
TLDR
Australia's Essential Eight maturity model sets four cyber security levels; Maturity Level One is the practical baseline for small firms facing opportunistic ransomware. Businesses turning over more than $3 million must report any ransomware payment within 72 hours. A misrepresentation on an insurance proposal form can void a claim under section 28 of the Insurance Contracts Act 1984.
KEY TAKEAWAYS
The framework behind the question
When a cyber insurer asks whether your business uses multi-factor authentication or keeps offline backups, it is not making small talk. It is scoring you against a government framework that has become the de facto benchmark for underwriters in this market. That framework is the Australian Signals Directorate's Essential Eight, and the level that matters most to a small or mid-sized Australian business is the first one.[1]
The ASD's Essential Eight maturity model defines four maturity levels, running from Zero to Three, to support the implementation of eight prioritised mitigation strategies.[1] Level Zero means no meaningful controls are in place. Level Three means defences calibrated against targeted, persistent adversaries. For most businesses with a handful of staff and a part-time IT arrangement, the realistic conversation starts and ends at Level One.
What the eight controls actually require
The eight mitigation strategies are: patch applications; patch operating systems; multi-factor authentication; restrict administrative privileges; application control; restrict Microsoft Office macros; user application hardening; and regular backups.[2] Each one sounds like a policy document item. In practice, each one represents a class of decision a business either makes or avoids making.
Patching applications means applying security updates to software within a defined window after a vendor releases a fix. Patching operating systems means doing the same for the underlying platform. The two patching controls together close the doors that commodity malware and ransomware kits are programmed to walk through automatically.[2]
Multi-factor authentication requires a second proof of identity beyond a password: a code from an app, a hardware key, a biometric. At Level One, this applies to remote access and to accounts with elevated permissions. Restricting administrative privileges means staff do not log in with administrator rights for everyday work; those rights are assigned only to accounts used for specific administrative tasks, and those accounts are not used for email or web browsing.
Application control limits which software can run on a machine to an approved list. Restricting Office macros means that code embedded in Word or Excel documents cannot execute without explicit authorisation, a common vector for business email compromise payloads. User application hardening means disabling browser features such as Flash and Java, which are rarely needed by staff and frequently exploited by attackers. Regular backups means maintaining copies of critical data and configuration settings, verifying they can be restored, and keeping at least one copy offline or isolated from the network.[2]
Why Level One is the honest target
Maturity Level One is designed to mitigate opportunistic attacks using commodity tradecraft, such as exploiting unpatched vulnerabilities and reusing stolen credentials, making it a realistic cyber security baseline for small businesses.[1] The word "opportunistic" is doing real work in that description. Opportunistic attackers do not research your business specifically; they scan the internet for known vulnerabilities, buy credential lists from previous breaches, and run automated tools. Level One controls are calibrated to defeat exactly that class of attack.
Self-assessment before renewal means working through each of the eight controls and asking, for each one, whether the Level One requirement is documented, implemented and verifiable. "Implemented" means it is running, not planned. "Verifiable" means someone could confirm it without relying solely on your word. Where the answer is uncertain, that uncertainty belongs on the proposal form, not in a box marked "yes".
Adam Peckman, Head of Cyber Solutions, Asia Pacific at Aon, said bad actors continue to target sensitive data and leverage online platforms to amplify reputational harm on the targeted business and data subjects, at times through direct harassment of employees, customers, or executives.[6] For small businesses, that means a ransomware incident is no longer simply an operational disruption; it carries a reputational tail that can outlast the recovery.
The 72-hour reporting clock
Under the Cyber Security Act 2024 and the Cyber Security (Ransomware Payment Reporting) Rules 2025, any reporting business entity with annual turnover exceeding AUD 3 million must lodge a ransomware payment report within 72 hours of making or becoming aware of the payment.[3] The rules took effect on 30 May 2025. The 72-hour window carries a civil penalty for non-compliance.
The trigger is making a payment or becoming aware that a payment has been made on your behalf. A business that authorises a third party, such as a cyber insurer acting under a managed response arrangement, to make a payment in its name remains the reporting entity. The obligation does not transfer with the payment.
Lodgement is done through the Australian Signals Directorate's reporting portal. The report must identify the business, describe the ransomware incident, confirm the amount and nature of the payment, and provide contact details for follow-up. The government has been explicit that the intent is intelligence collection, not punishment of victims; the data is used to map threat actor activity across the economy.[3]
Minister for Cyber Security Tony Burke said the legislation ensures Australia keeps pace with emerging threats, positioning individuals and businesses better to respond to, and bounce back from cyber security threats.[5] The 72-hour obligation is the sharpest edge of that legislative intent for businesses above the reporting threshold.
What your answers on the proposal form actually cost
Cyber insurance proposal forms have grown considerably more detailed over the past three years. Where once a single question covered "do you use antivirus software", forms now routinely ask specifically about each of the Essential Eight controls, the maturity level claimed, the patch cycle in days, the backup frequency and the last tested restore date. The specificity is deliberate: it creates a clear factual record of what was represented before the policy was bound.
Under section 28 of the Insurance Contracts Act 1984, an insurer may avoid a general insurance contract or reduce its liability if the insured made a misrepresentation to the insurer before the contract was entered into.[4] The section distinguishes between fraudulent misrepresentation, which allows the insurer to avoid the contract entirely, and non-fraudulent misrepresentation, which allows the insurer to reduce its liability to the extent it would have offered different terms had it known the truth. Either outcome at claim time is significantly worse than the alternative.
The alternative is an honest answer on the proposal form. An applicant who marks "no" against MFA for remote access will likely receive a higher premium, a sub-limit on ransomware coverage, or a requirement to implement the control within 90 days as a condition of the policy. Those outcomes are negotiable before inception. A coverage dispute at claim time, after a ransomware incident has encrypted the business's systems and the insurer has pulled the proposal form, is not.
The practical step before any renewal is a structured walkthrough of the proposal questions against actual system state. For each control where the honest answer is "partially" or "no", the business has a defined period before renewal to close the gap or disclose it accurately. Documented evidence of patching schedules, MFA enrolment reports, backup test logs and privilege access reviews serves two purposes: it supports an accurate proposal form, and it gives the insurer verifiable evidence at claim time that the controls described were genuinely operating.
The Essential Eight is not a compliance exercise invented by insurers. The ASD designed it to give organisations a structured path from no controls to meaningful defences.[1] The insurance market adopted it because it maps cleanly onto the question every underwriter is trying to answer: how likely is this business to make a claim? For a small business owner signing a renewal form, that same framework now answers a second question: how likely is the insurer to pay it?
SOURCES & CITATIONS
- Essential Eight Maturity Model, Australian Signals Directorate
- Essential Eight Said, Australian Signals Directorate
- Ransomware Payment Reporting Factsheet, Department of Home Affairs
- Insurance Contracts Act 1984 s28, AustLII
- Government introduces Cyber Security legislation, Minister Tony Burke
- Building Better Resilience Against Ransomware, Aon (Adam Peckman)
FREQUENTLY ASKED QUESTIONS
What is Maturity Level One of the Essential Eight?
Which businesses must report a ransomware payment to the government?
What happens if I tick 'yes' on a cyber insurance form but don't have the controls in place?
What are the eight controls in the Essential Eight?
When did the ransomware payment reporting obligation take effect?

Elias Thorne writes about interest rates, the bond market and the Reserve Bank. He is interested in what monetary policy actually does to household budgets, and in the long stretches of economic history that tend to repeat.



