A local government had answered yes to the cyber insurance firewall question for years, in good faith. The firewall had never been plugged in. What an onboarding inventory found, and why the paperwork gap mattered more than the hardware.
The situation
A local government came to Tech Dynamix as a new client, and the engagement started the way every engagement here starts: before changing anything, we document what exists. What is running, what state it is in, and what depends on it.
That inventory turned up a firewall, a real one, sitting installed in the rack. It was not plugged in.
The story behind it was simple and nobody had ever assembled it in one place. Whenever the firewall was connected, the network went down, so at some point somebody had unplugged it to keep the office working, and it had stayed unplugged. The device was never configured correctly, and rather than being fixed, it was quietly routed around. The previous IT arrangement reported that a firewall was in place, which was true in the narrowest possible sense: one had been purchased and mounted.
Meanwhile, every year, the office renewed its cyber insurance. And every year, somebody answered the questionnaire's firewall question with yes, in complete good faith, because that is what they had been told.
- A firewall in the rack, unplugged, because plugging it in took the network down
- Nothing actually doing the job the firewall was bought for
- A cyber insurance application answered yes, honestly, and wrongly, year after year
That last item is the one that matters most, and the client had no idea it was happening. A false answer on a cyber insurance application, however innocently given, is exactly the kind of thing a carrier can point to when it is deciding whether to pay a claim. The policy the office believed it had may not have been the policy it actually had, and it would have found out at the worst possible moment: after an incident, during the claim.
What we did
What we did
There is no criticism of anyone in this story worth writing. A firewall that takes the network down when you plug it in is a configuration problem, and configuring one correctly for a working office, with its applications, its traffic, and its quirks, is specialist work. The failure was not that somebody unplugged it. The failure was that the gap between "we bought one" and "we have one" went unmeasured for years, and answers kept flowing to an insurance form out of that gap.
The fix was not dramatic, which is rather the point.
Tech Dynamix replaced the aging unit with a current firewall and configured it around how the office actually works: what needed to pass, what needed to be blocked, and what needed to be watched. It went in as part of the onboarding, and the network did what a correctly configured network does when the firewall comes online, which is nothing visible at all. It stayed up. Everyone kept working.
From that day, the insurance answer became true.
Where it landed
The office has been a managed client for several years now, and its cyber insurance has just renewed again, this time on answers that describe the network as it actually is.
- A configured firewall doing its job, monitored as part of the managed agreement
- An insurance questionnaire that can be answered from documentation rather than from inherited assurances
- A network that stayed up on the day the firewall came online, and since
For a local government the stakes on this have only gone up since. Public offices hold exactly the data attackers want, and insurers have responded by asking harder questions and checking answers more carefully after incidents. An answer that cannot be traced to something real is not protection, it is a time bomb inside the policy.
The wider lesson applies to any organization that has ever answered a security questionnaire with what it was told rather than what it verified. The question on the form is not "did somebody say you have a firewall." Documentation is the difference, and it is why our engagements begin with an inventory rather than a proposal: the most valuable thing we found in that rack was not the firewall. It was the gap between the paperwork and the wall.
The numbers
| What changed | Before | After |
|---|---|---|
| The firewall | In the rack, unplugged | Current, configured, running |
| When it was plugged in | The network went down | Nothing visible happened |
| The insurance question "do you have a firewall" | Answered yes, in good faith, falsely | Answered yes, verifiably |
| Where the answer came from | What somebody had been told | Documentation |
What it changed
- The office has been a managed client for several years since, and its cyber insurance has just renewed on answers that describe the network as it actually is.
- The fix took an onboarding, not a crisis. The alternative version of this story ends with a denied claim after an incident, and nobody in it would have known why until then.