All Guides
Insurance and Risk

cyber insurance requirements australia: get insured, stay insured, and get paid when you claim

Insurers check five controls before they quote: MFA, backups, EDR, admin controls and incident response. Close the gaps that cost you cover, and walk into your next renewal ready.

Last reviewed September 2026

Overview

Cyber insurance is getting harder to buy. Questionnaires are longer, controls are stricter, and common gaps are now dealbreakers. Even if you have a policy, gaps can mean higher excess, lower limits, or a claim denied. Getting ready matters as much as the policy itself. Meeting the cyber insurance requirements australia insurers now enforce means having MFA, EDR, tested backups and a documented incident response plan in place before you apply.

cyber insurance requirements australia: what insurers actually assess

MFA everywhere

All users, all admins, all remote access, all privileged SaaS. No SMS on admin accounts. Phishing-resistant preferred.

Backups (immutable and tested)

Daily backups, offsite, immutable, tested restores. Ransomware recovery is the single biggest claim category.

EDR on every endpoint

Not antivirus. EDR with logging, monitoring, and ideally MDR. Coverage on servers and workstations.

Admin controls

Least privilege, separate admin accounts, PIM or just-in-time admin. No daily use of domain admin.

Incident response capability

Documented plan, tested tabletop, named DFIR firm or retainer, insurance panel awareness.

Email security

Anti-phishing, DMARC at p=reject, attachment sandboxing, user training.

Patching cadence

Critical CVEs patched in days, not months. Evidence required.

Security awareness training

Annual minimum. Quarterly phishing simulation preferred.

Common Gaps That Affect Premium or Cover

SMS MFA on admin accounts

Acceptable for users, not admins. Auto-fail on most questionnaires.

Backups not offsite or not immutable

Onsite-only backups mean no ransomware recovery.

AV instead of EDR

Many policies now require EDR explicitly.

No incident response plan

Documented plan with named contacts. Must exist and be tested.

Shared admin accounts

No accountability. Auto-fail.

No email authentication (DMARC)

BEC claims routinely denied where DMARC is missing.

No logging or unified audit log

Investigators need 6-12 months of logs. Without them, claim harder to validate.

Unsupported operating systems still running

Server 2012, Windows 7 in production. Insurer exclusion.

What Actually Reduces Your Premium

  • Essential Eight Maturity Level assessment (ML1 minimum, ML2 reduces premium)
  • SMB1001 Gold or ISO 27001 certification
  • MDR service with 24/7 SOC
  • Immutable backups with documented test restores
  • Documented and rehearsed incident response plan
  • Multi-factor authentication (phishing-resistant) on privileged accounts
  • Patch management with measurable SLAs and evidence

At Claim Time

Notify within the required window

Most policies require notification within 24-72 hours. Late notification voids cover.

Use the insurer panel

DFIR, legal, PR, ransomware negotiators on panel. Going off-panel may breach the policy.

Preserve evidence

Do not wipe or restore until forensics have imaged affected systems.

Document everything

Timeline, decisions, communications, spend. All reimbursable with evidence.

Communicate carefully

Legal reviews external statements before they go out. Wrong messaging creates regulatory issues.

Common Mistakes

Filling the questionnaire with best-case answers

Misrepresentation voids cover. Answer accurately and fix gaps.

Treating the policy as a substitute for controls

Policies assume controls. Without them, claims fail.

Never testing the IR plan

Having a plan on paper is not enough. Tabletop exercises annually.

No backups off the domain

Domain compromise means backup compromise. Separate identity tier.

Not reviewing renewal requirements 60 days out

Controls take time to implement. Start renewal prep early.

Related: Essential Eight, Ransomware Guide, IT Risk Guide.

Get Renewal-Ready

We run cyber insurance readiness assessments and remediations that close the gaps insurers actually assess. Evidence-based, audit-ready.