Overview
Cyber insurance is getting harder to buy. Questionnaires are longer, controls are stricter, and common gaps are now dealbreakers. Even if you have a policy, gaps can mean higher excess, lower limits, or a claim denied. Getting ready matters as much as the policy itself. Meeting the cyber insurance requirements australia insurers now enforce means having MFA, EDR, tested backups and a documented incident response plan in place before you apply.
cyber insurance requirements australia: what insurers actually assess
MFA everywhere
All users, all admins, all remote access, all privileged SaaS. No SMS on admin accounts. Phishing-resistant preferred.
Backups (immutable and tested)
Daily backups, offsite, immutable, tested restores. Ransomware recovery is the single biggest claim category.
EDR on every endpoint
Not antivirus. EDR with logging, monitoring, and ideally MDR. Coverage on servers and workstations.
Admin controls
Least privilege, separate admin accounts, PIM or just-in-time admin. No daily use of domain admin.
Incident response capability
Documented plan, tested tabletop, named DFIR firm or retainer, insurance panel awareness.
Email security
Anti-phishing, DMARC at p=reject, attachment sandboxing, user training.
Patching cadence
Critical CVEs patched in days, not months. Evidence required.
Security awareness training
Annual minimum. Quarterly phishing simulation preferred.
Common Gaps That Affect Premium or Cover
SMS MFA on admin accounts
Acceptable for users, not admins. Auto-fail on most questionnaires.
Backups not offsite or not immutable
Onsite-only backups mean no ransomware recovery.
AV instead of EDR
Many policies now require EDR explicitly.
No incident response plan
Documented plan with named contacts. Must exist and be tested.
Shared admin accounts
No accountability. Auto-fail.
No email authentication (DMARC)
BEC claims routinely denied where DMARC is missing.
No logging or unified audit log
Investigators need 6-12 months of logs. Without them, claim harder to validate.
Unsupported operating systems still running
Server 2012, Windows 7 in production. Insurer exclusion.
At Claim Time
Notify within the required window
Most policies require notification within 24-72 hours. Late notification voids cover.
Use the insurer panel
DFIR, legal, PR, ransomware negotiators on panel. Going off-panel may breach the policy.
Preserve evidence
Do not wipe or restore until forensics have imaged affected systems.
Document everything
Timeline, decisions, communications, spend. All reimbursable with evidence.
Communicate carefully
Legal reviews external statements before they go out. Wrong messaging creates regulatory issues.
Common Mistakes
Filling the questionnaire with best-case answers
Misrepresentation voids cover. Answer accurately and fix gaps.
Treating the policy as a substitute for controls
Policies assume controls. Without them, claims fail.
Never testing the IR plan
Having a plan on paper is not enough. Tabletop exercises annually.
No backups off the domain
Domain compromise means backup compromise. Separate identity tier.
Not reviewing renewal requirements 60 days out
Controls take time to implement. Start renewal prep early.
Related: Essential Eight, Ransomware Guide, IT Risk Guide.
Get Renewal-Ready
We run cyber insurance readiness assessments and remediations that close the gaps insurers actually assess. Evidence-based, audit-ready.

Remote Support