Cyber insurance is quietly rewriting your IT requirements

For most Australian small businesses the organisation setting their security standards is now their insurer. What is being asked, why the questionnaire matters more than the policy, and how to prepare.

For most Australian small businesses, the organisation now setting their security standards isn’t the government, an auditor, or their own board. It’s their insurer.

This has happened gradually and without much announcement. Cyber cover used to be a policy you bought and largely forgot. Now the application is a detailed technical questionnaire, the answers form part of the contract, and the requirements tighten every renewal.

What insurers are now asking for

The specifics vary, but the direction is consistent. Controls that were “recommended” three years ago are increasingly conditions of cover:

  • Multi-factor authentication on email and remote access, usually with no exceptions permitted, including for executives.
  • Backups that are tested and separated from the production environment, so ransomware can’t reach them.
  • Endpoint detection rather than traditional antivirus.
  • A patching regime with defined timeframes, particularly for internet-facing systems.
  • Security awareness training that happens on a schedule rather than once at induction.
  • An incident response plan that exists as a document, with names and phone numbers in it.

None of this is unreasonable. It’s roughly the set of controls that actually prevents the claims insurers are tired of paying.

Why the questionnaire matters more than the policy

This is the part businesses underestimate, and it’s the reason I write about it.

When you complete a proposal form, you’re making representations that the insurer relies on. If you tick that MFA is enforced across all remote access, and it later emerges during a claim that three service accounts and two directors were exempt, you have a problem that is considerably larger than the exemption itself.

I’m not a lawyer and this isn’t legal advice, so take the specifics to your broker. But the general shape is worth understanding: the risk isn’t only that you’re less secure than you thought. It’s that the document you signed says something different from your environment, at exactly the moment you need the document to be true.

Most inaccurate answers I see aren’t dishonest. Someone ticked a box in good faith, based on how things worked when the control was implemented, and nobody re-checked after the environment changed.

Renewal as a forcing function

Here’s the practical opportunity in all this. Security improvements are perpetually deprioritised because there’s no deadline. Insurance renewal supplies one, along with a number attached to it.

“We should improve our security posture” loses to every other agenda item. “Our renewal is in eleven weeks and we currently can’t answer yes to four of these questions” does not. Same work, entirely different conversation, and I’ve watched it unblock budgets that had been stuck for two years.

What to do before your next renewal

  1. Get last year’s completed questionnaire and read it as if you were investigating a claim. Which answers would you struggle to evidence?
  2. Verify rather than assume. Don’t ask whether MFA is enabled. Ask for the list of accounts that are exempt, because there is almost always a list.
  3. Do a documented test restore. This is the single most common gap, and “we have backups” is not the same claim as “we have restored from them recently”.
  4. Start twelve weeks out. Several of these controls take real time to implement, and doing them badly in a fortnight to answer yes is how you end up with an answer that isn’t quite true.
  5. Where a control is partial, say so and describe the compensating measure. A precise answer with a caveat is stronger evidence of maturity than a bare yes.

The wider point

It’s a slightly odd outcome that commercial insurance has become a more effective driver of Australian small business security than any amount of official guidance. But it’s working, because it attaches a price and a date to something that otherwise has neither.

If you’re going to be pushed into doing this work anyway, the better move is to do it deliberately, on your timeline, and end up with controls that genuinely function rather than a questionnaire that reads well. The first also happens to reduce the chance you ever need to claim.


Written by

Matt Rollins is a Melbourne-based technology founder. He runs TechAssist, a managed IT provider serving growing Australian businesses, and is building TeachingBlox, AussieWave Hosting and Self Storage Auctions.

Start a conversation or connect on LinkedIn.