Does the Applicant employ intrusion detection/prevention?
The question was written for an era of network appliances. In a cloud-first estate the honest answer describes a different set of controls that do the same job.
What the carrier is actually asking
The carrier is asking whether malicious traffic is detected and, ideally, blocked. Traditionally that meant an appliance inspecting network traffic. Today the same function is delivered by cloud-native threat detection, endpoint detection, and identity protection.
Why it is underwritten
Detection determines dwell time, and dwell time determines how much of the estate is affected before anyone notices. Carriers ask because insureds who detect in hours have incidents and insureds who detect in months have claims.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Cloud-native detection is measurable. Network appliances are attested.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Azure | Defender for Cloud plans across resource types | Threat detection enabled for servers, storage, databases, and the resource manager plane |
| Azure | Defender for DNS and Defender for Resource Manager | Detection on the two planes attackers use that traditional network monitoring never sees |
| Azure | Alert severity notification configuration | High-severity alerts route to a monitored destination rather than accumulating in the portal |
| Entra ID | Identity Protection risk detections | Identity-plane detection, which is where cloud-first intrusions actually begin |
| Network | Intrusion detection appliance or firewall inspection, where present | Signatures current and alerts monitored. Attested |
An estate with no network appliance and full cloud-native detection should answer yes and name the controls. Answering no because there is no hardware appliance understates a stronger position than the question anticipated.
What a defensible yes requires
- Detection covers the planes that matter for your estate: network, endpoint, identity, and cloud control plane.
- Alerts route to somewhere monitored with a response expectation.
- Prevention is enabled where it can be, not only detection.
- Coverage gaps are known, such as encrypted traffic that inspection cannot read.
- Detections are tuned, since an unmanageable alert volume becomes an unread one.
How this answer goes wrong
An appliance exists with signatures from three years ago and alerts flowing to an unmonitored mailbox. Or cloud-native detection is licensed and its alerts go nowhere. Both are detection without response, which produces evidence after the fact and prevents nothing.
Frequently asked
Do we need a network appliance?
Not in a cloud-first estate. Cloud-native detection and endpoint tooling cover the same ground more usefully. Describe what you have.
Detection or prevention?
Prevention where the confidence is high enough to block automatically, detection elsewhere. Most organisations run a mix, and saying so is accurate.
Who monitors the alerts?
Answer this explicitly, in-house or a managed provider with hours. It is asked separately on most forms and the answers should agree.
What about encrypted traffic?
Network inspection sees little of it, which is one reason endpoint and identity detection matter more than they used to.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture