Serving Central Coast, Newcastle & the Hunter Region, NSW

Contact us today 1300 270 412
Simple IT

24 August 2026

Cyber Insurance Requirements for Australian SMEs

Cyber Insurance Requirements for Australian SMEs

A cyber insurance application can look deceptively simple: a series of yes-or-no questions about passwords, backups and staff access. Yet those answers may shape the cover you can obtain, the premium you pay and how an insurer responds after an incident. For many local businesses, cyber insurance requirements are now closely tied to the everyday way their IT is managed.

This is not about making your business perfect. It is about being able to show that sensible safeguards are in place, documented and actually used. A policy cannot prevent a phishing email, an invoice scam or a staff member’s Microsoft 365 account being compromised. It can help with the financial and operational consequences, but insurers expect businesses to take reasonable steps to reduce the likelihood and impact of an incident.

Why cyber insurance requirements have become stricter

Cyber claims have become more frequent and more expensive. Ransomware can stop operations for days, while a compromised email account may lead to fraudulent payments, privacy notifications, legal costs and customer communication. Insurers have responded by asking more detailed questions before issuing or renewing cover.

For a business with 5 to 100 staff, the practical change is that cyber insurance is no longer only a finance or compliance task. It is also an IT governance task. The person completing the application needs accurate information about systems, users, cloud services, backups and security processes.

Requirements differ between insurers and policies. Some controls are mandatory for cover, while others affect the excess, premium or available limit. Policy wording also matters. Your broker or insurer is the right source for advice on your specific policy; your IT provider should help you understand and evidence the technical controls being asked about.

The cyber insurance requirements insurers commonly ask about

Multi-factor authentication

Multi-factor authentication, usually called MFA, is now one of the most common requirements. It asks users to provide something more than a password when signing in, such as an approval in an authenticator app or a code.

Insurers often want MFA enabled for email, remote access, cloud applications and administrator accounts. This matters because stolen passwords remain one of the simplest ways for criminals to enter a business. If your team uses Microsoft 365, MFA should cover every user, not just directors or the IT team.

There can be exceptions for older software or shared devices, but these should be identified and managed rather than ignored. A single unprotected administrator account can undermine otherwise good security.

Secure backups and recovery testing

A backup that has never been tested is not much reassurance during a ransomware event. Insurers commonly ask whether backups are kept separately from the main network, protected from unauthorised deletion and tested regularly.

For example, if a staff member can access both your file server and every backup with the same account, a compromised login may affect both. A stronger arrangement uses separate credentials, restricted access and at least one backup copy that cannot be easily altered by an attacker.

The second part is recovery. Your business should know what can be restored, how long it is likely to take and which systems need to be brought back first. An accounting firm may prioritise practice management software and client files; a warehouse may need its stock and dispatch systems running quickly. Recovery plans should reflect how your business actually operates.

Patching and supported software

Software providers regularly release updates to fix security weaknesses. Insurers may ask whether operating systems, applications, firewalls and other devices are patched within a defined timeframe.

The harder issue is unsupported software. An old computer or server may still work well enough for a specific application, but if it no longer receives security updates, it creates a known risk. Replacing it may not be convenient or inexpensive, particularly where specialist equipment is involved. However, a business should have a documented plan to replace, isolate or otherwise reduce the risk around unsupported technology.

Email and endpoint protection

Email remains a common entry point for cybercrime, particularly through fake invoices, password-reset messages and Microsoft 365 login pages that look genuine. Insurers increasingly ask about email filtering, anti-malware tools and protections on computers and laptops.

These questions are not simply about whether antivirus is installed. Insurers may want to know whether protection is centrally managed, whether alerts are reviewed and whether devices are kept up to date. A centrally managed service is generally easier to demonstrate than a collection of individually installed products with no visibility.

Access controls and administrator accounts

Businesses accumulate user accounts over time. A former employee’s mailbox, a contractor’s remote login or a shared administrator password can become an unnecessary exposure. Cyber insurance applications often ask how access is granted, reviewed and removed.

Each person should have their own account, and staff should only have access to the systems they need. Administrator access deserves particular care because it can change settings, create users and access large amounts of data. Day-to-day work should not normally be performed from a highly privileged account.

A simple offboarding process helps. When someone leaves, decide who is responsible for disabling their access, forwarding their email if needed and checking business-owned devices are returned. This is as much an operational discipline as a technical one.

Staff awareness and payment verification

Technology cannot catch every convincing email. Many cyber policies ask whether staff receive security awareness training and whether the business has processes to verify changes to bank account details or payment instructions.

Training works best when it is brief, repeated and relevant. A receptionist may need to recognise a suspicious document attachment, while accounts staff should know what to do when a supplier emails new bank details. A phone call to a known contact number can prevent a costly payment diversion. Do not rely on the number included in the email requesting the change.

An incident response plan

When an incident occurs, the first few hours are often confused. An incident response plan gives staff a practical starting point: who to call, who can make decisions, what systems should be isolated and how the insurer or broker should be notified.

It does not need to be a lengthy document sitting unused in a folder. For a smaller business, a clear contact list, basic response steps and a record of key suppliers may be enough to start. The plan should be stored somewhere available if the main network or email system is unavailable.

Completing an application accurately

The most overlooked requirement is accuracy. Avoid guessing when an insurer asks whether MFA is enabled for all users or whether backups are tested. “Mostly” may not be the same as “yes”, and a control that was in place last year may have changed after new software, staff turnover or an office move.

Before completing an application or renewal, ask your IT provider to review the questions with you. Gather evidence such as backup test records, MFA settings, software asset lists, security training records and incident response contacts. This is useful beyond insurance because it exposes gaps before they become urgent.

Be particularly careful with broad wording such as “all systems”, “all privileged accounts” or “regularly tested”. If there are exceptions, disclose them through the appropriate process and seek clarification from the insurer or broker. A lower premium is not worth an answer that cannot be supported later.

Turning requirements into sensible business practice

The best approach is not to chase each insurer question separately. Build a manageable security baseline that supports your business, then review it as your systems change. For many organisations, that means managed MFA, monitored endpoint protection, reliable backups, regular patching, documented user access processes and straightforward staff training.

There are trade-offs. Tight access restrictions can add a little friction, and replacing unsupported systems requires budget planning. But the alternative is often hidden cost: downtime, rushed purchases after an incident and uncertainty when completing an insurance renewal.

At Simple IT, we often see the greatest value come from making security controls visible and repeatable, rather than relying on one person’s memory. If your next renewal is approaching, start the conversation early. A practical review of the questions, your current controls and any gaps gives you time to make considered decisions instead of scrambling for answers at the last minute.

Book a free IT review with your local team

Talk to a local Central Coast IT team — no jargon, no obligation.