Row of empty office computer workstations with monitors, keyboards, and office chairs along a white desk.

What Does a Modern Cybersecurity Stack Look Like for an Insurance Agency?

by | Aug 24, 2026

A modern cybersecurity stack for an insurance agency should protect five layers: devices, users, identities, cloud applications, and business data. For an agency with 15 to 30 employees, the stack should include antivirus, Endpoint Detection and Response, email filtering, security awareness training, Microsoft 365 management, backup, monitoring, patching, documentation, and incident response procedures. Some agencies also need Business Continuity and Disaster Recovery, penetration testing, or compliance management. No single product provides complete protection. The stack must be layered, monitored, maintained, and aligned with the agency’s actual risks.


The 5-Layer Insurance Agency Security Stack

A complete security strategy should address:

  1. Device protection

  2. User and email protection

  3. Identity and cloud protection

  4. Data protection and recovery

  5. Monitoring, documentation, and response

Each layer addresses a different attack path.


Layer 1 – Device Protection

Every managed workstation and server should have:

  • Antivirus

  • Endpoint Detection and Response

  • Patch management

  • Remote monitoring

  • Device backup where applicable

  • Standard security configurations

  • Local administrator controls

Traditional antivirus looks for known threats. EDR adds behavioral monitoring and can help identify suspicious activity that traditional antivirus may miss.
Device protection should be verified continuously.

The agency should know:

  • How many devices are managed

  • Which devices are missing tools

  • Whether agents are reporting

  • Whether critical patches succeeded

  • Whether unsupported systems remain

  • Whether security alerts were investigated

An unmanaged laptop can create an entry point into the broader environment.


Layer 2 – User and Email Protection

Users are frequently the primary target.
Insurance employees regularly receive messages involving:

  • Policy renewals

  • Client attachments

  • Claims information

  • Vendor invoices

  • Carrier communications

  • Banking details

  • Password resets

  • Document signatures

Attackers imitate these normal workflows.
User and email security may include:

  • Inky email protection

  • Spam filtering

  • Phishing detection

  • Link and attachment inspection

  • BullPhish ID awareness training

  • Phishing simulations

  • Dark Web ID monitoring

  • Reporting procedures

  • Executive impersonation protection

Training should be ongoing. A single annual video may not be enough to change behavior.


Layer 3 – Identity and Cloud Protection

Microsoft 365 and other cloud platforms should be protected with:

  • Multi-factor authentication

  • Conditional access

  • Administrative account separation

  • Secure password practices

  • SaaS Alerts

  • Login monitoring

  • External sharing controls

  • User lifecycle management

  • Microsoft 365 maintenance

Identity protection matters because an attacker with valid credentials may be able to bypass device-level defenses.
The agency should review both human users and application access. Third-party applications connected to Microsoft 365 can also create risk.


Layer 4 – Data Protection and Recovery

Data protection should include more than a copy of files.
The agency should define:

  • What data is backed up

  • How often backups run

  • Where copies are stored

  • Who monitors backup results

  • How ransomware is prevented from reaching backups

  • How often recovery is tested

  • How quickly critical systems can be restored

  • Which systems require business continuity capabilities

Unified device backup and Datto SaaS Protection may address parts of this need.
Business Continuity and Disaster Recovery may be appropriate for agencies that cannot tolerate extended downtime. BCDR is an a la carte service and should be explicitly accepted or declined.
A backup that has never been tested should not be treated as a guaranteed recovery plan.


Layer 5 – Monitoring, Documentation, and Response

Security tools must be actively managed.
This layer includes:

  • Datto RMM monitoring

  • Automated ticket creation

  • Alert triage

  • Monthly audits

  • IT Glue documentation

  • Secure password management

  • Service escalation

  • Incident response procedures

  • Technology Alignment Manager oversight

  • Quality control

Without these processes, tools can fail silently.
For example:

  • A backup job may stop

  • An EDR agent may become disconnected

  • A laptop may miss patches

  • A user account may remain active

  • An alert may be ignored

  • A firewall may reach end of support

The management process turns individual products into an operational security program.


What Is Included in the Essentials Package?

The Essentials package is designed to protect devices and data.
It includes:

  • Antivirus

  • Endpoint Detection and Response

  • Unified device backup

  • Datto SaaS Protection where applicable

This package addresses malware, ransomware, data loss, and system-level threats.
It is an important foundation, but it does not fully address user, email, identity, and cloud risks.


What Does the Complete Package Add?

The Complete package includes everything in Essentials, plus:

  • Inky email security

  • BullPhish ID security awareness training

  • Dark Web ID monitoring

  • SaaS Alerts

  • Microsoft 365 management and maintenance

The Complete package is the standard recommendation for most organizations because modern attacks often begin with people, email, and identity.


How Much Should a Modern Security Stack Cost?

A properly secured managed environment commonly requires an effective investment of approximately $125 to $175 per endpoint per month.
The final amount may include:

  • Security package

  • $40 per-endpoint Managed Services Fee

  • Tiered Technology Fee

  • User-security services

  • Optional BCDR

  • Optional penetration testing

  • Optional Compliance Manager

  • Project work or remediation

The professional services benchmark is $150 per hour for projects, exceptional work, and services outside the managed agreement.
The goal is not to assemble the cheapest collection of software. The goal is to create a monitored, maintainable environment with clear accountability.


Security Stack vs Tool Collection

A tool collection is a list of products.
A security stack is a coordinated system with:

  • Defined purpose

  • Coverage standards

  • Monitoring

  • Escalation

  • Documentation

  • Testing

  • Ownership

  • Regular review

A business may own many tools and still be poorly protected.
Examples include:

  • Antivirus installed but not monitored

  • Backups running but never tested

  • MFA enabled for only some users

  • Security training purchased but not completed

  • Alerts generated but not reviewed

  • Documentation stored inconsistently

The agency should evaluate how the tools work together.


The Role of Technology Alignment

Technology alignment keeps the security stack effective over time.
Alignment reviews may identify:

  • Devices missing security tools

  • Unsupported hardware

  • Inconsistent user permissions

  • Backup failures

  • Unnecessary administrator access

  • Weak network configurations

  • Recurring employee problems

  • Licensing gaps

  • Tools that no longer match the environment

Technology alignment helps insurance agencies reduce downtime and security risk by correcting inconsistencies before they become larger incidents.


Legacy Technology Can Weaken the Entire Stack

A modern security platform cannot fully compensate for unsupported systems.
Legacy risks may include:

  • Operating systems that no longer receive patches

  • Old firewalls

  • Aging servers

  • Unsupported applications

  • Weak encryption

  • Hardware without vendor support

  • Systems that cannot run current security tools

Legacy systems can undermine an otherwise strong cybersecurity stack by creating vulnerabilities that cannot be fully patched or monitored.


Regulatory Compliance and the Security Stack

A security stack can support regulatory compliance by helping the agency:

  • Protect sensitive information

  • Control access

  • Monitor systems

  • Train employees

  • Document controls

  • Respond to incidents

  • Maintain backups

  • Review third-party risk

However, tools alone do not create compliance.
The agency may also need:

  • Written policies

  • Risk assessments

  • Vendor documentation

  • Incident response plans

  • Retention standards

  • Evidence of review

  • Leadership approval

  • Compliance-specific reporting

Compliance Manager may be offered separately. If declined, the associated risk should be acknowledged.


Example – Building a Stack for a 28-Employee Agency

Consider an agency with:

  • 28 employees

  • 34 endpoints

  • Microsoft 365

  • One local server

  • Remote staff

  • Two locations

  • Basic antivirus

  • Consumer-grade backup

  • No security training

  • Limited documentation

A modernized stack may include:

  • EDR on all endpoints

  • Managed patching

  • Inky email protection

  • BullPhish ID training

  • Dark Web ID monitoring

  • Microsoft 365 management

  • SaaS Alerts

  • Unified device backup

  • BCDR evaluation

  • Datto RMM monitoring

  • IT Glue documentation

  • Monthly service audits

The outcome is not simply more software.
The agency gains:

  • Better visibility

  • Faster alert handling

  • Stronger user protection

  • More reliable backup

  • Better documentation

  • Reduced operational risk

  • Improved compliance readiness


Security Stack Evaluation Checklist

Confirm whether the agency has:

Devices

  • Antivirus

  • EDR

  • Patch management

  • Monitoring

  • Device inventory

Users

  • Security awareness training

  • Phishing simulations

  • Dark web monitoring

  • Reporting procedures

Email

  • Spam filtering

  • Phishing protection

  • Impersonation protection

  • Link and attachment analysis

Identity

  • MFA

  • Conditional access

  • Admin account separation

  • Account lifecycle management

Cloud

  • Microsoft 365 management

  • SaaS alerts

  • External sharing controls

  • Login monitoring

Data

  • Backup

  • Recovery testing

  • SaaS protection

  • BCDR evaluation

Operations

  • Documentation

  • Alert triage

  • Monthly audits

  • Escalation procedures

  • Incident response

Who May Not Be a Fit for This Security Approach?

A layered security model may not align with a business that:

  • Wants antivirus only

  • Refuses MFA

  • Does not want employee training

  • Keeps unsupported systems indefinitely

  • Chooses tools only by lowest cost

  • Does not want active monitoring

  • Expects the provider to accept risk without implementing controls

Businesses that do not value layered security and proactive management may not be the right fit for West Texas IT Consulting.

Add Text here


Conclusion

A modern cybersecurity stack for an insurance agency should protect devices, users, identities, cloud systems, and business data. It should also include monitoring, documentation, response procedures, and regular technology alignment.

For agencies in Midland, Odessa, Monahans, Pecos, and the surrounding Permian Basin, the strongest security program is not built from one product. It is built from coordinated layers that are actively managed and improved over time.

Review managed services that combine device protection, user security, monitoring, documentation, and proactive technology alignment.

Ready to Talk About Your IT?

If you’re running a company or organization in the Permian Basin and want IT that actually understands your environment, we’d be happy to talk!