Before a renewal, Rockland businesses need three controls that are actively maintained rather than merely installed: detection somebody watches, a firewall that’s still patched and supported, and a backup that has been restore-tested and can be proven.
Owning a security product and maintaining one are different things. Very different. Underwriters worked that out a while ago, and the questions on a renewal application have quietly shifted to match.
The baseline set of controls hasn’t changed. My colleague and I covered those in the piece on MFA, EDR and backups, and if you’ve never been through this before, start there. What follows is the layer after that one. Same controls. Harder question. Not do you have it, but is anyone keeping it true.
That distinction is where most of the flagged applications I see actually come from. Nearly all of them, if I’m honest.
Installed Is Not the Same as Maintained
A control bought in 2023 and untouched since is not the control an underwriter is pricing. They’re pricing the version running today, on every device, with somebody accountable for it. Present tense throughout.
Ask what “we have a firewall” actually tells you. Nothing about firmware. Nothing about whether the rules still match how the business operates, or whether the vendor still ships security updates for that model. The box is present. That is the entire claim.
Same problem with detection software that generates alerts nobody triages, and with backup jobs reporting success into an inbox nobody opens. All three are real controls, all three are worth owning, and all three can be simultaneously true on an application and useless in practice, which is precisely the condition underwriters have spent the last few years learning to price for.
Renewal questionnaires have started asking the second question, and that’s what the three sections below are about.
Control One: Detection Somebody Actually Watches
Endpoint detection catches behavior rather than known signatures, which is the distinction we pulled apart in the EDR versus antivirus piece. Deploying it is the easy half.
So what happens when it fires at 6:40 on a Thursday evening? That’s the hard half. An alert that lands in a console nobody is responsible for is documentation of an incident, not a defense against one. Carriers have caught up to this, and applications increasingly ask whether alerts are acted on rather than merely produced.
Worth being precise about what that looks like at our size, because the marketing in this category is genuinely misleading. Managed detection and response as we run it means continuous automated monitoring, a real team triaging what comes in, immediate response during business hours, and a documented escalation path after hours. Not a staffed security operations center watching screens at 3am. Any small-business provider claiming that at a small-business price is worth a hard question.
An honest description of coverage answers the underwriter’s question better than an overstated one, and more to the point it holds up twelve months later when somebody compares what the application promised against what was actually running on the night it mattered.
Control Two: A Firewall That Hasn’t Been Left Alone
This is the control that gets skipped. Every time. It’s also the one I’d argue has moved most in the last two years.
Network edge devices are now among the most reliably exploited things on the internet, because they sit exposed by definition and they run software that ages. CISA maintains a catalog of vulnerabilities under active exploitation, and firewalls, VPN appliances and gateways appear on it constantly. In late 2025 the agency went further and issued an emergency directive over compromised network devices, which is not something that happens over a theoretical risk.
None of that requires a new firewall. Buy nothing. It requires the one you own to be patched on a schedule, to have its rules reviewed as the business changes, and to be replaced before the manufacturer stops issuing security updates for it.
Three things to check here. When was the firmware last updated. Who reviewed the rule set most recently. And is that model still supported by the vendor, because a device past end of support stops receiving fixes for exactly the vulnerabilities that catalog tracks.
If those answers aren’t available, the honest position on the application is that the firewall is present and unmanaged, and a managed firewall is the difference between those two answers.
Control Three: A Backup You Can Prove
Backups are where confidence outruns evidence more than anywhere else on the form. By a distance.
Two properties now matter beyond the job completing. Only two. The copy needs to be immutable or genuinely offline, so ransomware that reaches your production data can’t reach the recovery path with it. And a restore has to have actually been performed, recently, by somebody who wrote down when and how long it took. NIST’s contingency planning guidance is unambiguous that testing recovery is part of the control, not an optional extra once the plan exists.
A restore test produces something an underwriter can read. Paperwork, finally useful. That’s the quiet advantage. Most of the controls on an application are hard to evidence, and this one hands you a dated artifact almost for free, which is why restore-tested backup tends to be the fastest gap to close credibly.
What Maintained Looks Like on Paper
Three columns. The middle one is where most businesses actually sit, and the right one is what gets asked about at renewal.
| Control | Installed Looks Like | Maintained Looks Like |
|---|---|---|
| Detection and response | Agent deployed, alerts landing in a console | Alerts triaged by a named team, with a written escalation path and a record of what was acted on |
| Firewall and network edge | Device present and passing traffic | Firmware patched on a schedule, rules reviewed, model still vendor-supported, with patch history retained |
| Backup and recovery | Nightly job reporting success | Immutable or offline copy, plus a dated restore test somebody performed and logged |
Read the right-hand column again and notice how much of it is a record rather than a technology. That’s deliberate on the underwriter’s part. Evidence is the thing that survives a claim review, and how to assemble it is its own subject, covered in the piece on proof versus promises.
Where Rockland Businesses Usually Sit
Across the professional practices, medical offices, contractors and small manufacturers we work with in Rockland, the pattern is consistent and it isn’t negligence.
Detection is usually the most current of the three, because it tends to arrive bundled with something bought recently and therefore inherits somebody else’s upgrade cycle whether the business planned for it or not. The firewall is usually the oldest thing in the building, installed once by whoever wired the office and never revisited. Backups sit in between, running reliably and untested. Sound familiar?
Nobody chose that arrangement. It’s what happens when three controls have three different natural lifespans and no single person owns the calendar for any of them. Which is, more or less, the argument for managing them rather than buying them. One owner, one calendar.
What Owners Ask Me Before a Renewal
We bought all three of these. Isn’t that the same thing?
Our firewall works fine. Why would it need managing?
Does monitored mean somebody is watching a screen at three in the morning?
How would we even prove any of this to an underwriter?
Renewal is six weeks out. Which one moves fastest?
Our firewall is about five years old. Does age by itself matter?
A free assessment checks what’s deployed, what’s current, and what you could evidence tomorrow if an underwriter asked. No obligation, and the findings are yours either way.