TECHNICAL NEWS
·
Cyber Insurance
·
3 min read
Your Cyber Insurance Might Not Pay Out
Australian insurers now require evidence of compliance with your controls when you claim.

Cyber insurance has become a critical part of risk management for Australian small and medium businesses. But you need to ensure you are compliant.
The Australian Signals Directorate received more than 84,700 cybercrime reports in 2024–25. Small businesses self-reported average costs of $56,600, and medium businesses $97,200 — a 55% jump in a single year. Those numbers explain why cover is worth having. They also explain why insurers are now asking much harder questions before they payout on claims.

BOTTOM LINE UP FRONT
A cyber policy is a contract with conditions, not a recovery fund. Insurers rely on what you declare about multi-factor authentication, backups, patching and endpoint protection — and they will test those declarations after an incident. If a control was not actually in place, or cannot be evidenced, the claim gets harder.
Insurers now verify, not just ask
The Australian cyber insurance market has matured. Access is broader and pricing more competitive than it was a few years ago, but underwriting has tightened around a short list of basics.
Proposal forms from mainstream Australian underwriters ask the same practical questions. Is multi-factor authentication enforced on remote access, email, privileged accounts and backups? Are backups isolated, frequent and tested? How quickly are critical patches applied? Is endpoint detection deployed? Do staff receive social-engineering training?
If that list feels familiar, it should. It is largely the ACSC’s Essential Eight, written in an underwriter’s language.
What insurers ask you to prove
These are the controls that appear again and again on Australian SME proposal and renewal forms. Most map directly to the ACSC Essential Eight.
Multi-factor authentication (Essential Eight) — enforced on remote access, email, privileged accounts and backups, not just “enabled somewhere”.
Backups that restore (Essential Eight) — frequent, isolated or immutable, and test-restored, with the test result on file.
Patching cadence (Essential Eight) — critical patches applied within a stated window, across operating systems and applications.
Restricted administrator privileges (Essential Eight) — who holds admin rights, how they are reviewed, and whether vendors hold standing access.
Endpoint detection and response (insurer-specific) — next-generation endpoint protection deployed across servers and workstations.
Email and payment verification (insurer-specific) — email filtering and authentication, plus a call-back rule before any supplier bank-detail change.
Tested incident response plan (insurer-specific) — who calls the insurer, who preserves evidence, who notifies the regulator, rehearsed, not filed.
Where the risk is concentrated
If your business holds personal information, your sector is already visible in the national figures. Health service providers reported more notifiable data breaches than anyone else in 2025, followed by financial services. Legal, accounting and management services sit in the top group too. Insurers read these numbers as closely as regulators do, and they price accordingly.

Where claims run into trouble
Three patterns account for most disputed claims.
The incident does not fit the section claimed. Ransomware, a privacy breach and a redirected invoice payment often sit under different parts of the same policy, with different sub-limits and conditions. Business email compromise in particular is frequently handled as cybercrime or social engineering, with its own sub-limit and verification requirements.
The declaration did not match reality. A contractor login still on password-only access, or a backup that had never been test-restored, can undo an otherwise strong position. Australian insurer documents are explicit that failure to disclose relevant information may allow an insurer to reduce or refuse a claim.
The response ran ahead of the policy. Many wordings require prompt notification, preservation of evidence, insurer consent before certain costs are incurred, and the use of approved incident responders. Wiping systems or engaging your own forensics firm before making the call can complicate what follows.
The regulatory bar is rising too
Since 30 May 2025, businesses carrying on business in Australia with annual turnover of at least $3 million must report a ransomware or cyber-extortion payment within 72 hours. Separately, the OAIC has made clear that the notifiable data breach clock starts when anyone in the organisation becomes aware of the incident, not when it finally reaches the IT or privacy contact. An incident response plan that lives in a drawer will not meet either timeframe.
What you should do next
Treat your insurance proposal form as a business record, not paperwork. Before renewal, ask your IT provider or MSP to verify each answer, and keep the proof with the policy file: MFA configuration exports, backup restore-test results, patch reports, training records and your incident response plan.
Then read the policy for the practical details — notification timeframes, approved responders, cybercrime sub-limits, exclusions and consent requirements — and raise anything unclear with your broker now, not during an incident.
Finally, run a short tabletop exercise. Sixty minutes spent on “what would we do if email, payroll or invoicing were unavailable tomorrow?” will find the gaps faster than any questionnaire.
Insurance works best when it supports a prepared business. An independent assessment gives you a current, documented view of the controls insurers actually price — before the form is signed.
Frequently asked questions
Can a claim be denied because MFA was missing?
Are backups enough on their own?
What if my claim is disputed or declined?
Not sure where your business stands?
Independent assessments, Australia-wide. Every enquiry is confidential.
Request a Confidential Enquiry
More from Technical News
Stay informed with our latest articles on property protection, security trends, and best practices.

