What Underwriters Check Before They Cover an Australian Business

Claymation illustration of an insurance assessor with a clipboard examining a small business owner's setup

Before an insurer covers an Australian business for cyber, an underwriter weighs five things: the controls the business runs, the industry it operates in, the volume and nature of the data it holds, its third-party and supply chain exposure, and its claims history. The Insurance Council of Australia describes the process plainly: when writing a cyber insurance policy, insurers need to access their client's data and IT processes, and potentially test their cyber defences, in order to analyse and price the risk. Someone has to put a number on your environment. These are the inputs they use to do it.

None of that says what a particular policy would do after a particular incident. That question belongs to the insurer's assessment and the policy's own terms, and it is not one an IT provider can answer. What the five factors do explain is the questionnaire on your desk: once you know what the person on the other side of it is trying to establish, the questions stop looking arbitrary and the honest answers become easier to write.

And if this year's questionnaire is noticeably harder than last year's, the change is deliberate. The reason is worth understanding before you start filling it in.

TL;DR: What to remember

  • ✅ Underwriters price the current state of your environment. The Insurance Council of Australia states insurers may access data and IT processes and potentially test defences to analyse and price the risk.
  • ✅ Five factors carry the assessment: your controls, your industry sector, the data you hold, third-party and supply chain risk, and claims history. Controls are the only one you can change before a renewal.
  • ✅ The Insurance Council endorses the Australian Signals Directorate's Essential Eight Maturity Model as a good first step, particularly for small and medium-sized enterprises.
  • ✅ Answer the questionnaire against evidence, not intention. An honest no with a documented plan and a date is a stronger position than a yes that would not survive examination.

Contents

Why the renewal questionnaire got harder

Cyber insurance is a young product, and the Insurance Council is candid about the difficulty of pricing it. It describes the ever-changing nature of cyber risk as meaning coverage cannot be predicted on prior historical claims experience, and notes that incomplete data sets make premiums difficult to price. In most classes of insurance, decades of claims history do a lot of the pricing work. Here, that history is thin and ages quickly.

Where history is a weaker guide, the current state of the risk carries more of the weight. That is why the form now reads less like a form and more like a technical review. The insurer is not being difficult. Your environment, as it stands today, is the part of the picture that can actually be known, so that is where the questions go.

The costs sitting behind those questions are real and rising. The Insurance Council, citing the Australian Cyber Security Centre's (ACSC) Annual Cyber Threat Report for 2024-25, records that the ACSC answered over 42,500 calls to its hotline that year, and that the average self-reported cost of cybercrime per report was $56,600 for small businesses and $97,200 for medium businesses, both up on the year before. These figures are averages drawn from reports made to the ACSC rather than a measure of typical loss, so read them as an indication of scale, not a forecast for any particular business.

The five factors underwriters weigh

The Insurance Council describes insurers as typically placing a strong focus on a customer's risk management and cyber security controls when reviewing, assessing and pricing the risk. Its 2026 submission on small business cyber insurance sets out the other factors given consideration alongside them. Taken together, the assessment rests on five things.

The controls you run

The strong focus, in the Insurance Council's own description, and the one factor on this list you can materially change before a renewal. Everything in the next section is about this one, because it is where the work is.

The industry you operate in

Some sectors are targeted more often, hold more sensitive data, or carry heavier regulatory consequences when something goes wrong. This factor is fixed. You cannot argue a business into a different sector, and there is no point trying to on a proposal form.

The volume and nature of the data you hold

A business holding health information or financial records is a different proposition from one holding job records and an invoicing system, even at the same headcount. Underwriters ask about the data because the data is what an incident turns into a liability.

Third-party and supply chain risk

Who else can reach your systems, and whose systems hold your data. The Australian Securities and Investments Commission's (ASIC) cyber pulse survey found 44% of participants were not managing third-party or supply chain risks, which makes this the question most likely to expose a gap. If your answer here is thin, you are in large company, and underwriters know it.

Your claims history

Yours, and the sector's. Past incidents are part of the record whether or not they were claimed, and the sector's experience shapes the appetite you are walking into.

Notice what is absent from the five. How much you spend on IT is not there. How new the equipment is, is not there. How confident anyone feels is not there. An underwriter is assessing evidence of managed risk, not investment, and the questionnaire is built to find the evidence.

The controls that carry the most weight

Rather than guessing at any individual insurer's appetite, there is a published anchor to work from. For all businesses and particularly small and medium-sized enterprises (SMEs), the Insurance Council of Australia endorses the Australian Signals Directorate's (ASD) Essential Eight Maturity Model as a good first step towards improved cyber security health. That is the insurance industry's own peak body pointing at the same framework your clients and regulators are likely to reference.

The practical consequence: Essential 8 work and insurance readiness are the same work. The eight strategies are patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. A business that can describe its position against those eight, with evidence, has already answered a large proportion of what a questionnaire is reaching for.

Two of the eight tend to draw the closest reading. Multi-factor authentication reduces the likelihood that a stolen password becomes an intrusion. Tested restores, kept where an attacker with administrative access cannot destroy them, limit what an incident costs once it has started. Likelihood of a loss and size of a loss are the two quantities an underwriter has to price, which is why these two controls get examined line by line rather than ticked. What any policy does in response to a given event remains a matter for that policy's terms and the insurer's assessment.

There is a second-order benefit here, and the Insurance Council names it explicitly. Because insurers examine data and IT processes and may test defences, the assessment itself surfaces weaknesses in a business's data protection and security practices, which the Council frames as an opportunity to improve cyber security health. Put another way, an underwriting questionnaire is a structured review of your environment by someone with no incentive to flatter you. Most businesses pay for those.

When the honest answer on the form is no

The question inSUPPORT hears most at this point: what do we do when the honest answer to a question is no. Write no.

An inaccurate answer on a proposal is a serious matter in its own right and can affect the insurer's position later, which is precisely the situation nobody wants to discover in the middle of an incident. Beyond that, insurers assess and price risk for a living. A 60-person business without every control in place does not surprise them. An honest no, carried by a documented plan and a date, is a substantially stronger position than a yes that would not survive examination.

What genuinely helps when the form is in front of you:

  • Answer against evidence, not intention. If a control is partially deployed, say where it is and where it is not, rather than picking the answer that reads better.
  • Bring dates. A control scheduled for implementation with a named owner is a different risk from one nobody has planned.
  • Keep scope explicit. "Multi-factor authentication on email and remote access, not yet on the legacy finance system" is a real answer. "Yes" is not.
  • Talk to whoever arranged the policy before the deadline rather than after. Questions about the questionnaire itself, what a term means or how a control should be described, belong with your licensed insurance adviser.

inSUPPORT's role in this sits on the technical side: maintaining the agreed controls and being able to evidence them, as part of the 6 Step Cyber Strength System. Where cyber insurance forms part of a client's plan it is arranged through licensed insurance partners and underwritten by the insurer, and questions about wording, eligibility or whether a policy responds are for those licensed parties rather than for an IT provider.

Underwriting, from the owner's side of the desk

Will better controls reduce our premium?

Controls are described by the Insurance Council as a strong focus in reviewing, assessing and pricing risk, so they are a genuine input. What no IT provider can tell you is the effect on your specific premium, because pricing also reflects your sector, your data, your supply chain, your claims history and the insurer's own appetite. Treat improved controls as reducing the risk itself, and leave any pricing effect as a matter for the insurer.

Does the Essential 8 guarantee we can get cover?

No. The Insurance Council endorses the maturity model as a good first step towards improved cyber security health, which is a recommendation about security rather than a statement about underwriting outcomes. Whether cover is offered, on what terms, and at what price is the insurer's assessment.

What does a cyber policy typically cover?

The Insurance Council describes the range of assistance under a cyber policy as including forensic investigation, data restoration, customer notification and rectification such as call centres, and indemnification of penalties imposed by government regulators. Where a breach involves a foreign government actor or criminal gang, it notes coverage may extend to a negotiator's services, legal advice on whether a ransom payment is legal or reportable, and indemnification of a ransom the business decides to pay. All products differ, and what any specific policy covers is set out in that policy's own documents.

Who should we ask about what our policy actually says?

Whoever arranged it. inSUPPORT is not an insurer, insurance broker or underwriter and does not hold an Australian Financial Services Licence, so questions about coverage, eligibility, exclusions or claims belong with your licensed insurance adviser and the insurer. What an IT provider can tell you is what is actually running in your environment, which is the part of the questionnaire that is about facts.

See where you actually stand

inSUPPORT handles the technical side of this for Australian businesses of roughly 30 to 300 users, with more than 1,500 Cyber Strength Audits behind the current approach. If a renewal questionnaire is sitting on your desk and you are not sure which answers are true of your environment, that is a factual question with a checkable answer, and we can check it. A Cyber Strength Audit documents the current position control by control, so the form gets filled in from evidence rather than memory.

Book a Cyber Strength Audit →

Citations

  • "Cyber risk", Insurance Council of Australia. The source of the statements that insurers need to access client data and IT processes and potentially test defences to price risk, that coverage cannot be predicted on prior historical claims experience and incomplete data sets make pricing difficult, the endorsement of ASD's Essential Eight Maturity Model as a good first step for businesses and particularly SMEs, the typical range of cover under a cyber policy, and the ACSC cost figures cited. insurancecouncil.com.au
  • "Small business insurance: cyber insurance" submission, Insurance Council of Australia (2026). The source specifically for the factors weighed beyond controls: the nature of the business and industry sector, the volume and nature of data handled, third-party and supply chain risks, and claims history. insurancecouncil.com.au
  • "Annual Cyber Threat Report 2024-25", Australian Signals Directorate's Australian Cyber Security Centre, as cited by the Insurance Council. Over 42,500 hotline calls answered, and average self-reported cybercrime cost per report of $56,600 for small businesses and $97,200 for medium businesses. cyber.gov.au
  • "ASIC calls for greater organisational vigilance to combat cyber threats" (23-300MR, November 2023). The finding that 44% of cyber pulse survey participants were not managing third-party or supply chain risks. asic.gov.au
Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE