The cyber insurance checklist for Australian small businesses
Cyber insurance proposal forms have become far more demanding in the last few years. Insurers no longer ask whether you take security seriously — they ask for specific controls, and the answers change your premium, your excess, and sometimes whether you are offered cover at all. Here is what they actually ask, and how to be ready before you fill anything in.
Insurers price on controls you can demonstrate, not on how seriously you say you take security.
Multi-factor authentication has moved from a discount to a baseline expectation on most proposal forms.
A proposal form is a disclosure document. Guessing on an answer can affect a claim years later.
Why insurers ask these questions at all
Cyber claims in Australia are dominated by a small number of predictable causes: compromised email accounts, ransomware that reached backups, and stolen credentials that were never protected by a second factor. Underwriters have the claims data, and their proposal forms are built backwards from it.
That is useful to know, because it tells you what the questions are really for. Each one is a proxy for a claim pattern the insurer wants to avoid paying for. When you answer, you are not just filling in a form — you are telling them which of those patterns you are already protected against.
The eight questions almost every proposal form asks
Wording differs between insurers and brokers, but these eight themes appear on nearly every Australian cyber proposal form. For each one, here is what the underwriter is actually checking.
1. Multi-factor authentication (MFA)
What they are checkingWhether a stolen password alone is enough to get into your business. Expect to be asked about MFA specifically on email, remote access (VPN or remote desktop) and administrator accounts — not just "do you use MFA somewhere".
- Is MFA enforced on all email accounts, including shared mailboxes?
- Is it enforced for remote access into the network?
- Is it enforced for privileged or administrator accounts?
2. Backups — and whether you have tested them
What they are checkingWhether ransomware can reach your backups, and whether you have ever proven a restore works. "We have backups" is a weaker answer than "backups are kept offline or immutable, and we last restored a file successfully in March".
- Are backups kept separate from the production network?
- How frequently do they run, and how far back do they go?
- When did you last test a restore, and did it work?
3. Patching and updates
What they are checkingHow long a known vulnerability stays open in your environment. Insurers increasingly ask for a timeframe, not a yes/no — particularly for internet-facing systems and for operating systems no longer receiving security updates.
4. Administrator privileges
What they are checkingHow many people could do catastrophic damage with one compromised login. The favourable answer is a small, named set of admin accounts that are separate from the everyday accounts those same people use for email and browsing.
5. Email filtering and staff awareness
What they are checkingBecause most incidents still start in an inbox. Expect questions about spam and phishing filtering, and about whether staff receive any security training — even brief, occasional training is viewed better than none.
6. Endpoint protection
What they are checkingWhether something is watching the actual computers. Larger policies may ask specifically about endpoint detection and response (EDR) rather than traditional antivirus, and whether it is monitored or simply installed.
7. Incident response planning
What they are checkingWhether the first hour of an incident would be organised or chaotic, since that hour drives the size of the claim. A short written plan naming who is called, in what order, and who can authorise decisions is far better than nothing documented.
8. The data you hold and your Privacy Act obligations
What they are checkingYour exposure if data is lost. Expect questions about the volume and type of personal information you hold, whether you handle sensitive information such as health records, and whether you understand your obligations under the Notifiable Data Breaches scheme.
What tends to raise a premium — or stall an application
Brokers consistently report the same friction points for small businesses:
- No MFA on email. The most common reason an application is loaded, restricted, or sent back with conditions.
- Backups reachable from the network. If ransomware can encrypt the backups, the insurer is carrying the entire recovery cost.
- End-of-life systems. Operating systems or software no longer receiving security updates are a visible, easily priced risk.
- Shared administrator accounts. Especially a single admin login used by several people or by an external provider.
- "I'll have to ask our IT provider." Not a control problem, but it delays applications for weeks and signals that nobody internally owns security.
None of these are unfixable. Most are configuration changes rather than purchases — which is why knowing your gaps before you apply is worth so much.
What to have ready before you start the form
The form itself is quick. Gathering the evidence is the slow part. Have these to hand:
- A list of which systems have MFA enforced, and on which account types.
- Your backup arrangement: what is backed up, how often, where it is stored, and the date of your last successful restore test.
- Roughly how quickly security updates get applied, and whether anything is running unsupported software.
- The number of administrator accounts and who holds them.
- Your incident response plan, even if it is one page.
- An estimate of how many individual customer records you hold and whether any is sensitive information.
- Details of any previous incident or claim, which you will be asked to disclose.
Three mistakes worth avoiding
Guessing to make the answer look better
A proposal form is a disclosure document. An answer that is optimistic rather than accurate can affect how a claim is assessed later, when it matters most. If you are unsure, describe what you actually do — underwriters deal in nuance far better than most business owners expect.
Leaving it to the last week before renewal
If the application surfaces a gap, you want time to close it and answer "yes" rather than accept a loading or an exclusion. Starting a month out changes what you can negotiate.
Treating it as paperwork rather than a free risk assessment
The proposal form is, in effect, an insurer telling you exactly which controls they believe prevent expensive incidents. That list is worth acting on whether or not you end up buying the policy.
Questions we get asked
Do Australian cyber insurers require MFA?
Most Australian cyber insurers now treat multi-factor authentication as a baseline expectation rather than a bonus, particularly on email, remote access and administrator accounts. Requirements vary by insurer and policy, so confirm against your specific proposal form.
What happens if I answer a question incorrectly?
A proposal form is a disclosure document. Answering inaccurately, even unintentionally, can affect how a claim is assessed later. If you are unsure about a control, say so and describe what you actually do rather than guessing.
Do I need an incident response plan to get cover?
Many proposal forms ask whether you have a documented incident response plan and whether it has been tested. A short, written plan that names who is called and in what order is generally viewed more favourably than having nothing documented.
How long does preparing an application take?
Gathering the evidence is usually the slow part, not the form itself. Businesses that already know their control gaps and have their answers written down can typically complete a proposal form in an afternoon.
Find out how you would answer — in 12 minutes
PostureCheck asks 33 plain-English questions about how your business actually operates, then scores you against the Essential Eight, the Privacy Act 1988 and the NDB scheme. The assessment is free, nothing is installed, and you see your readiness score immediately. If the findings are useful, the full executive report unlocks for AUD 149.
Start the free assessmentPreparing an application right now? The Cyber Insurance Readiness Pack reformats your answers into insurer language, or see a sample report first.
This guide is general information for Australian businesses and is not insurance, legal or financial advice. Proposal form questions vary by insurer, broker and policy — always confirm against your own documentation. PostureCheck is a structured self-assessment tool and is not a licensed insurance intermediary; using it does not guarantee cover, eligibility, premium or any claim outcome.