Cyber insurance requirements in Australia: what insurers check

Cyber insurance requirements in Australia now hinge on demonstrable security hygiene: before they bind or renew a policy, Australian insurers typically require multi-factor authentication on remote access and privileged accounts, tested offline backups, timely patching, endpoint protection and a documented incident response plan. The application is effectively an underwriting questionnaire, and the answers you tick become warranties. If a claim is later contested, the insurer checks whether the controls you declared were actually operating — so the evidence behind each answer matters as much as the answer itself.

By Aneis Samaan, founder of CyberSentien · Last updated July 2026

Why the questionnaire became the underwriting engine

After a wave of ransomware and business-email-compromise losses, the Australian cyber market repriced sharply and tightened its appetite. Insurers stopped underwriting on trust and moved to control-based underwriting: premiums, sub-limits, excesses and even eligibility are now driven by which controls you can show are in place. The practical effect is that a proposal form is no longer a formality — it is a set of declarations that the insurer relies on. Overstate your maturity and you risk a coverage dispute at the exact moment you need to claim.

Two things follow. First, the controls insurers ask about map closely to widely recognised baselines, so the same work that raises your security posture also improves your insurability. Second, the honest answer to many questions is “partially” — and how you evidence “partially” determines whether an underwriter reads it as an acceptable risk or a red flag.

What Australian cyber insurers check

Requirements vary by insurer, revenue band and industry, but a consistent core appears across proposal forms. These are the controls insurers require — MFA, backups, patching — alongside the response and governance questions that increasingly gate cover.

Multi-factor authentication

MFA on remote access (VPN, RDP), email and cloud admin portals, and on all privileged and administrator accounts. This is frequently a hard eligibility gate, not a discount factor.

Backups — and recovery testing

Regular backups that are offline, immutable or otherwise segregated from production credentials, plus evidence they have been test-restored. Insurers ask about restore times because they underwrite your recovery, not just your storage.

Patching & vulnerability management

Timely patching of operating systems and applications, with faster clocks for internet-facing systems and critical vulnerabilities. Expect questions on end-of-life software still in production.

Endpoint & email protection

Endpoint detection and response or reputable anti-malware across the fleet, plus email filtering for phishing and malicious attachments.

Privileged access & identity

Least-privilege administration, removal of departed users, and control over local admin rights. Domain admin sprawl is a common decline reason.

Incident response & awareness

A documented, tested incident response plan, a nominated contact, and staff security-awareness training — increasingly a named requirement rather than a nicety.

Many of these map directly onto the ASD Essential Eight mitigation strategies. Aligning to that baseline is one of the cleaner ways to answer a proposal form with confidence — see our overview of the Essential Eight for how the strategies and maturity levels fit together.

A cyber insurance checklist for small business

Use this as a self-assessment before you complete a proposal form. For each item, the goal is not just a “yes” — it is a “yes, and here is where the evidence lives”.

Control areaWhat insurers typically wantEvidence that stands up
MFAEnforced on email, remote access and admin accountsIdentity-provider policy export showing enforcement scope and coverage
BackupsOffline/immutable copies, tested restoresBackup job configuration plus a dated successful test-restore log
PatchingDefined cadence, no unsupported software exposedPatch-management or vulnerability-scan report with dates
Endpoint protectionEDR/anti-malware deployed fleet-wideConsole coverage report listing managed devices
Incident responseDocumented, tested plan with named rolesThe IR plan itself plus notes from the last tabletop exercise
Awareness trainingRegular training, ideally phishing simulationCompletion records and simulation results

If you are a smaller organisation weighing which baseline to align to first, our comparison of Essential Eight maturity explains where each helps — and both feed the same insurer questions.

Evidence of controls, not just declarations

The gap that hurts at claim time is between what you declared and what you can prove. A proposal answer of “yes, we enforce MFA” is a warranty; if an incident later reveals a gap the insurer can argue non-disclosure and dispute the claim. The defensible position is a controls file where every declared answer is backed by an artefact with a date and a source — and where anything you cannot yet evidence is recorded honestly as work in progress rather than quietly ticked.

This is where CyberSentien fits. We do not sell insurance and we do not certify you. We take your declared controls and turn them into an insurer-ready, tamper-evident evidence pack: each control links to its supporting document, and any control without evidence is marked “manual assessment required” rather than shown as compliant. That honesty is the point — an underwriter, or your own board, can see exactly what is proven and what is asserted. It also means renewal is a refresh, not a scramble, because the evidence is already assembled and mapped to the questions insurers ask.

Try it on sample docs

How insurance sits alongside your other obligations

Cyber insurance is a control-driven contract, but it does not stand alone. Australian organisations may also carry regulatory duties — APRA-regulated entities under CPS 234 must identify and classify information assets, implement and test controls, and notify APRA within 72 hours of a material incident and within 10 business days of a material control weakness. Businesses covered by the Notifiable Data Breaches scheme have separate reporting obligations under the Privacy Act. Insurers increasingly ask about these because an entity that already meets a regulatory baseline is a better risk.

The efficiency here is real: the evidence that satisfies an insurer’s MFA, backup and patching questions is largely the same evidence that supports Essential Eight alignment, small-business certification readiness or a CPS 234 program. Building the evidence once, and keeping it current, serves all of them. For smaller teams, our guidance for small business shows how to assemble that foundation without a dedicated security team.

Primary sources worth reading first-hand: the ASD Essential Eight guidance at cyber.gov.au, APRA prudential standards at apra.gov.au, and the Privacy Act and Notifiable Data Breaches scheme via the OAIC. Always confirm the specific wording of your own insurer’s proposal form — requirements differ, and the declarations you sign are the ones that bind.

Frequently asked

What do cyber insurers require in Australia?

Underwriters typically require MFA, tested backups, timely patching, endpoint protection and incident response — the Essential Eight controls — plus evidence they are actually in place.

What controls do I need for cyber cover?

At minimum MFA on remote access and email, regular tested backups, and patching. Many insurers now ask for evidence, not just a declaration, and may decline claims on unmet warranties.

How do I prove my controls to an insurer?

CyberSentien assesses your controls on real evidence and outputs a tamper-evident, hash-sealed pack that answers underwriter questions with proof rather than assertion.

Does better evidence lower my premium?

Insurers price on demonstrated control maturity; verifiable evidence can support better terms and reduces the risk of a declined claim from an inaccurate declaration.