The Insurance Information Gap
The Insurance Information Gap: Are Commercial Security Questionnaires Asking the Right Questions?
Executive Insight
Most commercial security questionnaires confirm that a system is installed. Far fewer determine whether that system will perform when attacked, faulted, or stressed under real conditions.
That distinction matters. Presence tells you a system exists; performance tells you whether it will protect the client when it counts. For carriers, brokers, owners of high-value occupancies, security managers and specifiers, moving from presence-based questions to performance-based verification leads to better decisions, fewer severe surprises, and stronger justification at renewal.
Equipment quality is part of that equation. Two devices may look identical on paper while delivering very different real-world outcomes in tamper resistance, attack resistance, environmental durability, and supervision behavior. The same is true for tamper protection itself: the meaningful question is not whether tamper exists, but what the system does when tampering is induced.
Most importantly, protection should be demonstrated - not assumed. Structured proof is far more valuable than checkbox assurances or broad narrative claims.
Legal and Compliance Note
Industry discussions have referenced recent class-action complaints and demonstrations alleging performance issues with certain combination-listed, single data-bus control units under fault conditions. Those references are allegations, not adjudicated findings. For that reason, this framework focuses onobservable on-site performance and documented evidence rather than claims, labels, or assumptions.
Where Traditional Questionnaires Fall Short
Typical Presence-Based Questions
These are the questions most commonly asked:
- Is there an alarm system?
- What are the make and model?
- Is it UL listed?
- Is there monitoring?
- Are motion detectors or glass-break sensors installed?
- Are there door contacts on exterior openings?
- Are there shock or vibration sensors?
- Is there battery backup?
- Are cameras installed?
- Are cameras remotely viewable?
These questions establish basic system existence. They do
not establish resilience, fault response, or evidentiary quality.
Better Questions: Performance Under Real Conditions
A strong questionnaire asks how the system behaves when something goes wrong, especially in ways an attacker might intentionally cause, does the system meet an engineered design?
- What happens if core data bus wiring is faulted, including wiring to keypads or zone expansion modules?
- Does the panel send a specific actionable signal to the central station, or only general trouble?
- What event code is generated, and what response instructions are tied to that code?
- Does the system trigger a local audible alarm, or only a trouble-beep notification?
- Are surge-protection or isolation devices installed on the bus, and where?
- What happens when auxiliary power wiring is faulted for powered motions, glass-breaks, or vibration sensors?
- Does the panel report a specific actionable condition or only a general trouble?
- What event code is generated, and how is it handled?
- Does the panel produce a local alarm or only a trouble notification?
- Are surge-protection or isolation devices installed on the auxiliary power circuit?
- Is there a secondary power supply for field devices rather than full dependence on the panel's internal power circuit? If secondary power exists, is it supervised?
- If an outdoor siren is present, is the circuit in conduit, is the housing tamper-protected, and is overcurrent protection installed?
- What are the primary and secondary communication paths, and how many attempts are made on each?
- How is each communication path supervised, and at what interval?
- If IP is used, are the switches and router supported by UPS backup, and for how long?
- Is incoming IP or telephone service surge-protected?
- If the primary path fails, is that failure specifically identified and transmitted over the backup path for follow-up action?
- What grades protect safes, cases, and glass, and how were those grades verified?
- Are end-of-line resistors properly installed at the actual end of each supervised circuit?
- If wireless sensors are utilized, are they encrypted and frequency hopping, and have two-way communication with the control panel? Can the control panel detect and report jamming attempts? What event code is sent to the CS and what is the protocol?
- What is the battery replacement schedule?
- What is the verified standby duration under actual load?
- How are supervisory and trouble conditions reported and escalated?
- Are panel enclosures, auxiliary power enclosures, and hardwired sensor junction boxes tamper-protected?
- Is the control panel protected by motion detection, including the area above suspended ceiling systems?
- Is the panel mounted on an exterior perimeter wall?
- What type of transformer is used, plug-in or hardwired, and is the circuit dedicated and identified at the breaker panel?
- What evidence shows these conditions were tested within the past 12 months?
Evidence That Should Be Required
For high-confidence underwriting and defensible recommendations, request:
- A complete device list with grades, specifications, placement details, and a one-page verification summary
- A marked floor plan showing test points and pass/fail results
- A non-destructive bus-fault and auxiliary-power fault test report with timestamps, event codes, and central-station history
- Path-down, failover, and restore logs with measured time intervals
- Photographs of the control panel, supplemental power supplies, and surge or isolation devices
- A current load worksheet, battery specifications, and the latest reserve-verification record
High-Severity Enhancements for Jewelers
For jewelers and other high-value occupancies, the baseline should be higher. Protection should include:
- Intrusion architecture verified to maintain annunciation and signaling under bus-fault conditions
- Dual, independent communication paths with documented failover performance and after-hours escalation in under four minutes
- At least 24 hours of verified standby reserve aligned to inventory value and power-loss exposure
- Properly graded shock and vibration protection on safes and display cases, calibrated glass-break detection at storefront glazing, and cross-zoned interior motion detection along approach paths
- Documented opening and closing governance, including scheduled opening verification, late-to-close alerts, and duress procedures
- An evidence packet updated annually or whenever the system materially changes
Recommended Implementation Approach
Carriers, brokers, and security management can strengthen outcomes immediately by:
- Replacing presence-based questionnaire items with performance-based questions
- Requiring an annual Demonstrated Protection packet for high-value risks
- Linking credits and rate stability to verified controls and timely corrective-action closure
- Reviewing communication uptime, failover performance, supervision exception clearance, reserve verification, and documented detection testing
The core principle is simple:
a listed system is not the same as a verified system. The more severe the exposure, the more important it becomes to validate how protection actually performs under fault, attack, and degraded conditions.


