Cyber insurance requirements in Australia now hinge on demonstrable security hygiene: before they bind or renew a policy, Australian insurers typically require multi-factor authentication on remote access and privileged accounts, tested offline backups, timely patching, endpoint protection and a documented incident response plan. The application is effectively an underwriting questionnaire, and the answers you tick become warranties. If a claim is later contested, the insurer checks whether the controls you declared were actually operating — so the evidence behind each answer matters as much as the answer itself.
By Aneis Samaan, founder of CyberSentien · Last updated July 2026
After a wave of ransomware and business-email-compromise losses, the Australian cyber market repriced sharply and tightened its appetite. Insurers stopped underwriting on trust and moved to control-based underwriting: premiums, sub-limits, excesses and even eligibility are now driven by which controls you can show are in place. The practical effect is that a proposal form is no longer a formality — it is a set of declarations that the insurer relies on. Overstate your maturity and you risk a coverage dispute at the exact moment you need to claim.
Two things follow. First, the controls insurers ask about map closely to widely recognised baselines, so the same work that raises your security posture also improves your insurability. Second, the honest answer to many questions is “partially” — and how you evidence “partially” determines whether an underwriter reads it as an acceptable risk or a red flag.
Requirements vary by insurer, revenue band and industry, but a consistent core appears across proposal forms. These are the controls insurers require — MFA, backups, patching — alongside the response and governance questions that increasingly gate cover.
MFA on remote access (VPN, RDP), email and cloud admin portals, and on all privileged and administrator accounts. This is frequently a hard eligibility gate, not a discount factor.
Regular backups that are offline, immutable or otherwise segregated from production credentials, plus evidence they have been test-restored. Insurers ask about restore times because they underwrite your recovery, not just your storage.
Timely patching of operating systems and applications, with faster clocks for internet-facing systems and critical vulnerabilities. Expect questions on end-of-life software still in production.
Endpoint detection and response or reputable anti-malware across the fleet, plus email filtering for phishing and malicious attachments.
Least-privilege administration, removal of departed users, and control over local admin rights. Domain admin sprawl is a common decline reason.
A documented, tested incident response plan, a nominated contact, and staff security-awareness training — increasingly a named requirement rather than a nicety.
Many of these map directly onto the ASD Essential Eight mitigation strategies. Aligning to that baseline is one of the cleaner ways to answer a proposal form with confidence — see our overview of the Essential Eight for how the strategies and maturity levels fit together.
Use this as a self-assessment before you complete a proposal form. For each item, the goal is not just a “yes” — it is a “yes, and here is where the evidence lives”.
| Control area | What insurers typically want | Evidence that stands up |
|---|---|---|
| MFA | Enforced on email, remote access and admin accounts | Identity-provider policy export showing enforcement scope and coverage |
| Backups | Offline/immutable copies, tested restores | Backup job configuration plus a dated successful test-restore log |
| Patching | Defined cadence, no unsupported software exposed | Patch-management or vulnerability-scan report with dates |
| Endpoint protection | EDR/anti-malware deployed fleet-wide | Console coverage report listing managed devices |
| Incident response | Documented, tested plan with named roles | The IR plan itself plus notes from the last tabletop exercise |
| Awareness training | Regular training, ideally phishing simulation | Completion records and simulation results |
If you are a smaller organisation weighing which baseline to align to first, our comparison of Essential Eight maturity explains where each helps — and both feed the same insurer questions.
The gap that hurts at claim time is between what you declared and what you can prove. A proposal answer of “yes, we enforce MFA” is a warranty; if an incident later reveals a gap the insurer can argue non-disclosure and dispute the claim. The defensible position is a controls file where every declared answer is backed by an artefact with a date and a source — and where anything you cannot yet evidence is recorded honestly as work in progress rather than quietly ticked.
This is where CyberSentien fits. We do not sell insurance and we do not certify you. We take your declared controls and turn them into an insurer-ready, tamper-evident evidence pack: each control links to its supporting document, and any control without evidence is marked “manual assessment required” rather than shown as compliant. That honesty is the point — an underwriter, or your own board, can see exactly what is proven and what is asserted. It also means renewal is a refresh, not a scramble, because the evidence is already assembled and mapped to the questions insurers ask.
Try it on sample docsCyber insurance is a control-driven contract, but it does not stand alone. Australian organisations may also carry regulatory duties — APRA-regulated entities under CPS 234 must identify and classify information assets, implement and test controls, and notify APRA within 72 hours of a material incident and within 10 business days of a material control weakness. Businesses covered by the Notifiable Data Breaches scheme have separate reporting obligations under the Privacy Act. Insurers increasingly ask about these because an entity that already meets a regulatory baseline is a better risk.
The efficiency here is real: the evidence that satisfies an insurer’s MFA, backup and patching questions is largely the same evidence that supports Essential Eight alignment, small-business certification readiness or a CPS 234 program. Building the evidence once, and keeping it current, serves all of them. For smaller teams, our guidance for small business shows how to assemble that foundation without a dedicated security team.
Primary sources worth reading first-hand: the ASD Essential Eight guidance at cyber.gov.au, APRA prudential standards at apra.gov.au, and the Privacy Act and Notifiable Data Breaches scheme via the OAIC. Always confirm the specific wording of your own insurer’s proposal form — requirements differ, and the declarations you sign are the ones that bind.
Underwriters typically require MFA, tested backups, timely patching, endpoint protection and incident response — the Essential Eight controls — plus evidence they are actually in place.
At minimum MFA on remote access and email, regular tested backups, and patching. Many insurers now ask for evidence, not just a declaration, and may decline claims on unmet warranties.
CyberSentien assesses your controls on real evidence and outputs a tamper-evident, hash-sealed pack that answers underwriter questions with proof rather than assertion.
Insurers price on demonstrated control maturity; verifiable evidence can support better terms and reduces the risk of a declined claim from an inaccurate declaration.