4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Home | Cyber insurance questionnaire

Cyber insurance questionnaire: how to answer every question

An Australian cyber insurance proposal form asks between 40 and 100 questions, and the technical half almost always gets forwarded to the business’s IT provider. This page lists every one of those technical questions, in the wording insurers use, with the answer that satisfies an underwriter and the control you need in place before that answer is true. It is compiled from real Australian proposal forms, not from a generic checklist.

Sydney MSP

Greater Sydney, NSW

Printed insurance proposal form on a desk beside a laptop and a pen

Key facts

  • Australian cyber insurance proposal forms contain 45 distinct questions that only an IT provider can answer accurately.
  • Those 45 questions fall into 12 control areas: identity, endpoint protection, email security, backup, patching, end of life technology, asset security, data protection, policies, awareness training, incident response, and payment fraud.
  • Answering a question inaccurately is a breach of your duty of disclosure, and under Australian insurance law the insurer may reduce or refuse a claim, or cancel the policy.
  • The wording differs between insurers even when the question looks identical, and the thresholds differ with it. Dual authorisation on payments is triggered at $10,000 on some forms and at any amount on others.
  • Most technical questions map onto the Australian Signals Directorate Essential Eight, so a business at Maturity Level 1 has already implemented the majority of what underwriters assess.
  • The single most commonly missing piece of evidence is a dated record of a successful full restore from backup.

Why this page exists

Cyber insurance underwriting in Australia tightened through 2024 and 2025, and the proposal form got longer and more specific as a result. Where a form once asked whether a business had multi-factor authentication, it now asks separately about remote access, web-based email, privileged accounts and cloud resources including backups. Where it once asked whether backups existed, it now asks whether a copy is offline, segregated and inaccessible to the network, whether the backup environment uses immutable technology, and how often a full restore is tested.

That level of detail is the reason the form lands in an IT provider’s inbox. A business owner can answer the questions about revenue, employee numbers and prior claims. Nobody outside the IT function can honestly answer whether every remote entry point enforces multi-factor authentication.

The questions below are compiled from Australian cyber insurance proposal forms current as at September 2026, including both short-form and long-form versions. No insurer is named, because the wording changes when a carrier revises its form and because most businesses do not know which carrier their broker will place them with. Where forms differ on a threshold, the stricter version is given, since a control built to the stricter version answers both.

How to use this list

Work through it once, write the answers down, and keep them. Insurers ask substantially the same questions every year and multiple insurers ask the same questions as each other, so the work is reusable across renewals and across quotes. Treat any question you cannot answer as a finding rather than a form-filling problem: the gap exists whether or not the form asks about it.

One framing point before the list. The answers below describe what is true once a control is in place. They are not a script. Cyber insurance proposal forms carry a duty of disclosure, and an answer given for the sake of a better premium is worse than no cover at all, because it can be relied on to decline a claim at the worst possible moment. Where the honest answer is no, the useful move is to fix the control, not to soften the answer.

The 45 questions, grouped by control area

Each question below is given in the form an underwriter asks it, followed by the short answer. The detailed treatment for each area, including the evidence an underwriter or a claims assessor will ask to see, sits on the linked page for that area.

Identity and access management, 6 questions

  • Is multi-factor authentication required for all remote access to your systems? Yes, with no excluded users, applications or entry points, and with Remote Desktop Protocol not exposed to the internet at all.
  • Is multi-factor authentication required for web-based email? Yes, on every mailbox including shared and service accounts, with legacy authentication protocols disabled so they cannot be used to bypass it.
  • Is multi-factor authentication required for admin and privileged service accounts? Yes, on separate admin identities, with any service account that cannot take multi-factor authentication documented alongside the control that compensates for it.
  • Is multi-factor authentication required for cloud resources, including backups? Yes, and specifically on the backup console, with backup credentials held separately from production administrator credentials.
  • What counts as multi-factor authentication, and does SMS qualify? Something you know plus something you have. SMS meets that definition and is accepted, but it is the weakest available factor and some insurers ask about method separately.
  • Do you have controls on access to online banking and financial platforms? Two-factor authentication on every financial platform login. Some forms accept password rotation or complexity rules instead, both of which are weaker.

Endpoint detection and response, 4 questions

  • Have you deployed an EDR tool that covers 100% of your servers? Yes, on every server including hypervisors and domain controllers, proven against a complete server inventory rather than asserted.
  • Have you deployed an EDR tool that covers 100% of your endpoints? Yes, on every workstation and laptop, with a stated position on personal devices that access company data.
  • Is AI or automated rules-based enforcement enabled? Yes, meaning automatic isolation or remediation rather than alerts nobody reads overnight, or a managed detection and response service providing that cover.
  • If EDR covers less than 90%, what compensating measures are in place? Application allowlisting, an endpoint protection platform, a next generation firewall, intrusion detection or prevention, or web filtering, each documented against the gap it covers.

Email security, 1 question

  • Do you use an email filtering and scanning tool across all email accounts? Yes, on every mailbox with no exclusions, quarantining executables and dangerous attachment types. Native platform tooling is explicitly accepted by some insurers, so a third-party gateway is not always required.

Backup, immutability and restore testing, 4 questions

  • How frequently do you back up critical data and systems? Daily at minimum, evidenced by a job success report rather than a schedule.
  • Do you keep a copy of critical backups offline, segregated from and inaccessible to your network? Yes, on a target that production credentials cannot reach and production malware cannot traverse to.
  • Is your backup environment encrypted, multi-factor protected and using immutable technology? Yes, with an immutability window of at least 14 days and preferably 30, that an administrator cannot shorten.
  • How frequently do you test system restoration by performing a full restoration from backup? Quarterly at minimum, with a dated report of the result and the time it took.

Patching, scanning and assessments, 5 questions

  • Do you have a critical security patch management process, and how are patches applied? A documented cadence with a defined window for critical vulnerabilities, covering operating systems, third-party applications and firmware.
  • Have you had a vulnerability scan conducted in the last 12 months? Yes, internal and external, with the findings tracked through to closure.
  • Have you had a penetration test conducted in the last 12 months? Often no at small business scale, and that is usually the right answer. A vulnerability scan plus an external attack surface review addresses the same underwriting concern at a fraction of the cost.
  • Have you had an external IT audit conducted in the last 12 months? An Essential Eight maturity assessment is what this means for most Australian businesses.
  • Have you had a Payment Card Industry assessment conducted in the last 12 months? Only applicable where card data is stored, processed or transmitted. A compliant payment gateway usually removes the obligation.

End of life technology, 5 questions

  • Do you rely on any operating system, software or hardware that is no longer supported? For most businesses the honest answer is yes. Yes is not a decline. Yes with no compensating controls is.
  • Is any end of life technology internet facing? No. This is the sub-question that decides the outcome.
  • Is your end of life technology segregated from the rest of the network? Yes, on its own network segment with a deny-by-default rule set allowing only the flows the application needs.
  • Has additional support been purchased where available? Extended security updates where the vendor offers them, evidenced by the subscription record.
  • What additional security measures prevent exploitation of end of life technology? A free text answer, and the one place on the form where three well-written sentences change the outcome.

Asset inventory, secure configuration and logging, 4 questions

  • Do you maintain an inventory of all your hardware and software? Yes, generated live from a management platform rather than maintained by hand. Answer this one first, because endpoint coverage and end of life status cannot be proven without it.
  • Have you implemented secure configurations across all hardware and software assets? A documented build standard applied at deployment, covering default credentials, unneeded services, vendor hardening guidance, local storage encryption and logging.
  • Are all logs sent to a centralised logging server? Yes, from endpoints, servers, firewall and identity provider, with a stated retention period. Without logs, an insurer’s forensic investigator cannot establish the scope of an incident, and scope drives the claim.
  • Is any affiliated company’s IT fully separate and independent from yours? Either separate in every respect, or accompanied by a written description of exactly what is shared. Common in group structures, family businesses and franchises.

Data protection and encryption, 4 questions

  • Do you collect, process, hold or store data on behalf of any third party? Usually yes. Most businesses hold client data and answer no by reflex.
  • How many personally identifiable information records do you hold? A defensible count. All categories of information relating to the same individual count as one record, active or inactive, so counting rows instead of people overstates the number and pushes you into a higher band than you belong in.
  • What types of records do you collect, process, hold or store? Customer, payment card, identity, banking, health, biometric or intellectual property. Identity information is the category businesses forget: copies of drivers licences collected at onboarding count.
  • Is sensitive data encrypted at rest, in transit, in backups, on portable devices and with third parties? Yes across all five states. The third-party state cannot be answered from inside your own network and requires a vendor list.

Policies and bring your own device, 2 questions

  • Do you have a privacy policy, cookies policy, and data retention and destruction policy? All three, current and applied. The retention and destruction policy is the one most businesses lack, and it lowers your record count at the next renewal.
  • Do you have a bring your own device policy that ensures data on portable devices is encrypted? A written policy plus the technical enforcement behind it. A policy with no enforcement is not an accurate yes.

Security awareness training, 3 questions

  • How frequently do you provide security awareness training to employees? On a set cadence with completion tracked per person, including new starters. Completion rate matters more than frequency.
  • How frequently do you test employees through simulated phishing campaigns? Quarterly at minimum, with the click rate trend recorded, since the trend is the strongest evidence available in this area.
  • Do you maintain written training materials on social engineering, phishing and cyber fraud, with regular review? Yes, documented and distributed, with a review date. A training platform subscription alone does not answer this.

Incident response and resilience, 5 questions

  • Do you have a disaster recovery plan, business continuity plan and incident response plan, and are they tested annually? All three in place, each with named roles and a dated test record. In place but never tested is a very visible weak answer.
  • Does your incident response plan specifically address ransomware scenarios? Yes, as a named section covering isolation, the payment decision path, who is contacted first, notification obligations and the recovery sequence.
  • Have you had unforeseen downtime to your website or IT network of more than 8 hours? A factual disclosure that includes non-malicious outages: hardware failure, an internet outage, a failed migration.
  • Are critical components, services and supplies available from multiple sources? Named critical suppliers with the substitution position for each. For most businesses the critical dependency is one platform with no substitute inside ten days.
  • Who is the person responsible for cyber security in your business? A named director or manager, with the IT provider recorded alongside as the delivery party. Naming only the IT provider is the wrong answer.

Funds transfer and payment fraud, 2 questions

  • Are new payees and changes to existing payee bank details verified with the payee directly? Verified out of band, by phone or in person, to a number already held on file. Replying to the email to confirm is not verification, because the attacker controls the mailbox.
  • Do transfers require dual authorisation? Two-person authorisation on all transfers, plus cheques over $10,000 and any instruction to disburse assets, funds or investments.

The questions your IT provider cannot answer

Roughly a third of a proposal form is not a technical document, and sending those parts to your IT provider only adds a delay. The business answers these:

  • Australian Business Number, entity type, trading names, subsidiaries and affiliates.
  • Business activities and occupation classification.
  • Estimated revenue for the coming 12 months by territory, and the percentage of revenue from online or e-commerce activity.
  • Employee numbers, and the revenue or employee breakdown by state for stamp duty.
  • Stamp duty and GST exemption status.
  • Whether you work for the defence industry or Federal Government, or hold Defence Industry Security Program membership.
  • Insurance currently held, and whether cover has ever been declined, cancelled or issued with special terms.
  • Prior claims, losses, privacy breaches, regulatory investigations and social engineering incidents over the past five years.
  • Every commercial election: policy limit, excess, indemnity period, retroactive date, and the optional covers.

One part of the prior claims question does come back to IT. Forms typically ask what remediation steps and controls were implemented after a past loss, and invite a report as an attachment. The disclosure is the business’s, but the answer is your IT provider’s.

Where these answers go wrong

Three failure patterns account for most of the trouble. The first is the single exception: multi-factor authentication is enabled everywhere except one legacy application, and the form gets a yes. Underwriters treat one excluded entry point as no multi-factor authentication, because an attacker only needs one.

The second is answering from memory of last year’s form. Thresholds move between insurers and between versions, and the payment authorisation question is the clearest example, with one form triggering at $10,000 and another applying to any transfer at all.

The third is having the control but not the evidence. A claim assessment does not test whether you believed the control was in place; it tests what the logs, reports and policy exports show. A control with no evidence trail behaves, at claim time, much like a control that was never there.

If a questionnaire has landed in your inbox and the technical section is the part holding it up, 4iT works through the whole form against your actual environment, produces the evidence pack the underwriter will ask for, and quotes the remediation for anything that fails. Request a callback and we will work through it with you.

Ready to Talk to a Sydney IT Specialist?

4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details

Book a meeting