CyberSmart360

A business professional reviews a cyber insurance proposal and risk assessment form in an office.

The renewal pack arrives and the proposal form has grown. It is no longer name, turnover and limit. It now runs to pages of security questions: is multi-factor authentication enforced, are backups segregated, how quickly are critical patches applied, do you use software the vendor no longer supports.

Those questions are not idle. The answers go into the underwriting decision, and they stay on the file afterwards. This article covers why they are being asked, how they line up with the ACSC Essential Eight, and — the part most business owners underestimate — what an inaccurate answer can mean when you claim. If the framework itself is unfamiliar, our guide to what the Essential Eight is covers it quickly.

This is general information, not legal or financial advice, and it is not insurance advice. Cyber policies differ substantially between insurers and between years. Talk to your broker about your own policy and proposal form.

Why insurers ask these questions

Two reasons, and they work differently.

The first is underwriting. An insurer is deciding whether to accept the risk and on what terms, and a small number of controls do most of the work in preventing or limiting the losses cyber policies actually pay: business email compromise, funds transfer fraud, ransomware and the interruption that follows. Questions about multi-factor authentication, backups and patching are questions about how likely and how expensive a claim is.

The second is the record. Whatever you write on a proposal form becomes part of the information the insurer relied on. If a claim is made, that document is read again, closely, at a point when your position is weaker than it is today.

No insurer is named here and none of this article says any particular insurer requires the Essential Eight. Proposal forms differ, and the framework is not usually referenced by name. What has happened is convergence: insurers arrived at a similar short list of controls because the same few controls prevent the same few losses, and that list overlaps heavily with what ASD published. The Essential Eight is not an insurance standard, but it is a good map of the territory the form covers.

Where proposal-form questions line up with the Essential Eight

Typical proposal form questionEssential Eight strategyNote
Is multi-factor authentication enforced for email, remote access, administrative accounts and cloud services?Multi-factor authenticationAt Maturity Level 1 the requirement covers your own and third-party online services holding sensitive data, and customer-facing services holding sensitive customer data. Note the form usually asks about remote access and administrative accounts specifically — at Level 1 the Essential Eight covers online services rather than logging on to systems, so answer the form’s question, not the framework’s.
Are backups segregated, offline or otherwise protected from your network?Regular backupsMaturity Level 1 requires backups retained in a secure and resilient manner, with unprivileged user accounts unable to modify or delete them or access other accounts’ backups.
Are backups tested, and when did you last restore from them?Regular backupsMaturity Level 1 requires restoration to a common point in time to be tested as part of disaster recovery exercises. A date is the answer; “yes” is not.
How quickly are critical security patches applied?Patch applications; Patch operating systemsMaturity Level 1 uses 48 hours for internet-facing systems and online services where the vendor rates the vulnerability critical or a working exploit exists, two weeks for common everyday software, and one month for workstation operating systems.
Do you use any software or operating systems no longer supported by the vendor?Patch applications; Patch operating systemsMaturity Level 1 requires unsupported software to be removed and unsupported operating systems to be replaced. This is a question with only one safe answer, and it is frequently answered wrongly because nobody has checked the machine in the storeroom.
How many staff hold administrator access, and are administrator accounts separate from daily-use accounts?Restrict administrative privilegesMaturity Level 1 requires privileged users to hold a dedicated account used solely for privileged duties, kept off internet, email and web services.
Can staff install software on company devices?Application controlMaturity Level 1 requires application control on workstations, restricting execution to an organisation-approved set, including in the folders where downloads and email attachments land.

Just as usefully, here is what appears on proposal forms and is not in the Essential Eight at all: endpoint detection and response tooling, email filtering, staff security awareness training, phishing simulation, network segmentation, encryption of data at rest, a documented incident response plan, and a verified callback procedure for changes to payment details. Some of those appear at Maturity Level 2 or 3 rather than Level 1; several are simply outside the framework.

That matters for two reasons. Reaching Maturity Level 1 will not answer every question on the form. And the last item on that list — verified callback before any change to bank details — deserves attention regardless of the framework, because policies frequently treat social engineering and funds transfer fraud differently from other cover, sometimes with sub-limits or specific conditions. Ask your broker how your policy handles it.

The three that dominate

Multi-factor authentication. The critical word on the form is almost always “enforced”. Enabled and available is a different answer from required for every user, and the gap between them is where most inaccurate answers live. Read the scope carefully too: forms typically ask separately about email, remote access, administrative accounts and cloud services, and a business can honestly be at yes for one and no for another.

Backups. Forms ask three things: are they protected from the network that would be encrypted, when did you last test a restore, and how far back can you go. The Essential Eight wording maps almost directly: backups of data, applications and settings, synchronised to a common point in time, retained securely and resiliently, restoration tested as part of disaster recovery exercises, and out of reach of everyday accounts. If you can answer the Essential Eight requirement, you can answer the form.

Patching. Forms ask for a timeframe for critical patches and whether unsupported software is in use. Businesses tend to answer the first optimistically and the second without checking. Both are verifiable after a loss. A forensic investigator will establish what version was running on the machine the intrusion came through, and that is a fact rather than an impression.

What an inaccurate answer actually means

This is worth understanding properly, because the reality is neither as harmless as “it is just a form” nor as absolute as “your claim will be denied”.

Insurance in Australia is governed by the Insurance Contracts Act 1984 (Cth). Since October 2021, a consumer insurance contract — one obtained wholly or predominantly for personal, domestic or household purposes — carries a duty to take reasonable care not to make a misrepresentation. A business cyber policy is generally not a consumer insurance contract, which means the traditional duty of disclosure under section 21 continues to apply, alongside the general prohibition on misrepresentation. That duty requires disclosure of matters known to you that are relevant to the insurer’s decision to accept the risk and on what terms, and what a reasonable person in the circumstances could be expected to know. The insurer must give you written notice of the duty before the contract is entered into.

The remedies are set out in section 28, and the structure is proportionate rather than all-or-nothing. An insurer has no remedy if it would have entered the contract on the same terms regardless. If the failure was fraudulent, the insurer may avoid the contract. Otherwise, the insurer’s liability for the claim is reduced to the amount that would put it in the position it would have been in had the failure not occurred.

Read that last sentence again with a proposal form in front of you. If you answered yes to enforced multi-factor authentication, the insurer priced and accepted on that basis, and the intrusion came through an account without it, the argument at claim time is about what the insurer would have done had it known. You will be having that argument after a loss, under pressure, with a forensic report on the table.

Two practical consequences. The duty arises again on renewal, extension or variation, so an answer that was true three years ago is not automatically true now, and controls drift. And “I do not know” or a qualified answer is a legitimate response to a proposal form question. Brokers deal with partial and qualified answers constantly; that is much of what they are for. A guess presented as a fact is the thing to avoid.

None of this is legal advice, and how the Act applies to any particular policy and set of facts is a question for your broker and, if it matters enough, a lawyer.

Having a control, and being able to show it

There are three states, and businesses routinely confuse the first with the third.

  • You believe you have the control. Somebody set it up, probably correctly, at some point.
  • You have the control. It is configured, it applies to everyone, and it has not been quietly excepted for a legacy account, a service mailbox or the director who found it annoying.
  • You can show you have the control. There is a configuration export, a policy screenshot, a report or a dated assessment that demonstrates it to somebody who is not you, after an incident.

The classic failure is multi-factor authentication enforced for all users except a handful of exceptions created for legitimate reasons and never revisited, one of which becomes the entry point. On the form, the business answered yes in good faith. In the forensic report, the exception is the first thing found.

Evidence is not exotic. A configuration or policy export showing enforcement and any exceptions. The date and result of your last test restore. A list of who holds administrative access. A patch report showing what is genuinely current. A dated assessment recording your position across all eight strategies. Gathering these before the form is completed changes the answers you give, usually on one or two questions, which is exactly the point.

Before you complete the proposal form

  • Check enforcement rather than assuming it. Look at the actual setting, and look for exceptions.
  • Find out whether anything is running an operating system or application the vendor no longer supports. This is a single question with a checkable answer and it appears on almost every form.
  • Restore something from backup and record the date and the result.
  • List who holds administrator access and whether those accounts are separate from daily-use accounts.
  • Where an answer is partial, write the partial answer and let your broker present it. Do not round up.
  • Keep the working. If you are asked to substantiate an answer in two years, you want the assessment that supported it, with a date on it.

Where CyberSmart360 fits

The purpose here is accuracy, not premium. We make no claim about what an assessment does to your premium. That depends on the insurer, the policy and your own circumstances, and anyone who tells you otherwise without seeing your renewal is guessing. What an assessment does is give you an accurate picture before you commit answers to a form. CyberSmart360 walks you through 186 controls across the Essential Eight and the ACSC Security Principles, translated for 44 industries, and produces a compliance score, a gap report ranked by priority and a costed 12-month remediation plan. The feature that matters most here is evidence tracking: a record against each control of what you have and where the proof sits, so the answers you give your broker are supported rather than remembered. Our Maturity Level 1 guide sets out what it measures against.

Frequently asked questions

Do insurers require the Essential Eight?

Proposal forms rarely reference it by name, and requirements differ between insurers and between years. What is common is that the controls asked about overlap heavily with the Essential Eight, because both are aimed at the same small set of losses. Your broker can tell you what your particular insurer is asking for.

Will reaching Maturity Level 1 answer everything on the form?

No. Proposal forms commonly ask about endpoint detection and response, email filtering, staff training, incident response planning and payment verification procedures, several of which sit at higher maturity levels or outside the framework entirely. Level 1 covers a good share of the form, not all of it.

What if I answered something wrongly last year?

Raise it with your broker rather than leaving it. The duty of disclosure arises again at renewal, so a renewal is the natural point to correct the record, and correcting it before a claim is a materially better position than after one. How the Insurance Contracts Act applies to your situation is a question for your broker and, if the amount at stake justifies it, a lawyer.

Can I answer “partially”?

Yes, and it is usually the right answer. Multi-factor authentication enforced on email and cloud storage but not yet on remote access is a real position, and brokers present positions like that every day. A qualified answer with a date attached is far safer than a yes you cannot substantiate.

Does having cyber insurance mean we can skip the controls?

No, and the direction of travel is the opposite: the controls are increasingly what determines whether cover is offered and on what terms. Insurance also does not restore your data, resume your operations or repair the client relationships. It addresses the financial consequences after those things have already happened.

Get the picture before you fill in the form

The worst time to discover the real state of your controls is after a loss, when the answers on a proposal form are being compared against a forensic report. A dated assessment before the renewal costs an afternoon and makes every answer on the form defensible. The free 7-day trial at cybersmart360.com needs no credit card and covers one user and one assessment. Detail is on the plans and pricing page. Then talk to your broker. That part we cannot do for you.

This article is general information about a cyber security framework and the questions commonly appearing on cyber insurance proposal forms. It is not legal, financial or insurance advice and does not take account of your objectives, situation or needs.

Related Post

Do You Need a Consultant for the Essential Eight?

Sometimes yes. The honest answer depends on your environment, not on which option you found…

The Essential Eight for Builders and Construction Firms

The tender pack lands, and somewhere behind the insurances, the safety management plan and the…

Essential Eight Requirements in Government Tenders: How to Answer Honestly

It is usually about two-thirds of the way through the response schedule, between insurances and…