Cyber insurance readiness in Australia
Six chapters covering what Australian cyber insurers require in 2026, the evidence pack underwriters expect, and a 90-day renewal rhythm that produces better terms.
Drawn from APRA prudential guidance, ASD control frameworks, OAIC obligations, current Australian proposal forms, and broker market commentary.
Six required controls
Now standard on Australian proposal forms
Evidence pack
What underwriters actually expect
90-day renewal rhythm
When to start, what to lodge when
The market reality
The Australian cyber insurance market has matured rapidly.
Underwriting is now technical, not aspirational.
Australian cyber insurance premiums softened through 2024 and 2025 after the hard market of 2021 to 2023, but underwriting standards did not. Insurers now require evidence of specific controls before binding or renewing cover, and claims teams routinely investigate whether declared controls were operating at the time of incident.
APRA cyber resilience supervision
APRA's prudential standard CPS 234 has shaped market expectations across the financial sector and flowed through to broader Australian underwriting practice.
Source · APRA cyber securityInsurance Council of Australia position
The ICA describes cyber insurance as a part of a broader risk management framework rather than a substitute for security controls. Underwriters increasingly underwrite the controls, not the business.
Source · Insurance Council of AustraliaBroker market commentary
Major Australian brokers report that proposal forms now run to 20+ pages with detailed control attestations and that misrepresentations on those forms are a leading reason for claim disputes.
Source · Honan market updateWhat insurers require
Six controls now sit on virtually every Australian proposal form.
MFA, EDR, backup, patching, training, response plan.
Specific wording varies by insurer, but a consistent control set appears across proposal forms from AIG, Chubb, CFC, Emergence, Beazley, Liberty Specialty and the Lloyd's binders that dominate Australian cyber underwriting.
Multi-factor authentication, universal
MFA enforced for all users, all admins, all remote access, all email, and all cloud administration. Single exclusion is enough to materially affect cover.
Source · ASD MFA guidanceEndpoint Detection and Response
EDR or XDR on all endpoints. Traditional signature-based antivirus is no longer treated as a sufficient control by mainstream Australian underwriters.
Tested backups, offline or immutable
Backups protected from the production environment, with documented and recent successful restore tests. Most insurers ask the specific date of the last test restore.
Patching cadence
Critical vulnerabilities patched within 14 days, often 48 hours for internet-facing systems. Aligned with Essential Eight Maturity Level One.
Source · Essential EightDocumented security awareness training
Annual baseline training plus quarterly phishing simulation. Completion rates evidenced by report extract.
Documented incident response plan
A written plan covering detection, containment, communications and OAIC notification. Tested at least annually in a tabletop exercise.
Source · OAIC NDB schemeEvidence pack
Insurers no longer accept 'yes' as evidence.
Build a documentary pack the broker can lodge directly.
The fastest way to a defensible premium and a faster renewal is to provide pre-collected evidence the broker can attach to the submission. Without it, the broker chases internally for weeks and the proposal goes to underwriters with gaps the underwriter fills in unfavourably.
MFA coverage report
Microsoft 365 or identity provider report showing MFA registered users vs total active users, dated within 30 days of submission.
EDR coverage report
Endpoint protection console export showing managed devices vs known assets, dated within 30 days.
Backup attestation
One-page document signed by the backup provider or internal IT manager, naming the backup product, retention period, last successful restore date and the protection model (offline, immutable or air-gapped).
Patch compliance report
Either a vulnerability scanner export or an RMM patch compliance report showing percentage of devices compliant, dated within 30 days.
Training completion report
Learning management system export showing completion rate, plus a sample phishing simulation report.
Incident response plan extract
Cover page and table of contents of the IR plan, plus the date of the last tabletop exercise. Full plan only on underwriter request.
Application questions
The questions insurers actually ask in 2026.
Drawn from current Australian proposal forms.
These are not exhaustive, but they appear consistently across Australian cyber proposal forms in 2026. If your team cannot answer in writing, your broker will be guessing on your behalf, and underwriter pricing will reflect that.
Is MFA enforced for ALL users accessing email and remote access?
Single 'no' answer is the most common reason for declined cover or significant retention loading.
Do you have EDR on 100% of endpoints?
Insurers distinguish EDR from antivirus by feature set. Microsoft Defender for Business and Defender for Endpoint P1/P2 are generally accepted.
Are privileged accounts protected by phishing-resistant MFA?
Hardware keys or platform authenticators. SMS-based MFA on privileged accounts now flagged on most forms.
What is the frequency of your backup restore tests?
Quarterly is the practical floor. Annual is often acceptable for smaller businesses but trending toward unacceptable.
Do you have a written incident response plan, last tested within 12 months?
Tabletop attestation date is now a standard question, not just plan existence.
Have you experienced a cyber incident in the last 5 years?
Disclosure obligation is broad. Underdisclosure on this question is one of the leading reasons for claim disputes.
Claims process
What actually happens when you lodge a claim.
First call goes to the insurer's incident response panel.
Most Australian cyber policies route incidents through a panel of pre-approved incident response firms, legal counsel and forensic providers. The policyholder typically cannot freely choose advisors, and engaging an unapproved firm can void cover for that part of the claim.
Notify the insurer first
Policy notification clauses typically require notification within 24 to 72 hours of awareness. Late notification is grounds for declinature.
Engage the panel firms
Insurer-approved IR, legal and forensic firms are mobilised. Their fees are paid under the policy. Your own preferred advisors may be excluded.
Cooperate with the investigation
Insurers and panel firms investigate root cause and verify the controls declared on the proposal form. Misalignment can result in coverage disputes.
Parallel OAIC and ASD obligations
Claim cooperation does not pause the OAIC Notifiable Data Breach clock or, if applicable, the 72-hour ASD ransomware payment reporting obligation.
Business interruption proof
BI claims require detailed evidence of lost revenue, increased cost of working, and the causal link to the incident. Pre-existing financial records and continuity plans materially affect outcomes.
Renewal preparation
The renewal process starts 90 days before the policy expires.
Three months. Not three weeks.
Late renewal preparation is one of the strongest predictors of an unfavourable outcome. Insurers reward businesses that present cleanly and on time. The rhythm below is broadly what well-organised Australian businesses follow with their brokers.
T-minus 90 days
Refresh the evidence pack. Re-run MFA, EDR, patching and backup reports. Confirm the IR plan tabletop date is within 12 months.
T-minus 75 days
Initial broker meeting. Identify any changes in business operations, headcount, revenue, or sensitive data holdings that affect the proposal.
T-minus 60 days
Submission lodged with three or four insurers via the broker. Underwriter questions returned within 5 to 10 business days.
T-minus 30 days
Quotes returned. Comparison of limits, retentions, sub-limits and panel arrangements. Negotiation of any material wording points.
T-minus 14 days
Final terms accepted. Endorsements documented. Internal communication of any changed reporting obligations under the new policy.
Day zero
Policy incepts. Renewal evidence pack and policy documents archived for the next renewal cycle.
Sources referenced
- 01
Cyber security
Australian Prudential Regulation Authoritywww.apra.gov.au - 02
Essential Eight
Australian Signals Directoratewww.cyber.gov.au - 03
Multi-factor authentication
Australian Cyber Security Centrewww.cyber.gov.au - 04
Notifiable Data Breaches scheme
Office of the Australian Information Commissionerwww.oaic.gov.au - 05
Cyber insurance
Insurance Council of Australiainsurancecouncil.com.au - 06
Cyber insurance market update
Honan Insurance Grouphonan.com.au
This page summarises publicly available Australian government, regulator and legal sources. It is general information, not legal advice.
Why the six controls have hardened
Australian underwriters and reinsurers reference the Verizon DBIR when setting questionnaire content and pricing. The 2026 edition explains why MFA, EDR, patch cadence and a tested response plan now sit on every proposal form: the entry points have shifted, the human element remains, and third-party exposure has tripled in two years.
Read the Verizon 2026 DBIRTop vector
Vulnerability exploitation now the leading initial access vector for breaches
Overtook stolen credentials in 2026. The patch backlog has become the front door.
0 days
0 days median time from edge-device CVE disclosure to mass exploitation
Firewalls, VPN gateways and remote-access appliances are now hit at internet speed.
48%
48% of breaches involved a third party globally, up from 15% two years ago
Your supplier list is now part of your attack surface.
Trending up
Ransomware impact remains one of the most disruptive breach types and continues to climb
Premium calculators and underwriting questionnaires reflect this in 2026 renewals.
Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.
"An umbrella that doesn't open in the rain isn't protecting anyone, and a cyber insurance policy works in a very similar way."
Having a policy doesn't automatically mean it pays out when something goes wrong. Whether it does depends on details most business owners never look into closely until they actually need to.
Common assumptions worth understanding
What business owners get wrong about their coverage
These four assumptions show up regularly when claims are disputed or cover is reduced. Most of the time, the business genuinely believed they were protected.
"We have MFA, so we're covered."
Insurers mean MFA enforced on every account that touches your systems. A business might have MFA set up for inboxes and still leave it off on a VPN connection or an admin account. That single gap is often enough for a claim to be reduced or denied, even if everything else was handled well.
"Ransomware is always covered."
Many policies cap the ransomware payout and separate it entirely from the cost of rebuilding systems, notifying customers, legal fees, and lost revenue. Some policies can exclude a claim outright if the attack exploited a vulnerability the business knew about but hadn't addressed.
"Our business insurance covers cyber."
Standard business insurance was built for property damage, liability, and physical theft — not data breaches. Most general policies exclude cyber incidents outright. A business can carry solid coverage for years and have zero protection the day an attack occurs.
"We answered honestly, so we're fine."
A quick 'yes, we have backups' isn't enough anymore. Insurers want specifics: how often backups are tested and where the data lives. Most claims disputes in this area come from individuals answering based on what they assumed was true rather than what they could actually confirm.
Source: Real Bytes "Insurable, Not Just Insured" guide, drawing on ConnectWise State of SMB Cybersecurity 2025 (Vanson Bourne, 700 IT and business decision-makers, AU/NZ included).
The common ground
What most cyber insurers are looking for
Across industries, most Australian applications and renewals touch on the same core areas. Your specific questionnaire will adapt these to your industry, team size, and data type.
MFA enforced on every account that can access your systems
Not just email — VPN, admin accounts, cloud admin consoles included
Endpoint protection with real-time detection and response
Traditional antivirus alone is no longer considered sufficient
Backups tested on a real schedule, with a copy stored offline
Most insurers ask for the specific date of the last test restore
A documented patching process for known vulnerabilities
Critical patches within 14 days; internet-facing systems often 48 hours
Ongoing security awareness training for staff
Most breaches start with a person — training needs to be documented
Email filtering that stops phishing before it reaches inboxes
A specific question on most current Australian proposal forms
Some form of active monitoring for unusual activity
The faster you detect, the better the outcome and the claim position
Strengthening your security and strengthening your coverage case turn out to be the same project.
The controls insurers require are largely the same as those that make an incident less likely. Real Bytes can look at what's currently in place and help get anything missing in order before your next application or renewal.
New on 2026 proposal forms
The AI questions insurers added to Australian cyber renewals in 2026.
The six standard controls in the chapter above still apply. On top of them, every major Australian cyber insurer added AI-specific questions to 2026 proposal and renewal forms. Some now exclude agentic AI altogether unless specific human-approval controls are documented.
The questions below are paraphrased from current proposal forms across AIG, Chubb, CFC, Emergence and Beazley. Specific wording varies. The substance does not.
Material to premium and cover
Misrepresentation on AI questions is a leading cause of cover disputes on 2026 renewals. Where the answer is "we do not know", brokers report substantial retention loading or sub-limited AI exposure cover.
What AI tools are deployed across the business, by tenant licence and by personal account?
Why it matters: Insurers are now distinguishing tenant-licensed AI (Copilot, ChatGPT Enterprise, Gemini for Workspace) from consumer-account use. Personal-account use is treated as shadow AI and materially affects premium.
Where we get this answered
Is generative AI use governed by a written policy, and has the workforce been trained on it?
Why it matters: A written policy and an attested training record reduce the underwriter's view of negligent-use risk. Both are reaching every proposal form we have seen for 2026 renewals.
Where we get this answered
Have AI-augmented BEC, voice-cloning or deepfake risks been assessed and mitigated?
Why it matters: Multiple Australian insurers are now asking specifically about deepfake and voice-clone payment fraud, following high-profile losses. Out-of-band verification on payment changes is the practical control.
Where we get this answered
If Microsoft 365 Copilot or similar is deployed, how is data exposure controlled?
Why it matters: Copilot indexes whatever the user can access. Underwriters now ask whether SharePoint oversharing has been audited and whether sensitivity labels are applied before Copilot licences are activated.
Where we get this answered
Does the business deploy any AI agent that takes action (sends email, moves money, files records)?
Why it matters: Agentic AI is increasingly excluded from cover unless human approval is documented before any business-affecting action. Some Lloyd's binders now have explicit agentic-AI exclusions.
Where we get this answered
A practical sequencing note. If a renewal lands inside the next 90 days and AI controls are not yet in place, the right answer to the underwriter is not "yes" or "no" but "in progress, with a documented roadmap". An acceptable use of AI policy and a written register of AI tools in use are the two artefacts insurers most often accept as evidence the work is underway.
Common questions
Questions Australian leadership teams ask before renewal.
Ninety days before policy expiry is the practical floor. Submission goes to underwriters at T-minus 60 days. Late preparation is the strongest predictor of an unfavourable renewal outcome.
Related in this cluster
Other operational and regulatory pages for Australian businesses.
If a renewal is approaching
Renewal pricing reflects how clean the submission is.
If your cyber insurance renewal is within 90 days, the work below the line is essentially documentary. We help Australian businesses assemble the evidence pack, refresh the controls, and present cleanly to the broker. The result is generally a smoother renewal and a defensible position if a claim follows.
This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.

Remote Support