Independent insurance agencies in Lincoln and Omaha do not lose sleep over Hollywood hacks. They lose sleep over a producer’s laptop in a coffee shop, a car, or a home office — the same device that holds applications, loss runs, and a mailbox that can move premium money.
This post is a minimum security bar for producer and remote laptops. It is not a full agency IT program, not legal advice, and not a promise that any stack prevents every breach. For the wider agency picture — AMS, BEC on premiums, Safeguards-aware controls, questionnaires — start with IT & security requirements for independent insurance agencies. For what cyber carriers ask you to evidence, see the 12 controls carriers verify.
Primary next step: Get Your Free Security & IT Assessment · or call 531-625-2111.
Why do producer laptops deserve their own checklist?
Because they leave the suite. CSRs and principals often sit on a managed desk. Producers road-trip renewals, work from home after hours, and sometimes bring a personal machine that was never on the agency inventory.
When that laptop is the door into Microsoft 365 or the AMS, a lost bag or a phished session is not “their PC problem.” It is an agency problem: client data, carrier credentials, and a mailbox that looks legitimate to AP.
SAINT serves insurance agencies across the insurance vertical from Hickman — city-level HQ only, no storefront theater. Lincoln footprints are usually a short drive. Omaha-metro work is typically scheduled via I-80. Same bar. Different logistics.
What is the minimum bar — in plain language?
Treat every laptop that can open agency email or the AMS as agency-controlled, whether you bought it or approved it.
| Control | What “yes” means |
|---|---|
| MFA | Every mailbox and cloud app the producer uses — including the AMS — not a shared password on a sticky note |
| Disk encryption | BitLocker or FileVault on, recovery key escrowed where IT can find it |
| Patching | Critical OS and browser updates on a tracked window, not “when Windows nags” |
| EDR | Behavior-based endpoint protection with someone watching alerts — not consumer antivirus alone (cybersecurity) |
| Remote access | MFA on VPN / remote desktop / Conditional Access — no password-only path from home |
| Lost/stolen plan | Who to call, how to wipe or revoke, how to kill cloud sessions the same day |
| Mailbox hygiene | No silent forward to personal Gmail; inbox-rule audits; external sender awareness (email security) |
That table is a device and remote-work bar. It does not replace backups, SOC coverage, or a written incident plan for the whole shop — those live in the agency requirements and carrier-controls posts.
How should MFA work for producers who live in the field?
Producers will push back on friction. Friction that stops a stolen password from opening the book of business is the point.
- MFA on Microsoft 365 or Google Workspace for every producer mailbox.
- MFA on the AMS and any comparative rater that holds client data.
- Prefer authenticator apps or hardware keys over SMS when you can.
- Do not leave Global Admin or “the owner’s break-glass” on password-only “just in case.”
If a producer says MFA breaks their workflow, fix the workflow — enrollment support, backup methods, Conditional Access tuned to real devices — do not turn MFA off for the rainmakers.
Why does disk encryption matter more than another policy PDF?
Because laptops get left in cars. An unencrypted drive is readable with a screwdriver and a spare afternoon. Full-disk encryption does not stop a live phishing session. It does stop a cold disk from becoming an instant client-file dump.
BitLocker (Windows) or FileVault (Mac), escrow the recovery key in a place the agency can reach after the producer leaves, and refuse “I’ll encrypt it later” for any machine that syncs SharePoint, OneDrive, or downloads applications.
What about patching and “real” endpoint protection?
Unsupported Windows, a browser six versions behind, or a PDF reader nobody updates is how drive-by and document malware still work. Keep a tracked cadence for critical patches — carriers ask about this on questionnaires for a reason.
Antivirus logos on a renewal form are not enough. You want endpoint detection and response with investigation behind it. On SAINT engagements that is Huntress or Guardz — one core design, not both stacked for theater. Details: /cybersecurity. Day-to-day device care sits with managed IT.
VPN, Zero Trust, and working from the kitchen table
Password-only remote desktop exposed to the internet is still a favorite ransomware door. If producers need the office network or a jump host:
- Put MFA on every remote path.
- Prefer modern Conditional Access / Zero Trust access to apps over a flat VPN into the whole LAN when you can.
- Retire the ancient SSL VPN appliance that only the “IT cousin” remembers how to patch.
Home Wi-Fi is fine for browser AMS work if identity and the device are solid. A flat tunnel that drops a kitchen laptop onto the same VLAN as the file server is not fine.
Lost or stolen — what does a usable playbook look like?
Write it before the call at 9 p.m. Minimum steps:
- Producer (or office manager) reports loss immediately — same day, not Monday.
- IT revokes Microsoft / Google sessions and resets the password.
- Remote wipe or lock if MDM or Intune / Jamf is enrolled.
- Check mailbox forwarding and inbox rules — attackers love persistence.
- Rotate any passwords or tokens that lived in the browser.
- Document time, device ID, and what data may have been offline on disk.
If you need a human while that is in flight: 531-625-2111. Broader email fraud patterns for the office: business email compromise hub.
Mailbox hygiene for agencies that live in Outlook
Producer mail is often the real filing cabinet. Minimum hygiene:
- Block or alert on auto-forwarding to external personal addresses.
- Periodic inbox-rule reviews for anyone who touches payments or policy docs.
- No shared “producer@” password passed around at open enrollment.
- Seasonal / 1099 access gets a start date and an end date — same theme as the agency requirements guide, applied to the device and the mailbox.
Personal Gmail as the backup filing system for client PDFs is convenient until it is the incident.
How does this connect to cyber insurance questionnaires?
Carriers still ask about MFA, EDR, patching, and remote access. Producer laptops are where those answers go soft: “users have MFA” while the rainmaker’s home PC does not, or “we encrypt laptops” while BYOD never enrolled.
Score yourself on the same list we use publicly: free insurability check. Then put device gaps on a written plan. We help with evidence and remediation. We do not bind coverage and we are not your broker.
A practical checklist you can run this month
- Inventory every laptop and phone that opens agency email or AMS.
- MFA coverage export — find the gaps, especially admins and producers.
- Encryption status on every portable device; escrow recovery keys.
- EDR installed and checking in; retire AV-only outliers.
- Kill password-only VPN / RDP; require MFA on remote access.
- One-page lost/stolen procedure with names and the after-hours number.
- Disable casual external forwarding; spot-check inbox rules.
- Offboard last quarter’s departed producers from devices and cloud.
Lincoln and Omaha agencies can run that list without a 200-seat MSP contract. If you already have an MSP and cannot get a device inventory or an MFA export, that is a finding — vendor assessments exist for the paper trail; switching is optional.
When this post is not enough
- You need the full agency control set → IT requirements for independent insurance agencies.
- Renewal questionnaire is on the desk → 12 controls carriers verify + /tools/insurability.
- You already suspect mailbox or payment fraud → BEC hub and call 531-625-2111.
SAINT is veteran-owned and founder-led. We will not invent carrier stats, rate cards, or a guarantee that hardened laptops erase human trust mistakes. We will help you put a bar you can evidence.
Get the device gap list in writing. Free Security & IT Assessment · insurance agencies · 531-625-2111.

