Subscribe
Cybersecurity

Insurers now ask about your cyber security before renewing your policy

When a cyber insurer asks whether your business uses multi-factor authentication or keeps offline backups, it is not making small talk. It is scoring you against a government framework that has become the de facto benchmark for underwriters in this market.

9 min read
An IT technician's toolkit, laptop and network gear laid out on a workbench.
Insurers now ask control-by-control questions that a proposal form answer has to survive.
Elias Thorne
By Elias Thorne · 2026-08-04

TLDR

Australia's Essential Eight maturity model sets four cyber security levels; Maturity Level One is the practical baseline for small firms facing opportunistic ransomware. Businesses turning over more than $3 million must report any ransomware payment within 72 hours. A misrepresentation on an insurance proposal form can void a claim under section 28 of the Insurance Contracts Act 1984.

KEY TAKEAWAYS

01Maturity Level One targets unpatched software and credential reuse, the tactics most likely to hit small firms.
02All eight ASD controls matter, but insurers focus hardest on MFA, patching, backups and restricted admin privileges.
03Businesses above $3 million turnover faced a 72-hour ransomware payment reporting deadline from 30 May 2025.
04Section 28 of the Insurance Contracts Act 1984 allows an insurer to avoid or reduce a claim after a misrepresentation.
05An honest 'no' on a renewal form is recoverable before inception; a wrong 'yes' discovered at claim time is not.

The framework behind the question

When a cyber insurer asks whether your business uses multi-factor authentication or keeps offline backups, it is not making small talk. It is scoring you against a government framework that has become the de facto benchmark for underwriters in this market. That framework is the Australian Signals Directorate's Essential Eight, and the level that matters most to a small or mid-sized Australian business is the first one.[1]

The ASD's Essential Eight maturity model defines four maturity levels, running from Zero to Three, to support the implementation of eight prioritised mitigation strategies.[1] Level Zero means no meaningful controls are in place. Level Three means defences calibrated against targeted, persistent adversaries. For most businesses with a handful of staff and a part-time IT arrangement, the realistic conversation starts and ends at Level One.

What the eight controls actually require

The eight mitigation strategies are: patch applications; patch operating systems; multi-factor authentication; restrict administrative privileges; application control; restrict Microsoft Office macros; user application hardening; and regular backups.[2] Each one sounds like a policy document item. In practice, each one represents a class of decision a business either makes or avoids making.

Patching applications means applying security updates to software within a defined window after a vendor releases a fix. Patching operating systems means doing the same for the underlying platform. The two patching controls together close the doors that commodity malware and ransomware kits are programmed to walk through automatically.[2]

Multi-factor authentication requires a second proof of identity beyond a password: a code from an app, a hardware key, a biometric. At Level One, this applies to remote access and to accounts with elevated permissions. Restricting administrative privileges means staff do not log in with administrator rights for everyday work; those rights are assigned only to accounts used for specific administrative tasks, and those accounts are not used for email or web browsing.

Application control limits which software can run on a machine to an approved list. Restricting Office macros means that code embedded in Word or Excel documents cannot execute without explicit authorisation, a common vector for business email compromise payloads. User application hardening means disabling browser features such as Flash and Java, which are rarely needed by staff and frequently exploited by attackers. Regular backups means maintaining copies of critical data and configuration settings, verifying they can be restored, and keeping at least one copy offline or isolated from the network.[2]

Why Level One is the honest target

Maturity Level One is designed to mitigate opportunistic attacks using commodity tradecraft, such as exploiting unpatched vulnerabilities and reusing stolen credentials, making it a realistic cyber security baseline for small businesses.[1] The word "opportunistic" is doing real work in that description. Opportunistic attackers do not research your business specifically; they scan the internet for known vulnerabilities, buy credential lists from previous breaches, and run automated tools. Level One controls are calibrated to defeat exactly that class of attack.

Self-assessment before renewal means working through each of the eight controls and asking, for each one, whether the Level One requirement is documented, implemented and verifiable. "Implemented" means it is running, not planned. "Verifiable" means someone could confirm it without relying solely on your word. Where the answer is uncertain, that uncertainty belongs on the proposal form, not in a box marked "yes".

Adam Peckman, Head of Cyber Solutions, Asia Pacific at Aon, said bad actors continue to target sensitive data and leverage online platforms to amplify reputational harm on the targeted business and data subjects, at times through direct harassment of employees, customers, or executives.[6] For small businesses, that means a ransomware incident is no longer simply an operational disruption; it carries a reputational tail that can outlast the recovery.

Australia Just Made Ransomware Payment Reporting Mandatory

The 72-hour reporting clock

Under the Cyber Security Act 2024 and the Cyber Security (Ransomware Payment Reporting) Rules 2025, any reporting business entity with annual turnover exceeding AUD 3 million must lodge a ransomware payment report within 72 hours of making or becoming aware of the payment.[3] The rules took effect on 30 May 2025. The 72-hour window carries a civil penalty for non-compliance.

The trigger is making a payment or becoming aware that a payment has been made on your behalf. A business that authorises a third party, such as a cyber insurer acting under a managed response arrangement, to make a payment in its name remains the reporting entity. The obligation does not transfer with the payment.

Lodgement is done through the Australian Signals Directorate's reporting portal. The report must identify the business, describe the ransomware incident, confirm the amount and nature of the payment, and provide contact details for follow-up. The government has been explicit that the intent is intelligence collection, not punishment of victims; the data is used to map threat actor activity across the economy.[3]

Minister for Cyber Security Tony Burke said the legislation ensures Australia keeps pace with emerging threats, positioning individuals and businesses better to respond to, and bounce back from cyber security threats.[5] The 72-hour obligation is the sharpest edge of that legislative intent for businesses above the reporting threshold.

Australia's New Ransomware Law

What your answers on the proposal form actually cost

Cyber insurance proposal forms have grown considerably more detailed over the past three years. Where once a single question covered "do you use antivirus software", forms now routinely ask specifically about each of the Essential Eight controls, the maturity level claimed, the patch cycle in days, the backup frequency and the last tested restore date. The specificity is deliberate: it creates a clear factual record of what was represented before the policy was bound.

Under section 28 of the Insurance Contracts Act 1984, an insurer may avoid a general insurance contract or reduce its liability if the insured made a misrepresentation to the insurer before the contract was entered into.[4] The section distinguishes between fraudulent misrepresentation, which allows the insurer to avoid the contract entirely, and non-fraudulent misrepresentation, which allows the insurer to reduce its liability to the extent it would have offered different terms had it known the truth. Either outcome at claim time is significantly worse than the alternative.

The alternative is an honest answer on the proposal form. An applicant who marks "no" against MFA for remote access will likely receive a higher premium, a sub-limit on ransomware coverage, or a requirement to implement the control within 90 days as a condition of the policy. Those outcomes are negotiable before inception. A coverage dispute at claim time, after a ransomware incident has encrypted the business's systems and the insurer has pulled the proposal form, is not.

The practical step before any renewal is a structured walkthrough of the proposal questions against actual system state. For each control where the honest answer is "partially" or "no", the business has a defined period before renewal to close the gap or disclose it accurately. Documented evidence of patching schedules, MFA enrolment reports, backup test logs and privilege access reviews serves two purposes: it supports an accurate proposal form, and it gives the insurer verifiable evidence at claim time that the controls described were genuinely operating.

The Essential Eight is not a compliance exercise invented by insurers. The ASD designed it to give organisations a structured path from no controls to meaningful defences.[1] The insurance market adopted it because it maps cleanly onto the question every underwriter is trying to answer: how likely is this business to make a claim? For a small business owner signing a renewal form, that same framework now answers a second question: how likely is the insurer to pay it?

This article contains analysis and commentary on market conditions. It does not constitute financial, investment, or professional advice. Past performance is not indicative of future results. Always consult a qualified adviser before making financial decisions.

FREQUENTLY ASKED QUESTIONS

What is Maturity Level One of the Essential Eight?
It is the first tier of the ASD's Essential Eight maturity model, designed to defeat opportunistic attacks that exploit unpatched software or reused credentials. It is the practical baseline recommended for small businesses with limited IT resources.
Which businesses must report a ransomware payment to the government?
Any Australian business entity with annual turnover exceeding AUD 3 million that makes or becomes aware of a ransomware payment must report it to the Australian Signals Directorate within 72 hours under the Cyber Security (Ransomware Payment Reporting) Rules 2025.
What happens if I tick 'yes' on a cyber insurance form but don't have the controls in place?
Under section 28 of the Insurance Contracts Act 1984, a misrepresentation before the contract was entered can allow the insurer to avoid the contract or reduce its liability. A fraudulent misrepresentation allows full avoidance; a non-fraudulent one allows the insurer to reduce the payout to what it would have offered had it known the truth.
What are the eight controls in the Essential Eight?
Patch applications; patch operating systems; multi-factor authentication; restrict administrative privileges; application control; restrict Microsoft Office macros; user application hardening; and regular backups.
When did the ransomware payment reporting obligation take effect?
The Cyber Security (Ransomware Payment Reporting) Rules 2025 took effect on 30 May 2025 under the Cyber Security Act 2024.
Elias Thorne

Elias Thorne

Elias Thorne writes about interest rates, the bond market and the Reserve Bank. He is interested in what monetary policy actually does to household budgets, and in the long stretches of economic history that tend to repeat.

What's your reaction?

Make us a preferred source on Google

Tap once and our reporting shows at the top of your Google search results and AI answers. You can change this at any time.

Add as a preferred source on Google
Subscribe — it's free