4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Home | Cyber insurance questionnaire | end of life technology

Cyber insurance end of life technology questions: how to answer them

Australian cyber insurance proposal forms ask whether you rely on any operating system, software or hardware that is no longer supported, and then ask four follow-up questions if you say yes. For most Australian businesses the honest answer is yes, and yes is not a decline. Yes with nothing protecting it usually is. The four follow-ups are where the outcome is decided, and one of them is a free text box where a well-written answer changes what the underwriter does.

Sydney MSP

Greater Sydney, NSW

Older desktop computer and industrial control panel in a workshop

Key facts

  • Insurers ask one question about end of life technology and four follow-ups: whether it is internet facing, whether it is segregated from the rest of the network, whether extended support has been purchased, and what other measures prevent exploitation.
  • Proposal forms define end of life as the point where a product is no longer developed, maintained or supported by the manufacturer.
  • Answering yes is common and acceptable. Unsupported and internet facing is close to an automatic decline.
  • Network segmentation is the cheapest control in this entire area, usually a network segment and a handful of firewall rules, and it converts a poor answer into an acceptable one.
  • The compensating measures question is free text, which makes it the one place on the form where three well-written sentences directly affect the result.
  • The usual culprits in Australian SMEs are a line-of-business application that will not run on a current operating system, and a computer attached to a piece of equipment that the equipment vendor will not certify on anything newer.

Why insurers ask about this in so much detail

An unsupported system will never be patched again, so every vulnerability found in it from its end of support date onward stays open permanently. That makes it a different category of risk from a system that is merely behind on updates. An underwriter cannot price “we will fix it eventually” on something the vendor has stopped fixing.

What insurers have learned, though, is that refusing to cover any business with an unsupported system would exclude a large share of the market, particularly in manufacturing, healthcare, professional services with legacy practice software, and anywhere with equipment that outlasts the computer driving it. So the questions moved from whether unsupported technology exists to whether it is contained. That is a much more answerable question, and it is one an IT provider can change the answer to.

The questions below come from Australian cyber insurance proposal forms current as at September 2026. No insurer is named. The full set of 45 technical questions is on the cyber insurance questionnaire guide.

The end of life technology questions insurers ask

Do you rely on any operating system, software or hardware that is no longer supported or is considered end of life by the manufacturer?

Australian proposal forms ask this as a yes or no, with the four follow-up questions appearing only if the answer is yes. The temptation to answer no is strong and it is where the trouble starts, because the question covers hardware and software as well as operating systems, and it covers anything the manufacturer has stopped maintaining rather than only things that have stopped working.

To answer accurately you need a current inventory with vendor support status recorded against each item, so the answer is a fact rather than a recollection. Compiling that list nearly always turns up more than expected: an old switch, a network video recorder, a wireless controller, a database engine two major versions behind, a payroll application the vendor stopped shipping updates for.

The evidence is the asset list with vendor support end dates. Answering yes and then answering the follow-ups well is a much stronger position than a no that unravels when an insurer’s investigator looks at the environment after an incident, because at that point the inaccurate disclosure is the problem rather than the old server.

Is any end of life technology internet facing?

This is the follow-up that determines the outcome. An unsupported system reachable from the internet has permanent, publicly known vulnerabilities and an unlimited number of people able to try them. Insurers treat it accordingly.

What has to be in place is nothing unsupported published to the internet. Where remote access to a legacy application is needed, it goes behind a modern access layer: a VPN or a reverse proxy with multi-factor authentication in front of it, so the internet reaches the access layer and never the legacy system. That is a configuration change rather than a project in most cases.

The evidence is an external attack surface scan showing what is published, plus the firewall rule set. Do the scan rather than assuming, because published services accumulate. A rule added years ago for a supplier’s remote support tool tends to survive long after the supplier stopped using it.

Is your end of life technology segregated from the rest of the network?

Segregation is what stops an unsupported system becoming the route into everything else. Insurers ask because the realistic attack path is not the legacy box itself being the target: it is the legacy box being the foothold from which the attacker reaches the file server and the backup target.

What satisfies the question is the unsupported system on its own network segment with a deny-by-default rule set, permitting only the specific traffic the application requires in each direction. Not a separate subnet with everything routed freely between it and the main network, which is a common arrangement that looks like segmentation on a diagram and provides none of the benefit.

The evidence is a network diagram together with the actual firewall or access control list rules, and the rules matter more than the diagram. This is the single best-value control in this whole area. It is usually a VLAN, a handful of rules, and an afternoon, and it moves the answer to three of the five questions on this page.

Has additional support been purchased where available?

Some vendors sell extended security updates past the normal end of support date, and proposal forms ask whether you have taken that option. The phrase “where available” matters, because it is often not available, and a no for that reason is a different answer from a no because nobody looked.

What to have in place is the extended support subscription where the vendor offers one and the cost is proportionate to the risk. Where no extended support exists, the answer is no and the weight shifts to the segregation and compensating controls questions, which is exactly how the form is structured.

The evidence is the support agreement or subscription record. Where the answer is no, note the reason in the free text box below rather than leaving it bare, because a no with “no extended support is offered for this product, and the system is segregated with application allowlisting” reads entirely differently from a no on its own.

What additional security measures have been implemented to prevent exploitation of any vulnerabilities?

This is a free text field, and it is the most valuable box on this section of the form. Everything else here is a tick. This is where you get to explain the position, and an underwriter reading a specific, technically credible answer will price the risk differently from one reading a blank or a vague reassurance.

What belongs in it: application allowlisting on the host so only approved programs can run, no outbound internet access from the system, credentials isolated so the legacy machine’s account has no rights elsewhere, enhanced logging on that segment, and a replacement plan with an actual date. The replacement plan is the part that changes the tone of the whole answer, because it turns a permanent risk into a temporary one.

A useful answer reads something like this. The system runs a practice management application the vendor has not certified beyond its current platform. It sits on an isolated network segment with deny-by-default rules permitting only database traffic to one server. It has no internet access, application allowlisting is enforced, its service account has no rights outside the segment, and the vendor’s replacement release is scheduled for migration in the first quarter of next year. Three or four sentences of that kind is what the box is for.

The evidence to assemble before the form arrives

  • An asset list with vendor support end dates recorded per item.
  • An external attack surface scan showing what is published to the internet.
  • The firewall rule set for the segment holding the unsupported systems.
  • Extended support subscription records, or a note of why none is available.
  • A written replacement plan with dates, for each unsupported system.

Patching operating systems and patching applications are two of the eight strategies in the Australian Signals Directorate Essential Eight, and both explicitly require that unsupported versions be removed or otherwise mitigated. The Essential Eight guide for Australian SMEs covers how that is assessed, and the framework is published by the Australian Cyber Security Centre at cyber.gov.au.

One thing not to do

Do not answer no because the old system still works. End of life is about vendor support, not about function, and the machine running quietly in the corner for six years is precisely the one the question is aimed at. An inaccurate no on this question is worse than a yes with weak follow-ups, because it converts a technical shortcoming into a disclosure failure, and those are treated very differently when a claim is assessed.

If a questionnaire has landed and you have an old system you are not sure how to describe, 4iT works through the whole form against your environment, gets the containment in place, and writes the compensating controls answer in the terms an underwriter reads. Request a callback and we will work out where you stand.

Ready to Talk to a Sydney IT Specialist?

4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details

Book a meeting