Network, logging and monitoring

How is the Applicant's VPN infrastructure hosted (exclusively cloud-based, exclusively on-premises, or hybrid)?

The interesting consequence of this answer is who is responsible for patching the appliance, because that is where recent intrusions have concentrated.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether remote access infrastructure is cloud-based, on-premises, or a mix. It is a profiling question that sets up the follow-up about which product you use.

Why it is underwritten

On-premises concentrators are your responsibility to patch, and vulnerabilities in them have driven a significant share of recent ransomware intrusions. Cloud-delivered access shifts that burden to the provider. Neither answer is wrong; they carry different responsibilities.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Remote access infrastructure sits outside the cloud tenant unless it is cloud-delivered, so this is largely attested.

PlatformWhere the setting livesWhat has to be true
NetworkVPN concentrator location, model, and versionThe inventory of remote access infrastructure, including anything left over from a previous design. Attested
AzureVPN gateway or virtual WAN configuration, where cloud-hostedCloud gateway configuration, which is measurable and patched by the platform
Entra IDWhether remote access authenticates against the directoryFederated authentication, which brings Conditional Access into the remote access path
VendorZero trust network access or cloud-delivered access service, where usedThe service and its configuration. Attested
NetworkLegacy remote access paths still in placeDecommissioned properly rather than left listening, which is a recurring finding
The old concentrator is still listening

Organisations migrate to a new remote access solution and leave the previous appliance powered on, unpatched, and reachable. It no longer appears in any process because it is no longer the official solution. It is still an internet-facing service accepting credentials.

What a defensible yes requires

  • The full inventory of remote access paths is known, including legacy ones.
  • Where infrastructure is on-premises, firmware currency has an owner and a short patch window.
  • Authentication federates to the directory so one policy governs.
  • Decommissioned solutions are removed from the network rather than disabled in configuration.
  • The answer given here is consistent with the remote access multi-factor answer.

How this answer goes wrong

The answer describes the current solution and omits the legacy path that still exists. Or a hybrid estate is described as cloud-based because the new deployment is the one people think about.

Frequently asked

Is cloud-hosted better for underwriting?

Marginally, because patching moves to the provider and appliance vulnerabilities have been a major loss driver. The controls on the access matter more than the hosting model.

What counts as hybrid?

Any estate with more than one remote access path, which is most estates once you count the legacy ones. Disclose it accurately.

Does zero trust network access change the answer?

It usually means cloud-delivered with no inbound listener, which is a strong answer. Describe it rather than forcing it into one of the offered options.

What if we have no VPN?

Say so. A cloud-first estate with no inbound network path is a good position and worth stating explicitly.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture