Cyber Insurance Readiness
Brisbane & Gold Coast
Insurance forms ask detailed security questions. We check your answers against what is really in place, fix the gaps and give you evidence for every technical answer.
- Questionnaire gap review
- Evidence for every answer
- SMB1001 Gold achieved

Average reported cost of a cybercrime to a medium business in 2024-25 (ASD).
Areas insurers ask about
EDR alert monitoring
Incident response time, business hours
Achieved through CyberCert
Your answers need to be true on the day
Cyber insurance forms are now detailed and technical, and whoever signs is confirming the answers are accurate.
Most problems we see are honest guesses, not lies: a “yes” to MFA when it covers email but not admin accounts, or “tested backups” when nobody has run a restore. If an answer proves wrong when you claim, it can give the insurer grounds to question it. Your broker can explain how your policy treats this.
We’re not insurance brokers and don’t give insurance advice. We make your security answers accurate and your controls real.
- “Yes” to MFA when some accounts don’t have it
- “Antivirus” when the form asks about EDR
- “Tested backups” with no restore on record
- A patching timeframe nobody has checked
- “No local admins” when half the office has admin rights
Eight areas almost every form covers
Wording varies by insurer, but these topics come up on nearly every form we see.
Multi-factor authentication
Is MFA on for all email, remote access, cloud apps and admin accounts? Many forms treat it as a must-have.
Endpoint detection and response
Whether EDR is on every device, and who watches the alerts around the clock.
Patching
How you patch operating systems and apps, and how quickly critical fixes go on once released.
Backups
Where backups are stored, how often they run, whether they are kept separate, and when you last tested a restore.
Email security
Phishing and link filtering, plus SPF, DKIM and DMARC to stop criminals sending email as you.
Admin privileges
Who has administrator access, and whether everyday staff have local admin rights (the right answer is no).
Incident response plan
A written plan for when something goes wrong: who to call, who decides, how you restore and who you must notify.
Security awareness training
Whether staff are trained to spot phishing, and whether simulated phishing tests check it works.
Some forms also ask about firewalls, vulnerability scanning and Microsoft Secure Score. See our cyber security services.
Renewal coming up?
Our free cyber security assessment covers most of what insurers ask, so you know which answers need work before the form is due.
From questionnaire to accurate answers
Start well before renewal. With some controls in place, gaps often close within a few weeks. From scratch, allow four to eight weeks.
Gap review
We check each security question on your insurer’s form, or a typical one, against how your systems are really set up.
Fix the gaps
We close the gaps in order of risk: MFA on every account, EDR on every device, patching, email security, admin rights and backups.
Build your evidence pack
Configuration reports, MFA coverage, backup test results, training records and written policies.
Help with the form
We go through the technical questions with you or your broker, so the signer understands every answer.
What changes when you are insurance-ready
Guessing whether MFA covers every account
A report showing MFA on every account, or the exceptions and why
“We have antivirus”
EDR on every device, with alerts watched 24/7
Backups assumed to work
Test restores done and recorded, with dates
Patching when someone remembers
Scheduled patching, with critical fixes applied quickly
Most staff running as administrators
Admin rights removed, software requests approved in real time
No plan for an incident
A written incident response plan your team has seen
A stronger application can help, but approval, premiums and payouts are always the insurer’s decision.
Your IT team, not your broker
We handle the technical side. We don’t sell policies, compare insurers or advise on cover, exclusions or premiums. That is your broker’s job.
We make the security section of your application accurate and easy to support. With your permission, we’ll talk to your broker directly.

- MFA coverage for every user and admin account
- EDR deployment and monitoring summary
- Patching and vulnerability scan reports
- Backup schedule and test restore records
- Email security settings (SPF, DKIM, DMARC)
- Incident response plan, policies and training records
Back your answers with SMB1001 or the Essential Eight
A questionnaire is self-declared. An SMB1001 certificate, issued through CyberCert, shows your controls meet a recognised Australian standard, and many of them are the ones insurers ask about.
A documented Essential Eight maturity level does a similar job for the technical questions. As a CyberCert Certification Partner, we take clients through SMB1001 Bronze, Silver and Gold.

Evidence from a team that has done it
We achieved SMB1001 Gold through CyberCert, so we know what it takes to document controls to a recognised standard. Your evidence pack gets the same care.

SMB1001 Gold

Certification Partner

Partner and Cloud Solution Provider (CSP)

Google Cloud Partner
Cyber insurance readiness: common questions
What do cyber insurers require from small businesses?
Most questionnaires ask about multi-factor authentication, EDR, patching, backups, email security, admin privileges, an incident response plan and staff training. Requirements differ between insurers and change over time, so we review your own form and show where answers need work.
Can you help us fill in our cyber insurance application?
Yes, the technical security sections. We explain each question, check the answer against your real setup and supply evidence. For managed clients we can usually draft those answers for you to review. You still sign the form, and your broker handles questions about cover.
We were declined for cyber insurance. Can you help?
Often, yes. Ask your broker which controls were the concern. If it was MFA, EDR, backups or similar, we can put them in place, document them and help you prepare an accurate application for next time. The decision is always the insurer’s.
Will better security lower our cyber insurance premium?
It may help, because insurers price risk and documented controls show lower risk. But premiums depend on many factors, so we can’t promise a lower one. We can make sure your answers are accurate and backed by evidence.
What is Microsoft Secure Score and why do insurers ask for it?
Secure Score measures how your Microsoft 365 setup compares with Microsoft’s security recommendations, and some insurers ask for it. We manage your Microsoft 365 security settings, can tell you your current score and explain which changes would raise it.
Is cyber insurance worth it for a small business?
That’s a decision for you and your broker. For context, ASD’s Annual Cyber Threat Report 2024-25 put the average self-reported cost of a cybercrime at $56,600 for a small business. Insurance helps with costs afterwards but doesn’t stop an attack, so the controls matter either way.
Strengthen your application
Essential Eight
Measure your controls against ASD’s eight strategies.
SMB1001 certification
A recognised certificate to back up your answers.
Data backup and recovery
Monitored backups with test restores on record.
Business continuity planning
A tested plan for downtime.
Accounting and finance IT
Security for firms that hold client financial data.
Get ready before your next renewal
Tell us when your policy renews and send the questionnaire if you have it. We’ll show you which answers need work and what fixing them involves.
- Your answers checked against your real setup
- A plan to close the gaps before the form is due
- An evidence pack for the technical answers
Prefer to talk? Call 1300 619 750, Monday to Friday.
Tell us what you need. We’ll get back to you within one business day.
