Cyber insurance readiness · Brisbane and Gold Coast

Cyber Insurance Readiness
Brisbane & Gold Coast

Insurance forms ask detailed security questions. We check your answers against what is really in place, fix the gaps and give you evidence for every technical answer.

  • Questionnaire gap review
  • Evidence for every answer
  • SMB1001 Gold achieved
SEQ IT helpdesk technician on a support call
$97,200

Average reported cost of a cybercrime to a medium business in 2024-25 (ASD).

8

Areas insurers ask about

24/7

EDR alert monitoring

1 hour

Incident response time, business hours

SMB1001 Gold

Achieved through CyberCert

Why accuracy matters

Your answers need to be true on the day

Cyber insurance forms are now detailed and technical, and whoever signs is confirming the answers are accurate.

Most problems we see are honest guesses, not lies: a “yes” to MFA when it covers email but not admin accounts, or “tested backups” when nobody has run a restore. If an answer proves wrong when you claim, it can give the insurer grounds to question it. Your broker can explain how your policy treats this.

We’re not insurance brokers and don’t give insurance advice. We make your security answers accurate and your controls real.

Answers that cause trouble later
  • “Yes” to MFA when some accounts don’t have it
  • “Antivirus” when the form asks about EDR
  • “Tested backups” with no restore on record
  • A patching timeframe nobody has checked
  • “No local admins” when half the office has admin rights
What insurers ask

Eight areas almost every form covers

Wording varies by insurer, but these topics come up on nearly every form we see.

Accounts

Multi-factor authentication

Is MFA on for all email, remote access, cloud apps and admin accounts? Many forms treat it as a must-have.

Devices

Endpoint detection and response

Whether EDR is on every device, and who watches the alerts around the clock.

Weaknesses

Patching

How you patch operating systems and apps, and how quickly critical fixes go on once released.

Recovery

Backups

Where backups are stored, how often they run, whether they are kept separate, and when you last tested a restore.

Email

Email security

Phishing and link filtering, plus SPF, DKIM and DMARC to stop criminals sending email as you.

Access

Admin privileges

Who has administrator access, and whether everyday staff have local admin rights (the right answer is no).

Planning

Incident response plan

A written plan for when something goes wrong: who to call, who decides, how you restore and who you must notify.

People

Security awareness training

Whether staff are trained to spot phishing, and whether simulated phishing tests check it works.

Renewal coming up?

Our free cyber security assessment covers most of what insurers ask, so you know which answers need work before the form is due.

How we help

From questionnaire to accurate answers

Start well before renewal. With some controls in place, gaps often close within a few weeks. From scratch, allow four to eight weeks.

01
Check

Gap review

We check each security question on your insurer’s form, or a typical one, against how your systems are really set up.

02
Close

Fix the gaps

We close the gaps in order of risk: MFA on every account, EDR on every device, patching, email security, admin rights and backups.

03
Prove

Build your evidence pack

Configuration reports, MFA coverage, backup test results, training records and written policies.

04
Answer

Help with the form

We go through the technical questions with you or your broker, so the signer understands every answer.

Before and after

What changes when you are insurance-ready

Before
After a readiness review with SEQ IT

Guessing whether MFA covers every account

A report showing MFA on every account, or the exceptions and why

“We have antivirus”

EDR on every device, with alerts watched 24/7

Backups assumed to work

Test restores done and recorded, with dates

Patching when someone remembers

Scheduled patching, with critical fixes applied quickly

Most staff running as administrators

Admin rights removed, software requests approved in real time

No plan for an incident

A written incident response plan your team has seen

A stronger application can help, but approval, premiums and payouts are always the insurer’s decision.

Where we fit

Your IT team, not your broker

We handle the technical side. We don’t sell policies, compare insurers or advise on cover, exclusions or premiums. That is your broker’s job.

We make the security section of your application accurate and easy to support. With your permission, we’ll talk to your broker directly.

SEQ IT technician helping a client with her laptop at her desk
Your evidence pack
  • MFA coverage for every user and admin account
  • EDR deployment and monitoring summary
  • Patching and vulnerability scan reports
  • Backup schedule and test restore records
  • Email security settings (SPF, DKIM, DMARC)
  • Incident response plan, policies and training records
Documented proof

Back your answers with SMB1001 or the Essential Eight

A questionnaire is self-declared. An SMB1001 certificate, issued through CyberCert, shows your controls meet a recognised Australian standard, and many of them are the ones insurers ask about.

A documented Essential Eight maturity level does a similar job for the technical questions. As a CyberCert Certification Partner, we take clients through SMB1001 Bronze, Silver and Gold.

SEQ IT technician reviewing a laptop setup with a client
Our standard

Evidence from a team that has done it

We achieved SMB1001 Gold through CyberCert, so we know what it takes to document controls to a recognised standard. Your evidence pack gets the same care.

SMB1001 Gold certification badge

SMB1001 Gold

CyberCert logo

Certification Partner

Microsoft logo

Partner and Cloud Solution Provider (CSP)

Google Cloud logo

Google Cloud Partner

FAQ

Cyber insurance readiness: common questions

Most questionnaires ask about multi-factor authentication, EDR, patching, backups, email security, admin privileges, an incident response plan and staff training. Requirements differ between insurers and change over time, so we review your own form and show where answers need work.

Yes, the technical security sections. We explain each question, check the answer against your real setup and supply evidence. For managed clients we can usually draft those answers for you to review. You still sign the form, and your broker handles questions about cover.

Often, yes. Ask your broker which controls were the concern. If it was MFA, EDR, backups or similar, we can put them in place, document them and help you prepare an accurate application for next time. The decision is always the insurer’s.

It may help, because insurers price risk and documented controls show lower risk. But premiums depend on many factors, so we can’t promise a lower one. We can make sure your answers are accurate and backed by evidence.

Secure Score measures how your Microsoft 365 setup compares with Microsoft’s security recommendations, and some insurers ask for it. We manage your Microsoft 365 security settings, can tell you your current score and explain which changes would raise it.

That’s a decision for you and your broker. For context, ASD’s Annual Cyber Threat Report 2024-25 put the average self-reported cost of a cybercrime at $56,600 for a small business. Insurance helps with costs afterwards but doesn’t stop an attack, so the controls matter either way.

Get insurance-ready

Get ready before your next renewal

Tell us when your policy renews and send the questionnaire if you have it. We’ll show you which answers need work and what fixing them involves.

  • Your answers checked against your real setup
  • A plan to close the gaps before the form is due
  • An evidence pack for the technical answers

Prefer to talk? Call 1300 619 750, Monday to Friday.

Talk to us

Tell us what you need. We’ll get back to you within one business day.