loss prevention and portfolio risk as well.

Technology requires preparation: the role of consultancy

As impressive as the platform is – it does not run itself. Its effectiveness stands or falls on preparation: Which processes are critical? Who is authorised to press the button? Which war rooms are needed, and who should staff them? What data needs to be backed up, and how frequently? What do reporting channels, communication plans and playbooks look like – including those for the regulator? Our experience shows that even large organisations often do not have their incident response plans and playbooks in a state that would hold up in an emergency. The consultancy component of a Panic Button implementation is therefore deliberately extensive – ranging from business impact analysis and the definition of the Minimum Viable Company to regular drills and continuous improvement.

Or to put it simply: Continuity Management tells you what to do. The Panic Button ensures it happens immediately.

Conclusion

The question is no longer whether a serious cyber incident will occur, but when – and whether an insurer will remain capable of acting at that moment: vis-à-vis customers, sales partners and the regulator. The Panic Button reduces the critical time between an incident and a coordinated response from days to an hour: with a clean, isolated emergency environment, pre-prepared structures and the right information in the right place. Combined with sound business continuity management, this creates genuine cyber resilience – DORA-compliant, robust, tried and tested in practice, and just a click away when it matters most.

Would you like to know how resilient your organisation really is in an emergency? At adesso, we provide comprehensive support to insurers: from business impact analysis and the development of your BCM and disaster recovery strategy right through to the implementation and regular testing of an emergency platform such as the Panic Button. Please get in touch.

Picture Madru Kortz

Author Madru Kortz

Madru Kortz is a Team Lead in the Information Security division of the IT Management Consulting business line at adesso SE. In recent years, he has focused on information security in regulated environments. In this field, he has acquired in-depth specialist knowledge regarding the introduction, optimisation and further development of the Information Security Management System (ISMS) and the implementation of regulatory requirements.