Guide · Updated October 2026

Cyber Insurance Australia: What Insurers Now Require of Your IT

Cyber insurance used to be a tick-box. These days Australian insurers want proof your IT controls actually work before they'll pay out — and here's what they're asking Hills small businesses to have in place.

A few years ago you could fill in a short form, pay a modest premium and walk away with a cyber insurance policy. Those days are gone. After a run of high-profile Australian breaches and rising ransomware claims, insurers have tightened their requirements sharply. Today, the application form reads more like a security audit — and if your answers don't stack up, you'll either be declined, charged a steep premium, or find a claim knocked back later.

For small businesses across The Hills and Greater Sydney, that's not necessarily bad news. The controls insurers now demand are the same ones that genuinely reduce your risk of being breached in the first place. Get them right and you qualify for cover, pay less, and sleep better. Here's what Australian insurers are looking for in 2025 and how to get there without overcomplicating things.

Why the goalposts moved

Insurers lost money on cyber. Ransomware payouts, business interruption claims and the cost of notifying affected customers all climbed faster than premiums. The response was predictable: raise prices, narrow what's covered, and insist policyholders prove they've done the basics. The questionnaires got longer and the follow-up questions got sharper.

The important shift is that insurers now treat your controls as conditions of cover, not just pricing inputs. If you declare you have multi-factor authentication everywhere and a breach later shows you didn't, your claim can be reduced or refused for misrepresentation. Accuracy on that form matters as much as having the controls themselves.

The controls insurers now expect

While every insurer words things differently, the same handful of requirements come up again and again. Think of these as the entry ticket.

Multi-factor authentication (MFA), everywhere that matters

MFA is the single most-requested control. Insurers want it on email, remote access (VPN and remote desktop), cloud admin accounts, and any system reachable from the internet. "We have it on some accounts" usually isn't enough. The expectation is MFA on all user and especially all privileged accounts. If you're on Microsoft 365, this is straightforward to enforce — see our notes on Microsoft 365 security settings.

Managed, tested backups

Because ransomware is the big claim driver, insurers want to know you can recover without paying. They'll ask whether backups are regular, whether at least one copy is offline or immutable (so attackers can't encrypt it too), and — crucially — whether you've actually tested a restore. An untested backup is a guess. A documented backup and disaster recovery process answers this question properly.

Endpoint detection and response (EDR)

Traditional antivirus is no longer enough for most insurers. They increasingly ask for EDR — modern endpoint protection that detects suspicious behaviour and can isolate a compromised device, ideally monitored by someone who'll respond. This is a core part of a managed cybersecurity setup.

Email filtering and phishing protection

Most incidents still start with an email. Insurers expect spam and malware filtering, protections against spoofing (SPF, DKIM, DMARC), and often some form of staff awareness training. The human layer counts.

Patching and updates

Expect questions about how quickly you apply security updates to operating systems, software and firewalls. Unpatched, internet-facing systems are a common entry point, and insurers know it. A documented patch cadence — managed rather than left to chance — is what they want to see.

Privileged access controls

Insurers increasingly ask whether everyday users run as administrators, whether admin accounts are separate and tightly controlled, and whether old accounts get removed when staff leave. Limiting who can do powerful things limits how far an attacker can go.

An incident response plan

Finally, they want to know you've thought about what happens when something goes wrong: who you call, how you contain it, and your obligations under the Notifiable Data Breaches scheme. Even a simple, written plan puts you ahead of most small businesses.

How this maps to Australian frameworks

If this list feels familiar, it's because it closely mirrors the Australian Cyber Security Centre's Essential Eight. Insurers lean on the Essential Eight because it's a recognised local benchmark. You don't need to be at the highest maturity level to get cover, but demonstrating steady progress against those mitigation strategies makes the application far smoother — and gives you a clear roadmap rather than a scramble before renewal.

Filling in the form honestly (and why it pays)

The temptation is to tick every box to secure the best premium. Resist it. The worst possible outcome is paying premiums for years, suffering a breach, then having the claim denied because a declaration didn't match reality. If you're unsure whether a control is fully in place, find out before you sign — not after an incident.

A good approach is to treat the questionnaire as a gap analysis. Work through it with whoever manages your IT, mark honestly where you stand, and build a short plan to close the gaps that matter most. Many of them — enabling MFA, turning on immutable backups, tightening admin access — cost little and can be done quickly.

Where a managed IT partner fits

Most Hills small businesses don't have an in-house security team, and that's fine. This is exactly the sort of work a managed IT provider handles day to day. A good partner can complete the technical sections of your insurance application accurately, implement the controls that are missing, and — importantly — provide the evidence insurers sometimes request, such as backup reports or MFA enforcement settings.

There's a practical payoff beyond compliance. The same controls that satisfy insurers are the ones that actually keep you running. Immutable backups, EDR, enforced MFA and prompt patching don't just help you qualify for cover — they're what stops a bad day becoming a business-ending one. Insurance is the safety net; these controls are the floor.

A sensible next step

If your renewal is coming up, don't leave the questionnaire until the last week. Pull it out now, walk through it honestly, and identify the two or three gaps that would most affect your premium or your eligibility. Fix those first. If you'd like a hand working through what insurers are asking and getting your controls to match, we're happy to review your setup and give you a plain-English picture of where you stand — no jargon, no scare tactics.

Free, no-obligation

Talk to a local IT partner

Book a 15-minute call — we'll give you a clear, jargon-free picture of where your IT stands.