4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Home | Cyber insurance questionnaire | data and encryption

Cyber insurance data and encryption questions: how to answer them

Australian cyber insurance proposal forms ask four questions about the data you hold, and the answers directly affect what you pay. Insurers want to know whether you hold data for third parties, how many personally identifiable information records you have, which categories they fall into, and whether the data is encrypted in five separate states. The record count question is the one businesses most often get wrong, and they usually get it wrong in the direction that costs them money.

Sydney MSP

Greater Sydney, NSW

Filing cabinet drawer open beside a laptop on a desk

Key facts

  • Insurers ask four data questions: third-party data, record count, record types, and encryption across five states.
  • Proposal forms specify that all categories of information relating to the same individual count as a single unique record, whether that individual is active or inactive.
  • Counting database rows instead of people overstates the number and can push a business into a higher band than it belongs in.
  • Inactive records still count, so archived and historical data does not fall out of the calculation.
  • Record types are asked as seven categories, and identity information is the one businesses most often forget they hold.
  • Encryption is asked across five states: at rest, in transit, backed up, on portable devices, and stored with third parties. The last cannot be answered from inside your own network.

Why insurers ask about this in so much detail

Data is what a cyber policy pays out on. Notification costs, credit monitoring, regulatory response and third-party claims all scale with the number of individuals affected and the sensitivity of what was exposed. The record count and record type questions are the closest thing on the form to a direct measure of the insurer’s maximum exposure, which is why they are asked with banded precision rather than in general terms.

The encryption question serves a different purpose. Encrypted data that is stolen may not trigger a notifiable breach at all, depending on the circumstances, because the information may not be accessible to whoever took it. So encryption does not only reduce the chance of a loss, it can reduce whether an incident becomes a reportable event, and that is worth more to an insurer than most technical controls on the form.

The questions below come from Australian cyber insurance proposal forms current as at September 2026. No insurer is named. The full set of 45 technical questions is on the cyber insurance questionnaire guide.

The data protection questions insurers ask

Do you collect, process, hold or store data on behalf of any third party?

Australian proposal forms open the data section with this as a yes or no. It is answered no by reflex far more often than it should be, because the four verbs are broad and most businesses do hold data belonging to somebody else.

Accountants hold client financial records. Recruiters hold candidate identity documents. Anyone running a platform on behalf of customers holds their customers’ customer data. Anyone doing outsourced processing, bookkeeping, payroll or claims handling is squarely inside this question. The test is not whether you own the data, it is whether it is in your possession.

The evidence is a data inventory or a data flow map naming the third parties whose data you hold and where it sits. Answering yes does increase the assessed exposure. It is also a disclosure obligation rather than a negotiation, and an insurer that discovers third-party data during a claim it did not know about at underwriting has a simple argument available to it.

How many personally identifiable information records do you hold?

Some Australian forms ask for a band, running from under 25,000 up to over 5,000,000. Others ask for a single figure. Either way, this is the question where the counting method matters more than the count.

Proposal forms state that all categories of personally identifiable information relating to the same individual, whether active or inactive, count as one unique record. Read that carefully, because it cuts both ways. A person who appears in your CRM, your accounting system, your email archive and your file server is one record, not four. That correction usually reduces the number substantially, and businesses routinely over-report by counting rows across systems. At the same time, inactive means inactive: a customer who last transacted in 2018 and is still in the database is a live record for this purpose, so archived data does not drop out.

What you need is a defensible method: deduplicate individuals across systems, include historical and archived records, and write the method down so the same figure can be reproduced at the next renewal. The evidence is the count together with the method. This is also the question that gives a data retention and destruction policy a direct commercial payoff, because data you have properly destroyed is data you no longer count.

What types of records do you collect, process, hold or store?

Proposal forms ask this as seven categories, each answered separately: customer information such as name, address, email and phone number; payment card information; identity information such as drivers licence, tax file number or passport number; banking or financial information; medical or healthcare information; biometric data; and trade secrets or intellectual property.

Identity information is the category businesses most often miss. Very few Australian SMEs think of themselves as holding identity documents, and a large share of them do: drivers licence scans collected to verify a new client, tax file numbers in payroll, passport copies for a visa or a background check, all sitting in a mailbox or a shared folder somebody set up years ago. The category is triggered by holding the document, not by having a system designed to hold it.

The evidence is a data inventory mapped to those seven categories. Keep the payment card answer consistent with the Payment Card Industry assessment question elsewhere on the form, because claiming no card data and then a PCI assessment, or the reverse, invites a follow-up.

Is personally identifiable and sensitive data encrypted at rest, in transit, in backups, on portable devices and with third parties?

Australian proposal forms ask this as five separate answers rather than one, and the five are not equally easy. At rest, in transit, in backups and on portable devices are all answerable from inside your own environment. The fifth is not.

What needs to be in place is disk encryption on every endpoint and server, encryption in transit through TLS on anything carrying data across a network, encryption on the backup data itself, encryption enforced by policy on portable devices including removable media, and for third parties either a contractual commitment or the vendor’s own published position. That last one requires a list of every platform holding your data, which most businesses do not have, and building it is the real work in this question.

The evidence is an encryption compliance report per device, the backup encryption setting, the device policy enforcing portable encryption, and for third parties the vendor attestations or security documentation. Answer the third-party state honestly: a yes that rests on an assumption about what a supplier does is the weakest claim in this section, and it is the one most likely to be tested if that supplier is the one that gets breached.

The evidence to assemble before the form arrives

  • A data inventory or data flow map, naming third-party data and where it sits.
  • A written record count method, with the deduplicated figure it produces.
  • The inventory mapped to the seven record categories the forms use.
  • An encryption compliance report covering endpoints and servers.
  • A vendor list covering every platform that holds your data, with each vendor’s encryption position.

Under the Notifiable Data Breaches scheme, businesses covered by the Privacy Act 1988 have obligations when a breach is likely to result in serious harm, and the categories above are what determine whether that threshold is met. The Office of the Australian Information Commissioner publishes the scheme guidance at oaic.gov.au. The related questions on the form are the policies question, which covers data retention and destruction, and the encryption elements of the backup questions.

One thing not to do

Do not guess the record count upward to be safe. Over-reporting is not the cautious option, it is the expensive one: the bands on these forms feed directly into pricing and into the limits an underwriter is willing to offer, and a business that counts rows across four systems instead of counting people can land two bands above where it belongs. Deduplicate properly, write the method down, and keep it so the figure is consistent and defensible at every renewal.

If a questionnaire has landed and the data section is the part nobody can answer with confidence, 4iT builds the inventory, produces a defensible record count with the method written down, and assembles the encryption evidence the underwriter will ask for. Request a callback and we will work through it with you.

Ready to Talk to a Sydney IT Specialist?

4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details

Book a meeting