Australian underwriting realitySix chapters · sourced

Cyber insurance readiness in Australia

Six chapters covering what Australian cyber insurers require in 2026, the evidence pack underwriters expect, and a 90-day renewal rhythm that produces better terms.

Drawn from APRA prudential guidance, ASD control frameworks, OAIC obligations, current Australian proposal forms, and broker market commentary.

Six required controls

Now standard on Australian proposal forms

Evidence pack

What underwriters actually expect

90-day renewal rhythm

When to start, what to lodge when

Editorially reviewed
Last reviewed31 Aug 2026
Sources verified31 Aug 2026
01

The market reality

The Australian cyber insurance market has matured rapidly.

Underwriting is now technical, not aspirational.

Australian cyber insurance premiums softened through 2024 and 2025 after the hard market of 2021 to 2023, but underwriting standards did not. Insurers now require evidence of specific controls before binding or renewing cover, and claims teams routinely investigate whether declared controls were operating at the time of incident.

01

APRA cyber resilience supervision

APRA's prudential standard CPS 234 has shaped market expectations across the financial sector and flowed through to broader Australian underwriting practice.

Source · APRA cyber security
02

Insurance Council of Australia position

The ICA describes cyber insurance as a part of a broader risk management framework rather than a substitute for security controls. Underwriters increasingly underwrite the controls, not the business.

Source · Insurance Council of Australia
03

Broker market commentary

Major Australian brokers report that proposal forms now run to 20+ pages with detailed control attestations and that misrepresentations on those forms are a leading reason for claim disputes.

Source · Honan market update
02

What insurers require

Six controls now sit on virtually every Australian proposal form.

MFA, EDR, backup, patching, training, response plan.

Specific wording varies by insurer, but a consistent control set appears across proposal forms from AIG, Chubb, CFC, Emergence, Beazley, Liberty Specialty and the Lloyd's binders that dominate Australian cyber underwriting.

01

Multi-factor authentication, universal

MFA enforced for all users, all admins, all remote access, all email, and all cloud administration. Single exclusion is enough to materially affect cover.

Source · ASD MFA guidance
02

Endpoint Detection and Response

EDR or XDR on all endpoints. Traditional signature-based antivirus is no longer treated as a sufficient control by mainstream Australian underwriters.

03

Tested backups, offline or immutable

Backups protected from the production environment, with documented and recent successful restore tests. Most insurers ask the specific date of the last test restore.

04

Patching cadence

Critical vulnerabilities patched within 14 days, often 48 hours for internet-facing systems. Aligned with Essential Eight Maturity Level One.

Source · Essential Eight
05

Documented security awareness training

Annual baseline training plus quarterly phishing simulation. Completion rates evidenced by report extract.

06

Documented incident response plan

A written plan covering detection, containment, communications and OAIC notification. Tested at least annually in a tabletop exercise.

Source · OAIC NDB scheme
03

Evidence pack

Insurers no longer accept 'yes' as evidence.

Build a documentary pack the broker can lodge directly.

The fastest way to a defensible premium and a faster renewal is to provide pre-collected evidence the broker can attach to the submission. Without it, the broker chases internally for weeks and the proposal goes to underwriters with gaps the underwriter fills in unfavourably.

01

MFA coverage report

Microsoft 365 or identity provider report showing MFA registered users vs total active users, dated within 30 days of submission.

02

EDR coverage report

Endpoint protection console export showing managed devices vs known assets, dated within 30 days.

03

Backup attestation

One-page document signed by the backup provider or internal IT manager, naming the backup product, retention period, last successful restore date and the protection model (offline, immutable or air-gapped).

04

Patch compliance report

Either a vulnerability scanner export or an RMM patch compliance report showing percentage of devices compliant, dated within 30 days.

05

Training completion report

Learning management system export showing completion rate, plus a sample phishing simulation report.

06

Incident response plan extract

Cover page and table of contents of the IR plan, plus the date of the last tabletop exercise. Full plan only on underwriter request.

04

Application questions

The questions insurers actually ask in 2026.

Drawn from current Australian proposal forms.

These are not exhaustive, but they appear consistently across Australian cyber proposal forms in 2026. If your team cannot answer in writing, your broker will be guessing on your behalf, and underwriter pricing will reflect that.

01

Is MFA enforced for ALL users accessing email and remote access?

Single 'no' answer is the most common reason for declined cover or significant retention loading.

02

Do you have EDR on 100% of endpoints?

Insurers distinguish EDR from antivirus by feature set. Microsoft Defender for Business and Defender for Endpoint P1/P2 are generally accepted.

03

Are privileged accounts protected by phishing-resistant MFA?

Hardware keys or platform authenticators. SMS-based MFA on privileged accounts now flagged on most forms.

04

What is the frequency of your backup restore tests?

Quarterly is the practical floor. Annual is often acceptable for smaller businesses but trending toward unacceptable.

05

Do you have a written incident response plan, last tested within 12 months?

Tabletop attestation date is now a standard question, not just plan existence.

06

Have you experienced a cyber incident in the last 5 years?

Disclosure obligation is broad. Underdisclosure on this question is one of the leading reasons for claim disputes.

05

Claims process

What actually happens when you lodge a claim.

First call goes to the insurer's incident response panel.

Most Australian cyber policies route incidents through a panel of pre-approved incident response firms, legal counsel and forensic providers. The policyholder typically cannot freely choose advisors, and engaging an unapproved firm can void cover for that part of the claim.

01

Notify the insurer first

Policy notification clauses typically require notification within 24 to 72 hours of awareness. Late notification is grounds for declinature.

02

Engage the panel firms

Insurer-approved IR, legal and forensic firms are mobilised. Their fees are paid under the policy. Your own preferred advisors may be excluded.

03

Cooperate with the investigation

Insurers and panel firms investigate root cause and verify the controls declared on the proposal form. Misalignment can result in coverage disputes.

04

Parallel OAIC and ASD obligations

Claim cooperation does not pause the OAIC Notifiable Data Breach clock or, if applicable, the 72-hour ASD ransomware payment reporting obligation.

05

Business interruption proof

BI claims require detailed evidence of lost revenue, increased cost of working, and the causal link to the incident. Pre-existing financial records and continuity plans materially affect outcomes.

06

Renewal preparation

The renewal process starts 90 days before the policy expires.

Three months. Not three weeks.

Late renewal preparation is one of the strongest predictors of an unfavourable outcome. Insurers reward businesses that present cleanly and on time. The rhythm below is broadly what well-organised Australian businesses follow with their brokers.

01

T-minus 90 days

Refresh the evidence pack. Re-run MFA, EDR, patching and backup reports. Confirm the IR plan tabletop date is within 12 months.

02

T-minus 75 days

Initial broker meeting. Identify any changes in business operations, headcount, revenue, or sensitive data holdings that affect the proposal.

03

T-minus 60 days

Submission lodged with three or four insurers via the broker. Underwriter questions returned within 5 to 10 business days.

04

T-minus 30 days

Quotes returned. Comparison of limits, retentions, sub-limits and panel arrangements. Negotiation of any material wording points.

05

T-minus 14 days

Final terms accepted. Endorsements documented. Internal communication of any changed reporting obligations under the new policy.

06

Day zero

Policy incepts. Renewal evidence pack and policy documents archived for the next renewal cycle.

What the 2026 breach data shows

Why the six controls have hardened

Australian underwriters and reinsurers reference the Verizon DBIR when setting questionnaire content and pricing. The 2026 edition explains why MFA, EDR, patch cadence and a tested response plan now sit on every proposal form: the entry points have shifted, the human element remains, and third-party exposure has tripled in two years.

Read the Verizon 2026 DBIR

Top vector

Vulnerability exploitation now the leading initial access vector for breaches

Overtook stolen credentials in 2026. The patch backlog has become the front door.

0 days

0 days median time from edge-device CVE disclosure to mass exploitation

Firewalls, VPN gateways and remote-access appliances are now hit at internet speed.

48%

48% of breaches involved a third party globally, up from 15% two years ago

Your supplier list is now part of your attack surface.

Trending up

Ransomware impact remains one of the most disruptive breach types and continues to climb

Premium calculators and underwriting questionnaires reflect this in 2026 renewals.

Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.

"An umbrella that doesn't open in the rain isn't protecting anyone, and a cyber insurance policy works in a very similar way."

Having a policy doesn't automatically mean it pays out when something goes wrong. Whether it does depends on details most business owners never look into closely until they actually need to.

Common assumptions worth understanding

What business owners get wrong about their coverage

These four assumptions show up regularly when claims are disputed or cover is reduced. Most of the time, the business genuinely believed they were protected.

01

"We have MFA, so we're covered."

Insurers mean MFA enforced on every account that touches your systems. A business might have MFA set up for inboxes and still leave it off on a VPN connection or an admin account. That single gap is often enough for a claim to be reduced or denied, even if everything else was handled well.

02

"Ransomware is always covered."

Many policies cap the ransomware payout and separate it entirely from the cost of rebuilding systems, notifying customers, legal fees, and lost revenue. Some policies can exclude a claim outright if the attack exploited a vulnerability the business knew about but hadn't addressed.

03

"Our business insurance covers cyber."

Standard business insurance was built for property damage, liability, and physical theft — not data breaches. Most general policies exclude cyber incidents outright. A business can carry solid coverage for years and have zero protection the day an attack occurs.

04

"We answered honestly, so we're fine."

A quick 'yes, we have backups' isn't enough anymore. Insurers want specifics: how often backups are tested and where the data lives. Most claims disputes in this area come from individuals answering based on what they assumed was true rather than what they could actually confirm.

Source: Real Bytes "Insurable, Not Just Insured" guide, drawing on ConnectWise State of SMB Cybersecurity 2025 (Vanson Bourne, 700 IT and business decision-makers, AU/NZ included).

The common ground

What most cyber insurers are looking for

Across industries, most Australian applications and renewals touch on the same core areas. Your specific questionnaire will adapt these to your industry, team size, and data type.

MFA enforced on every account that can access your systems

Not just email — VPN, admin accounts, cloud admin consoles included

Endpoint protection with real-time detection and response

Traditional antivirus alone is no longer considered sufficient

Backups tested on a real schedule, with a copy stored offline

Most insurers ask for the specific date of the last test restore

A documented patching process for known vulnerabilities

Critical patches within 14 days; internet-facing systems often 48 hours

Ongoing security awareness training for staff

Most breaches start with a person — training needs to be documented

Email filtering that stops phishing before it reaches inboxes

A specific question on most current Australian proposal forms

Some form of active monitoring for unusual activity

The faster you detect, the better the outcome and the claim position

Strengthening your security and strengthening your coverage case turn out to be the same project.

The controls insurers require are largely the same as those that make an incident less likely. Real Bytes can look at what's currently in place and help get anything missing in order before your next application or renewal.

New on 2026 proposal forms

The AI questions insurers added to Australian cyber renewals in 2026.

The six standard controls in the chapter above still apply. On top of them, every major Australian cyber insurer added AI-specific questions to 2026 proposal and renewal forms. Some now exclude agentic AI altogether unless specific human-approval controls are documented.

The questions below are paraphrased from current proposal forms across AIG, Chubb, CFC, Emergence and Beazley. Specific wording varies. The substance does not.

Material to premium and cover

Misrepresentation on AI questions is a leading cause of cover disputes on 2026 renewals. Where the answer is "we do not know", brokers report substantial retention loading or sub-limited AI exposure cover.

01

What AI tools are deployed across the business, by tenant licence and by personal account?

Why it matters: Insurers are now distinguishing tenant-licensed AI (Copilot, ChatGPT Enterprise, Gemini for Workspace) from consumer-account use. Personal-account use is treated as shadow AI and materially affects premium.

02

Is generative AI use governed by a written policy, and has the workforce been trained on it?

Why it matters: A written policy and an attested training record reduce the underwriter's view of negligent-use risk. Both are reaching every proposal form we have seen for 2026 renewals.

03

Have AI-augmented BEC, voice-cloning or deepfake risks been assessed and mitigated?

Why it matters: Multiple Australian insurers are now asking specifically about deepfake and voice-clone payment fraud, following high-profile losses. Out-of-band verification on payment changes is the practical control.

04

If Microsoft 365 Copilot or similar is deployed, how is data exposure controlled?

Why it matters: Copilot indexes whatever the user can access. Underwriters now ask whether SharePoint oversharing has been audited and whether sensitivity labels are applied before Copilot licences are activated.

05

Does the business deploy any AI agent that takes action (sends email, moves money, files records)?

Why it matters: Agentic AI is increasingly excluded from cover unless human approval is documented before any business-affecting action. Some Lloyd's binders now have explicit agentic-AI exclusions.

A practical sequencing note. If a renewal lands inside the next 90 days and AI controls are not yet in place, the right answer to the underwriter is not "yes" or "no" but "in progress, with a documented roadmap". An acceptable use of AI policy and a written register of AI tools in use are the two artefacts insurers most often accept as evidence the work is underway.

Common questions

Questions Australian leadership teams ask before renewal.

Ninety days before policy expiry is the practical floor. Submission goes to underwriters at T-minus 60 days. Late preparation is the strongest predictor of an unfavourable renewal outcome.

If a renewal is approaching

Renewal pricing reflects how clean the submission is.

If your cyber insurance renewal is within 90 days, the work below the line is essentially documentary. We help Australian businesses assemble the evidence pack, refresh the controls, and present cleanly to the broker. The result is generally a smoother renewal and a defensible position if a claim follows.

This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.