Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

The 3 Security Controls Every Rockland Business Needs Before Insurance Renewal

CybersecurityManaged IT
Last updated: September 9, 2026

Before a renewal, Rockland businesses need three controls that are actively maintained rather than merely installed: detection somebody watches, a firewall that’s still patched and supported, and a backup that has been restore-tested and can be proven.

Owning a security product and maintaining one are different things. Very different. Underwriters worked that out a while ago, and the questions on a renewal application have quietly shifted to match.

The baseline set of controls hasn’t changed. My colleague and I covered those in the piece on MFA, EDR and backups, and if you’ve never been through this before, start there. What follows is the layer after that one. Same controls. Harder question. Not do you have it, but is anyone keeping it true.

That distinction is where most of the flagged applications I see actually come from. Nearly all of them, if I’m honest.

Installed Is Not the Same as Maintained

A control bought in 2023 and untouched since is not the control an underwriter is pricing. They’re pricing the version running today, on every device, with somebody accountable for it. Present tense throughout.

Ask what “we have a firewall” actually tells you. Nothing about firmware. Nothing about whether the rules still match how the business operates, or whether the vendor still ships security updates for that model. The box is present. That is the entire claim.

Same problem with detection software that generates alerts nobody triages, and with backup jobs reporting success into an inbox nobody opens. All three are real controls, all three are worth owning, and all three can be simultaneously true on an application and useless in practice, which is precisely the condition underwriters have spent the last few years learning to price for.

Renewal questionnaires have started asking the second question, and that’s what the three sections below are about.

Control One: Detection Somebody Actually Watches

Endpoint detection catches behavior rather than known signatures, which is the distinction we pulled apart in the EDR versus antivirus piece. Deploying it is the easy half.

So what happens when it fires at 6:40 on a Thursday evening? That’s the hard half. An alert that lands in a console nobody is responsible for is documentation of an incident, not a defense against one. Carriers have caught up to this, and applications increasingly ask whether alerts are acted on rather than merely produced.

Worth being precise about what that looks like at our size, because the marketing in this category is genuinely misleading. Managed detection and response as we run it means continuous automated monitoring, a real team triaging what comes in, immediate response during business hours, and a documented escalation path after hours. Not a staffed security operations center watching screens at 3am. Any small-business provider claiming that at a small-business price is worth a hard question.

An honest description of coverage answers the underwriter’s question better than an overstated one, and more to the point it holds up twelve months later when somebody compares what the application promised against what was actually running on the night it mattered.

Control Two: A Firewall That Hasn’t Been Left Alone

This is the control that gets skipped. Every time. It’s also the one I’d argue has moved most in the last two years.

Network edge devices are now among the most reliably exploited things on the internet, because they sit exposed by definition and they run software that ages. CISA maintains a catalog of vulnerabilities under active exploitation, and firewalls, VPN appliances and gateways appear on it constantly. In late 2025 the agency went further and issued an emergency directive over compromised network devices, which is not something that happens over a theoretical risk.

None of that requires a new firewall. Buy nothing. It requires the one you own to be patched on a schedule, to have its rules reviewed as the business changes, and to be replaced before the manufacturer stops issuing security updates for it.

Three things to check here. When was the firmware last updated. Who reviewed the rule set most recently. And is that model still supported by the vendor, because a device past end of support stops receiving fixes for exactly the vulnerabilities that catalog tracks.

If those answers aren’t available, the honest position on the application is that the firewall is present and unmanaged, and a managed firewall is the difference between those two answers.

Control Three: A Backup You Can Prove

Backups are where confidence outruns evidence more than anywhere else on the form. By a distance.

Two properties now matter beyond the job completing. Only two. The copy needs to be immutable or genuinely offline, so ransomware that reaches your production data can’t reach the recovery path with it. And a restore has to have actually been performed, recently, by somebody who wrote down when and how long it took. NIST’s contingency planning guidance is unambiguous that testing recovery is part of the control, not an optional extra once the plan exists.

A restore test produces something an underwriter can read. Paperwork, finally useful. That’s the quiet advantage. Most of the controls on an application are hard to evidence, and this one hands you a dated artifact almost for free, which is why restore-tested backup tends to be the fastest gap to close credibly.

What Maintained Looks Like on Paper

Three columns. The middle one is where most businesses actually sit, and the right one is what gets asked about at renewal.

ControlInstalled Looks LikeMaintained Looks Like
Detection and responseAgent deployed, alerts landing in a consoleAlerts triaged by a named team, with a written escalation path and a record of what was acted on
Firewall and network edgeDevice present and passing trafficFirmware patched on a schedule, rules reviewed, model still vendor-supported, with patch history retained
Backup and recoveryNightly job reporting successImmutable or offline copy, plus a dated restore test somebody performed and logged

Read the right-hand column again and notice how much of it is a record rather than a technology. That’s deliberate on the underwriter’s part. Evidence is the thing that survives a claim review, and how to assemble it is its own subject, covered in the piece on proof versus promises.

Where Rockland Businesses Usually Sit

Across the professional practices, medical offices, contractors and small manufacturers we work with in Rockland, the pattern is consistent and it isn’t negligence.

Detection is usually the most current of the three, because it tends to arrive bundled with something bought recently and therefore inherits somebody else’s upgrade cycle whether the business planned for it or not. The firewall is usually the oldest thing in the building, installed once by whoever wired the office and never revisited. Backups sit in between, running reliably and untested. Sound familiar?

Nobody chose that arrangement. It’s what happens when three controls have three different natural lifespans and no single person owns the calendar for any of them. Which is, more or less, the argument for managing them rather than buying them. One owner, one calendar.

What Owners Ask Me Before a Renewal

We bought all three of these. Isn’t that the same thing?
It’s most of the way there, and the remaining gap is what gets priced. Purchase proves capability existed on the day of purchase. A renewal question is about the present tense, on every device, with someone accountable. The businesses that get flagged usually bought correctly and then nobody owned the upkeep.
Our firewall works fine. Why would it need managing?
Working and being current are separate conditions, unfortunately. A firewall passing traffic normally can be running firmware with publicly known vulnerabilities, or rules written for an office layout you changed two years ago. Neither shows up as a symptom. Both show up on a questionnaire that asks when it was last patched and reviewed.
Does monitored mean somebody is watching a screen at three in the morning?
No, and I’d be careful with anyone who says otherwise at this price point. What we run is continuous automated monitoring with a real team triaging alerts, immediate response during business hours, and a documented escalation process after hours. That’s an honest answer on an application, and it’s a materially better one than a staffed-SOC claim that doesn’t survive scrutiny.
How would we even prove any of this to an underwriter?
Three artifacts cover most of it. A device list from the detection console showing what’s actually reporting, a patch and configuration history for the firewall, and a dated restore test log. None of those take long to produce if the work is genuinely being done, and the time it takes to produce them is itself a reasonable measure of whether it is.
Renewal is six weeks out. Which one moves fastest?
The restore test, almost always. It’s a scheduled piece of work with a defined end, and it produces a dated document at the finish. Firewall firmware and rule review come next. Anything involving changing how detection is monitored takes longer, because you’re changing a process rather than running a task.
Our firewall is about five years old. Does age by itself matter?
Age matters only through support status, which is the thing worth checking. Plenty of five-year-old hardware is still receiving security updates and is perfectly defensible. Some three-year-old models aren’t. Find the vendor’s end-of-support date for your exact model, because once that passes, no amount of managing compensates for fixes that will never ship.
Find Out Which of the Three Is Actually Being Maintained

A free assessment checks what’s deployed, what’s current, and what you could evidence tomorrow if an underwriter asked. No obligation, and the findings are yours either way.

Get Your Free IT Assessment →

Or call (845) 440-5000