Home | Cyber insurance questionnaire | EDR
Cyber insurance EDR questions: how to answer them
Australian cyber insurance proposal forms ask whether endpoint detection and response covers 100% of your servers and 100% of your endpoints, whether automated enforcement is switched on, and what compensating controls exist where coverage falls short. The answers are banded rather than yes or no, so partial coverage is accepted and stated honestly. What you cannot do is claim a coverage percentage you have no inventory to prove.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner

Key facts
- Insurers ask about server coverage and endpoint coverage as two separate questions, with bands of 100%, 90% or more, less than 90%, or no endpoint detection and response deployed.
- Coverage percentages are only provable against a complete hardware inventory, which is why the inventory question should be answered first.
- Proposal forms ask separately whether automated rules-based enforcement is enabled, meaning automatic isolation or remediation rather than alerts alone.
- Where coverage falls below 90%, forms invite a list of compensating controls: application allowlisting, an endpoint protection platform, a next generation firewall, intrusion detection or prevention, and web or URL filtering.
- Compensating controls turn a weak answer into an acceptable one, so a business does not have to reach 100% coverage to get a workable outcome.
- Alert-only detection with nobody monitoring overnight does not meet the intent of the automated enforcement question, even though the deployment technically exists.
Why insurers ask about this in so much detail
Endpoint detection and response is the control that determines whether an intrusion is caught during the reconnaissance phase or discovered when files start encrypting. Insurers care about coverage percentage specifically because attackers do not need the protected machines. They need the one that was missed: the machine attached to a piece of equipment, the server nobody wanted to touch, the laptop belonging to someone who left.
The automated enforcement question exists for a related reason. Most intrusions in Australian small and medium businesses progress outside business hours, and a platform that raises an alert nobody reads until 8am has given the attacker a full night. Longer proposal forms define this as a mechanism actively monitoring and enforcing rules to respond to a threat, which is a description of automatic action or of a service with humans watching, not of a dashboard.
The questions below come from Australian cyber insurance proposal forms current as at September 2026. No insurer is named, and where forms differ the stricter wording is used. The full set of 45 technical questions is on the cyber insurance questionnaire guide.
The endpoint protection questions insurers ask
Have you deployed an EDR tool that covers 100% of your servers?
Australian cyber insurance proposal forms ask this with four possible answers: coverage of 100%, coverage of 90% or more, coverage of less than 90%, or no endpoint detection and response tool deployed. Servers are asked about separately from workstations because a compromised server is a far larger event than a compromised laptop.
To answer 100% you need an agent on every server, including hypervisors, domain controllers, and any appliance or virtual machine that will accept one. Where something cannot take an agent at all, and there is usually at least one such device, it belongs on a documented exception list with the control that protects it instead, most often network segmentation.
The evidence is an agent coverage report reconciled against the server inventory, and the reconciliation is the whole point. A coverage report on its own shows the percentage of known servers protected, which is a different and much more flattering number than the percentage of actual servers protected. Insurers are asking about the second one.
Have you deployed an EDR tool that covers 100% of your endpoints?
The same four bands apply to workstations and laptops. The answer is easier to reach than on servers because endpoint agents deploy through management tooling, but it is harder to prove, because the endpoint population changes constantly as people join, leave and replace hardware.
What you need is an agent on every company-owned workstation and laptop, plus a stated position on personal devices that access company data. Personal devices are the usual gap. A business with a bring your own device arrangement and no management on those devices has a coverage figure that looks strong on paper and a real exposure that the figure does not describe. Being clear about which devices are in scope is more credible than a bare 100%.
Hold a coverage report reconciled against the device inventory, plus the count of unmanaged devices that touch company data. This question connects to the bring your own device policy that proposal forms ask about separately, and the two answers should tell the same story.
Is AI or automated rules-based enforcement enabled?
Longer proposal forms ask this as a sub-question and define it as a mechanism designed to enforce predefined rules within security systems, actively monitoring and enforcing conditions to respond to a threat. In plain terms, the insurer is asking whether something acts when a detection fires, or whether it only records that a detection fired.
What satisfies it is automatic isolation or remediation enabled in policy rather than the platform running in detect-only mode, or a managed detection and response service where a security team responds around the clock. For most small and medium businesses the managed service is the more realistic answer, because automatic isolation without anyone available to investigate creates its own operational problem when it triggers at 2am on a machine somebody needs.
The evidence is the policy configuration showing the enforcement mode, or the managed detection and response service agreement. Answering yes because the platform is capable of automated response, when it is deployed in detect-only mode, is the trap here. Capability and configuration are different things and the question is about configuration.
If EDR covers less than 90%, what compensating measures have you implemented?
Proposal forms follow the coverage questions with a list of alternatives: application allowlisting, an endpoint protection platform, a next generation firewall, intrusion detection or prevention, web and URL filtering, and a free text option. This is the most useful question on the page for a business that cannot reach full coverage, because it exists specifically to let a partial answer still be a good one.
What to have in place depends on what is uncovered. If the gap is an unsupported machine running a piece of equipment, application allowlisting on that host plus network segmentation is a strong answer. If the gap is spread across older workstations, an endpoint protection platform on those machines plus web filtering covers a large share of the risk. The requirement is that whatever you claim is configured, documented, and matched to the specific gap it addresses.
Hold configuration evidence for each control claimed. A business at 85% coverage with three named compensating controls and a documented exception list presents better to an underwriter than a business claiming 100% that cannot produce an inventory to support it. Precision beats optimism on this form.
The evidence to assemble before the form arrives
Four artefacts cover all four questions:
- A current hardware inventory covering servers and endpoints, generated from a management platform rather than maintained by hand.
- An agent coverage report reconciled against that inventory, with the reconciliation shown.
- A documented exception list naming every uncovered device and the compensating control protecting it.
- The policy configuration showing enforcement mode, or the managed detection and response agreement.
These controls overlap with several strategies in the Australian Signals Directorate Essential Eight, particularly application control and patching applications. The Essential Eight guide for Australian SMEs sets out how they fit together, and the framework is published by the Australian Cyber Security Centre at cyber.gov.au.
One thing not to do
Do not claim 100% coverage from a management console that only reports on machines it already manages. That is the most common inaccurate answer in this section, and it is inaccurate by omission rather than intent: the number is correct as far as the console can see, and the console cannot see the machines that were never enrolled. Reconciling against an independent inventory, such as a network scan or the asset register, usually finds two or three devices. Finding them yourself before the form goes in is a considerably better outcome than an insurer’s investigator finding them after an incident.
If a cyber insurance questionnaire has landed and you are not confident of the coverage number, 4iT reconciles the agent report against a real inventory, documents the exceptions with the controls that cover them, and produces the evidence pack the underwriter will ask for. Request a callback and we will work out where you stand.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.







