Multi-factor authentication coverage, endpoint detection, tested backups and an incident response plan. Four questions that decide your premium — and, at claim time, whether the policy responds at all.
Cyber insurance renewal forms have got longer and more specific over the last few years, and that is not an accident. Australian insurers paid out enough on business email compromise and ransomware to stop asking “do you have cyber security measures in place?” and start asking questions with checkable answers.
Which is good news, in a backhanded way: the questions tell you exactly what a professional underwriter thinks matters. Here is what sits behind the four that come up almost every time.
Note the word enforced. Not enabled, not available, not encouraged. Insurers learned that “we have MFA” usually meant it was switched on and roughly two thirds of staff had enrolled.
Enforced means a conditional access policy that refuses the sign-in when the second factor is absent. If you answer yes to this question, the evidence you want on file is a screenshot of the policy and a sign-in report showing zero successful single-factor authentications in the period.
The gap that catches people: an exclusion for a service account, a mailbox on a legacy protocol, or the one director who found MFA annoying. One unenforced account is the account that gets used.
Not antivirus. Insurers are asking specifically about EDR because they can see the difference in their own claims data — environments with behavioural detection catch intrusions at the foothold stage rather than at the encryption stage, and the difference in claim size is enormous.
Answer honestly. Microsoft Defender Antivirus, which comes with Windows, is not EDR. Defender for Endpoint Plan 2 is. A third-party managed EDR product is. If you are not sure which you have, that uncertainty is itself the answer, and it is worth resolving before you sign a declaration.
Two questions bolted together, and both matter for different reasons.
Tested means somebody restored something and watched it come back. A green tick in a backup console tells you a job completed, not that the data inside it is usable. We write about that at more length in a backup you have never restored is a hypothesis.
Offline or immutable matters because modern ransomware goes looking for the backups first. If your backup server is domain-joined and reachable with the credentials the attacker just harvested, it will be encrypted alongside everything else. Immutable storage cannot be altered or deleted for a defined retention window, even by an administrator.
This is the question most small businesses answer optimistically, and the one that costs the most when it turns out to be untrue.
A plan is not a paragraph in an IT policy. At minimum it names who decides to disconnect something, who rings the insurer — and most policies require notification within a specific window, often 72 hours — who talks to staff, who talks to customers, and where the phone numbers live when the network is down and nobody can open SharePoint. A printed copy in a drawer is not old-fashioned; it is the whole point.
The obvious consequence of a weak answer is a higher premium or a declined application. The consequence people miss is at claim time.
An insurance proposal is a declaration. If you state that MFA is enforced on all accounts and the forensic report after an incident shows the compromised mailbox had no second factor, the insurer is entitled to examine whether the policy responds. That is the worst possible moment to discover the answer you gave was aspirational.
So the useful discipline is not answering well — it is being able to evidence every answer you give, on the day you give it.
If this list feels familiar, it is because it is nearly a subset of SMB1001 Gold: enforced MFA, endpoint detection and response, tested backups, a documented incident response plan, and cyber insurance in force. Australia's SMB cyber standard and Australian underwriters converged on the same short list, which is a reasonable signal that the list is right.
The practical benefit is that one piece of work answers both. Certify to Gold and the evidence pack you assemble for the attestation is the same evidence pack that substantiates your insurance declaration.
One caveat worth stating plainly: we are an IT provider, not insurance brokers. Policy wordings differ enormously and your broker is the right person to interpret yours. What we can do is make sure the answers you give them are true and evidenced.
Australia now has a cyber security standard written for businesses with no security team. Here is what the five tiers actually ask for, which one you should aim at, and what changed in the 2026 edition.
Read the article
Microsoft 365The oversharing review nobody wants to do, why sensitivity labels come before licences, and how to pick the two use cases per team that actually save time.
Read the article
ContinuityGreen ticks are not evidence. What a real restore test looks like, how often to run one, and the three failure modes that only ever show up during an actual recovery.
Read the article
The assessment is free, takes about ninety minutes on site, and ends with a written summary of what we found — yours to keep either way.
No obligation. We will tell you if you do not need us.