Home› Insights› Security
Security

Cyber insurance in 2026: what insurers now require

Adam Dodds
Adam Dodds
21 September 2026 · 6 min read
Cyber insurance in 2026: what insurers now require

A few years ago, cyber insurance was easy to buy. You ticked a box saying you had antivirus, paid the premium, and that was that. In 2026 it is a different product. The application form has become a technical questionnaire, the policy comes with conditions about what you must have in place, and insurers are far more willing to decline a claim when the answers on that form turn out not to be true. Here is what Australian insurers are now asking for, what happens if you cannot show it, and how to get there without turning your business upside down.

Why the rules changed

Insurers lost a great deal of money on cyber policies between about 2019 and 2022. Ransomware payouts, business interruption claims and the cost of forensic investigations ran far ahead of the premiums coming in. Their response was predictable: raise prices, lower the amount they will pay for ransomware specifically, and demand that policyholders actually do the basics before cover starts.

The result is that cyber insurance now works more like insuring a building with a sprinkler requirement. The insurer is not just pricing the risk, they are telling you what the minimum standard is. If the sprinklers were never fitted, the fire claim gets a very hard look.

The controls insurers now expect

The wording varies between insurers, but the list has settled into something quite consistent.

Multi-factor authentication, everywhere that matters. This is the first question on nearly every form, and “we have it on email” is no longer enough. Insurers want it on all accounts with administrative rights, on remote access of any kind (VPN, remote desktop), on cloud admin consoles, and increasingly on every user account for every cloud application. If a staff member can sign in to something that holds company data with just a password, expect to be asked about it.

Endpoint detection and response on every device. Traditional antivirus looks for known bad files. Endpoint detection and response (usually shortened to EDR) watches for suspicious behaviour and can isolate a machine the moment something looks wrong. Insurers now expect it on every computer and server, not just some. If you are on Microsoft 365 Business Premium, you already own one (Defender for Business); the question is whether it is switched on and configured on everything.

Backups that a criminal cannot reach. The thing that turns a ransomware incident into a catastrophe is finding out the backups were encrypted too. Insurers want backups that are kept separate from your main systems, that cannot be deleted or altered using the same accounts an attacker might steal, and that you have actually tested restoring from. “We have backups” is not the question; “when did you last restore a file from them?” is.

Patching with a deadline. Not just “we install updates”, but a stated timeframe for critical security fixes, typically within a couple of weeks of release, and some form of evidence that it is happening.

Staff awareness training. Because most incidents still start with a person clicking something. Insurers want to see regular training and, often, simulated phishing tests.

Control over privileged accounts. Who has administrator rights, why, and whether they use a separate account for admin work rather than their everyday login.

A written incident response plan. What you will do, who you will call and in what order, if something goes wrong. It does not have to be long, but it has to exist, and someone has to know where it is. We covered what goes into one in our incident response plan guide.

What happens if you cannot show these

Three things, roughly in order of how often we see them.

First, you pay more. Businesses that cannot demonstrate the basics are being quoted higher premiums, or being offered cover with a large excess.

Second, your ransomware cover is capped. It is now common for a policy to limit ransomware-related payouts to a fraction of the overall policy limit, particularly for smaller businesses without strong controls. The headline figure on the policy can be very different from the figure that applies to the incident you are most likely to have.

Third, and this is the one that catches people out, a claim can be declined or reduced because the application form said something that was not true. If the form says every account has MFA and the investigation finds the breached account did not, the insurer has grounds to walk away. The forms are usually signed by a director, and insurers increasingly treat them as warranties rather than estimates. It is worth having whoever looks after your IT fill in that form with you, line by line, rather than ticking what you think is probably right.

The good news: the list is the same list

If the controls above sound familiar, it is because they are essentially the Essential Eight and the lower tiers of SMB1001, written in an insurer’s language. There is no separate “insurance security” to build. A business that is aligned to the Essential Eight, or certified against SMB1001, can answer nearly every question on a 2026 cyber insurance form with a yes, and point to evidence.

That is also why we think SMB1001 certification is becoming a sensible step for businesses that want insurance to be straightforward. A current certificate is a clear, independent-looking statement of what you have in place. Several of our clients have found that the renewal conversation gets much shorter once they can attach one.

How to get there without a huge project

For a business on Microsoft 365 Business Premium, most of this is configuration rather than purchase:

  • MFA and the rules about which devices can reach company data come from the conditional access features in your licence.
  • EDR is Defender for Business, included in Business Premium, and it needs to be deployed to every device and set to isolate machines automatically.
  • Email protection against fake invoices and impersonation is in the licence too.
  • Backups usually need a dedicated product that keeps copies outside Microsoft 365 and outside your own network, with the ability to lock them so they cannot be altered.
  • Patching, training, admin account hygiene and the incident response plan are process and habit, which is exactly what a managed IT and security service is for.

If you want to see where you stand before renewal, we have written separately about the five changes that make the biggest difference to your premium, and the realistic picture of what ransomware looks like in 2026 explains why insurers care so much about backups in particular.

Before your next renewal

Pull out last year’s application form and read the answers again, honestly. If any of them have drifted from the truth since you signed it, that is the place to start, because it is the place a claim would fail. Then get your IT provider to go through the controls above with you and show you evidence for each one, not just a reassurance.

If you would like a hand with that, we are happy to review your renewal questionnaire alongside your current setup and tell you plainly where the gaps are. Get in touch.

Adam Dodds
Adam Dodds

Adam leads the Itopia team in Brisbane, helping professional-services firms get secure, productive and confident with their technology, in plain English.

Keep reading

Related insights

Security
4 min read

Ransomware in 2026: what's changed and what stops it

Read more →
Security
7 min read

Tax-time scams: how accounting firms get targeted

Read more →
Security
7 min read

Passkeys explained: the beginning of the end for passwords

Read more →

Want IT advice tailored to your business?

Talk to a local Brisbane technician, no jargon, no obligation.

Get a Quote Call 07 3063 2211