Managed IT
Renewal applications ask whether you have a firewall, and everybody answers yes. The follow-up questions are the ones that decide your premium: when the rules were last reviewed, who reads the logs, whether the firmware is current, and how quickly somebody could respond. A device on the rack answers the first question. Only a process answers the rest.
Underwriters are not asking about your firewall because it is a box worth having. They are asking because claims data tells them something specific about the businesses that get breached, and a firewall nobody has touched in two years turns out to be a reliable indicator of how the rest of the environment is run.
Why the firewall is on the application
The Sophos Threat Report puts 60% of breached organizations as having an improperly configured or unmanaged firewall at the time of the breach. Not an absent firewall. One that was there and was not being managed.
Verizon's 2024 Data Breach Investigations Report identifies network perimeter compromise as the leading initial access method in confirmed data breaches, which is to say the perimeter is where attackers most often get their first foothold. And the Ponemon Institute puts 18 months as the average time since a typical SMB firewall was last meaningfully reviewed or updated.
Put those together and you can see the underwriter's logic. The perimeter is the most common way in, most firewalls are stale, and staleness correlates with breach. That makes "do you have a firewall" a near-useless question and "how is it managed" a genuinely predictive one.
It is also a proxy for everything else
Worth understanding, because it explains why the questions get specific. Firewall management is visible, evidenceable and easy to verify from logs and configuration exports. A business that reviews rules quarterly and patches firmware on a schedule is very unlikely to be neglecting patching elsewhere. Underwriters use the perimeter as a reliable signal about operational discipline they cannot otherwise inspect.
What "actively managed" means to a carrier
The Three Parts
The phrase appears on applications without a definition attached, which is unhelpful when the answer affects your premium. In practice it resolves to three things, and a firewall that satisfies two of them is not managed.
What good looks like
Rules reviewed on a schedule
Documented review cadence · Change control · Stale rules removed · Business justification recorded
Firewall rules accumulate. A port opened for a vendor project in 2021, an any-any rule added at 6pm to get something working that nobody narrowed afterwards, an exception for a supplier who no longer exists. None of it announces itself, and every entry is an opening that was justified once and has not been revisited since. Active management means a scheduled audit that asks of each rule whether it is still needed and who owns it, with removals documented. That documentation is what turns a claim of review into evidence of one.
What good looks like
Firmware current and supported
Patched on a cadence · Vendor still shipping updates · End-of-life tracked · Emergency path
Firewall firmware is the most commonly deferred patching in most environments, because applying it usually means planned downtime somebody has to approve. The consequence is that the device inspecting all your traffic is frequently the one running the oldest code. Worse is a firewall past vendor end-of-support, which continues working perfectly while no longer receiving security fixes at all. That is a question applications increasingly ask directly, and it is one of the few dates you can know years in advance.
What good looks like
Logs watched by somebody
Retention period defined · Alerts triaged · Out-of-hours coverage · Response authority
Logging is enabled almost everywhere. Being read is much rarer, and the distinction is the whole of this part. A firewall generating alerts into a mailbox nobody opens is producing an audit trail rather than a defense. Carriers ask about monitoring because unread logs are how a perimeter compromise sits undetected for months. The follow-up worth preparing for is who responds outside business hours and whether they are permitted to tighten rules without waiting for approval.
Two out of three is a gap
These fail in combination rather than isolation. Current firmware with stale rules means a well-patched device enforcing a policy that no longer matches the business. Reviewed rules with unread logs means a good configuration nobody would notice being probed. Monitoring on a device past end-of-support means watching an attack against something that can no longer be fixed.
What you will be asked to evidence
Applications have shifted from yes-or-no questions to requests for proof, and the proof is usually easier to produce in advance than during a renewal window. Requirements vary by carrier, policy and year, so read your own form. These are the items that come up most.
A current configuration export
The rule set as it stands. This is the artifact that shows whether the policy is deliberate or accumulated, and it is the one most likely to be requested after an incident rather than before one.
Evidence of the last rule review
A date, who did it, and what changed. A review that produced no removals across eighteen months invites the question of whether it was a review. Recording what was taken out is what makes the process credible.
Firmware version and support status
The version running, when it was applied, and confirmation the device is still within vendor support. This is a fast question to answer if somebody tracks it and an awkward one otherwise.
Log retention period
How long perimeter logs are kept. Given how long intrusions commonly go unnoticed, retention shorter than your likely detection gap means the evidence is gone before anyone looks for it. Underwriters and incident responders both ask.
Who responds, and how fast
Named responsibility for alerts outside business hours, and whether that person can act without escalation. Saying that a provider monitors it invites the follow-up of what they are contracted to do when something fires, which is worth knowing before you are asked.
Answer accurately
One point worth stating plainly. Insurance applications are underwriting documents, and answers about controls can be revisited when a claim is made. Describing a firewall as actively managed when nobody has reviewed the rules in two years is not an optimistic framing, it is a misrepresentation on a document that matters. If a control is not in place, the better move is to say so and fix it, rather than to discover the discrepancy during a claim.
Firewall Assessment Checklist
The Checklist
Fifteen questions across posture, firmware, rule hygiene and monitoring. Tick the ones you can answer without going and asking someone, and the score updates as you go. Use it yourself or share it with your team.
Tick what you can answer without checking. The blanks are the gaps.
Firewall Posture
Do you know how many firewalls you actually have?
Branch offices and legacy sites produce devices nobody has counted since they were installed.
Is the management interface reachable from the internet?
One of the fastest checks available, and a finding that changes an underwriter's view immediately.
Does anyone still use the default or a shared admin password?
Shared credentials also mean no accountability for who changed what.
Could you produce a current configuration export today?
The artifact most likely to be requested after an incident, and the slowest to find under pressure.
Firmware & Patching
What firmware version is running, and when was it applied?
A date. The device inspecting all your traffic is often the one running the oldest code.
Is the device still within vendor support?
Past end-of-support it keeps working perfectly while no longer receiving security fixes at all.
Is there a scheduled window for firmware updates?
Without one, updates wait for a quiet week that never quite arrives.
Who approves the downtime an update requires?
Usually the real blocker. Naming the approver in advance is most of the fix.
Rule Age & Hygiene
When were the rules last reviewed, and what was removed?
A review that removed nothing in eighteen months invites the question of whether it happened.
Are there any any-to-any rules still in place?
Added at 6pm to get something working, never narrowed afterwards. Almost every rule set has one.
Does every rule have a business justification recorded?
Without one, nobody can safely remove anything, so the policy only ever grows.
Are there rules for vendors or projects that ended?
An opening justified once, for a supplier who may no longer exist.
Logging & Monitoring
Is anyone actually reading the logs?
Enabled and reviewed are different states. Unread logs are an audit trail, not a defense.
How long are perimeter logs retained?
Retention shorter than your likely detection gap means the evidence is gone before anyone looks.
Who responds at 3am, and can they change rules without approval?
Containment measured in minutes needs that authority agreed in advance, not requested mid-incident.
Frequently asked questions
Applications have largely moved past asking whether a firewall exists, because nearly every business answers yes. The questions that carry weight are about operation: when the rule set was last reviewed, whether firmware is current and still within vendor support, whether logs are monitored and by whom, and how quickly somebody could respond outside business hours. Specific wording varies by carrier, policy and year, so the form in front of you is the only authority on what yours asks.
In practice it resolves to three things running together. Rules are reviewed on a documented schedule with stale entries removed and changes recorded. Firmware is patched on a cadence and the device remains within vendor support. Logs are monitored by somebody who can act on what they see, including outside business hours. A firewall that satisfies two of the three is not actively managed, because each part covers a failure the others do not.
Frequently enough that rules do not outlive their purpose, which for most organizations means a scheduled quarterly or half-yearly audit rather than an annual one. The Ponemon Institute puts the average time since a typical small or mid-sized business firewall was last meaningfully reviewed at 18 months. What matters as much as the interval is that each review records what was removed and why, since a review producing no removals is difficult to distinguish from no review at all.
Yes, and it is among the most commonly deferred patching in most environments because applying it usually requires planned downtime that somebody has to approve. The result is that the device inspecting all your traffic is often the one running the oldest code. The more serious version is a firewall past vendor end-of-support, which continues to function normally while no longer receiving security fixes at all. End-of-life dates are published well in advance, so this is one you can plan for.
Rule sprawl is the gradual accumulation of firewall rules that were each justified when added and never reviewed afterwards. Typical examples include a port opened for a vendor project that finished years ago, a broad any-to-any rule added under time pressure and never narrowed, and exceptions for suppliers no longer engaged. The problem compounds because without a recorded business justification for each rule, nobody can safely remove anything, so the policy only ever grows.
Monitoring appears on most applications, because unread logs are how a perimeter compromise sits undetected for an extended period. Logging is enabled almost everywhere while being actively reviewed is much rarer, and that distinction is what the question is aimed at. Expect follow-ups on how long logs are retained and who responds outside business hours, since a retention period shorter than your likely detection gap means the evidence is gone before anyone goes looking for it.
Five items come up most often: a current configuration export showing the rule set as it stands, evidence of the last rule review including the date and what changed, the firmware version with its support status, the log retention period, and named responsibility for responding to alerts outside business hours. All five are considerably easier to assemble in advance and keep current than to produce under a renewal deadline with a quote about to expire.
Requirements vary by carrier and policy, so check your own application rather than assuming a general standard. What is consistent across applications is more interest in how the device is operated than in which product it is. A current next-generation firewall nobody has reviewed in two years tends to answer these questions worse than an older device with documented rule reviews, current firmware and monitored logs. The management process is what is being underwritten.
Renewal coming up?
Get a free firewall assessment. We'll walk the checklist with you, review the rule set, and get your evidence ready before the application lands.



