TECHNICAL NEWS

·

Cyber Insurance

·

3 min read

Your Cyber Insurance Might Not Pay Out

Australian insurers now require evidence of compliance with your controls when you claim.

Cyber insurance has become a critical part of risk management for Australian small and medium businesses. But you need to ensure you are compliant.

The Australian Signals Directorate received more than 84,700 cybercrime reports in 2024–25. Small businesses self-reported average costs of $56,600, and medium businesses $97,200 — a 55% jump in a single year. Those numbers explain why cover is worth having. They also explain why insurers are now asking much harder questions before they payout on claims.

Bar chart: average self-reported cost of cybercrime per report in FY2024-25. Small business $56,600, medium $97,200, large $202,700. Source: ASD Annual Cyber Threat Report 2024-25.

BOTTOM LINE UP FRONT

A cyber policy is a contract with conditions, not a recovery fund. Insurers rely on what you declare about multi-factor authentication, backups, patching and endpoint protection — and they will test those declarations after an incident. If a control was not actually in place, or cannot be evidenced, the claim gets harder.

Insurers now verify, not just ask

The Australian cyber insurance market has matured. Access is broader and pricing more competitive than it was a few years ago, but underwriting has tightened around a short list of basics.

Proposal forms from mainstream Australian underwriters ask the same practical questions. Is multi-factor authentication enforced on remote access, email, privileged accounts and backups? Are backups isolated, frequent and tested? How quickly are critical patches applied? Is endpoint detection deployed? Do staff receive social-engineering training?

If that list feels familiar, it should. It is largely the ACSC’s Essential Eight, written in an underwriter’s language.

What insurers ask you to prove

These are the controls that appear again and again on Australian SME proposal and renewal forms. Most map directly to the ACSC Essential Eight.

  • Multi-factor authentication (Essential Eight) — enforced on remote access, email, privileged accounts and backups, not just “enabled somewhere”.

  • Backups that restore (Essential Eight) — frequent, isolated or immutable, and test-restored, with the test result on file.

  • Patching cadence (Essential Eight) — critical patches applied within a stated window, across operating systems and applications.

  • Restricted administrator privileges (Essential Eight) — who holds admin rights, how they are reviewed, and whether vendors hold standing access.

  • Endpoint detection and response (insurer-specific) — next-generation endpoint protection deployed across servers and workstations.

  • Email and payment verification (insurer-specific) — email filtering and authentication, plus a call-back rule before any supplier bank-detail change.

  • Tested incident response plan (insurer-specific) — who calls the insurer, who preserves evidence, who notifies the regulator, rehearsed, not filed.

Where the risk is concentrated

If your business holds personal information, your sector is already visible in the national figures. Health service providers reported more notifiable data breaches than anyone else in 2025, followed by financial services. Legal, accounting and management services sit in the top group too. Insurers read these numbers as closely as regulators do, and they price accordingly.

Notifiable data breaches by sector in 2025: health service providers 225, financial services 157, Australian Government 118, business and professional associations 103, education 81, legal and accounting 81. Source: OAIC.

Where claims run into trouble

Three patterns account for most disputed claims.

The incident does not fit the section claimed. Ransomware, a privacy breach and a redirected invoice payment often sit under different parts of the same policy, with different sub-limits and conditions. Business email compromise in particular is frequently handled as cybercrime or social engineering, with its own sub-limit and verification requirements.

The declaration did not match reality. A contractor login still on password-only access, or a backup that had never been test-restored, can undo an otherwise strong position. Australian insurer documents are explicit that failure to disclose relevant information may allow an insurer to reduce or refuse a claim.

The response ran ahead of the policy. Many wordings require prompt notification, preservation of evidence, insurer consent before certain costs are incurred, and the use of approved incident responders. Wiping systems or engaging your own forensics firm before making the call can complicate what follows.

The regulatory bar is rising too

Since 30 May 2025, businesses carrying on business in Australia with annual turnover of at least $3 million must report a ransomware or cyber-extortion payment within 72 hours. Separately, the OAIC has made clear that the notifiable data breach clock starts when anyone in the organisation becomes aware of the incident, not when it finally reaches the IT or privacy contact. An incident response plan that lives in a drawer will not meet either timeframe.

What you should do next

Treat your insurance proposal form as a business record, not paperwork. Before renewal, ask your IT provider or MSP to verify each answer, and keep the proof with the policy file: MFA configuration exports, backup restore-test results, patch reports, training records and your incident response plan.

Then read the policy for the practical details — notification timeframes, approved responders, cybercrime sub-limits, exclusions and consent requirements — and raise anything unclear with your broker now, not during an incident.

Finally, run a short tabletop exercise. Sixty minutes spent on “what would we do if email, payroll or invoicing were unavailable tomorrow?” will find the gaps faster than any questionnaire.

Insurance works best when it supports a prepared business. An independent assessment gives you a current, documented view of the controls insurers actually price — before the form is signed.

Frequently asked questions

Can a claim be denied because MFA was missing?

Are backups enough on their own?

What if my claim is disputed or declined?

Not sure where your business stands?

Independent assessments, Australia-wide. Every enquiry is confidential.

Request a Confidential Enquiry