4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Home | Cyber insurance questionnaire | incident response

Cyber insurance incident response questions: how to answer them

Australian cyber insurance proposal forms ask five questions about how you would handle and survive an incident. Three plans have to exist and be tested annually, the incident response plan has to address ransomware specifically, past downtime over eight hours has to be disclosed, and you have to say who in the business is responsible for cyber security. That last question has a wrong answer that IT providers give on their clients’ behalf all the time.

Sydney MSP

Greater Sydney, NSW

Printed plan document in a binder on a meeting room table

Key facts

  • Insurers ask for three plans: a disaster recovery plan, a business continuity plan and an incident response plan, each answered twice, once for existence and once for annual testing.
  • That makes six answers hidden behind one question, and “in place but not tested” is the most common weak result.
  • The incident response plan is asked separately about whether it addresses ransomware scenarios specifically.
  • Most cyber policies require the insurer to be notified before the insured engages incident responders, so a plan naming the wrong first call can prejudice the claim.
  • The downtime question covers any unforeseen outage over eight hours, including hardware failure, an internet outage or a failed migration, not only security incidents.
  • The cyber security responsibility question asks for a person’s name, title, email and mobile, and the answer should be a director or manager, not only the IT provider.

Why insurers ask about this in so much detail

Every other control on the form is about reducing the chance of an incident. This section is about reducing its cost once it happens, which is the part the insurer pays for. A business that can isolate quickly, knows who to call, and has a tested recovery sequence generates a smaller claim than an identical business improvising at 11pm on a Friday, and the difference is often an order of magnitude in business interruption alone.

The testing half of the plan question exists because untested plans reliably fail on contact. The usual discoveries during a first tabletop exercise are that the contact list is out of date, that the recovery order was never worked out so people restore the file server before the domain controller, and that nobody knows who has authority to shut down production.

The questions below come from Australian cyber insurance proposal forms current as at September 2026. No insurer is named. The full set of 45 technical questions is on the cyber insurance questionnaire guide.

The incident response questions insurers ask

Do you have a disaster recovery plan, business continuity plan and incident response plan, and are they tested annually?

Australian proposal forms present this as a small grid: three plans down the side, and two columns asking whether each is in place and whether each is tested at least annually. Six answers, and the second column is where most businesses lose ground.

What each plan needs is different. The disaster recovery plan covers the technical sequence for restoring systems, in order, with recovery time and recovery point objectives stated. The business continuity plan covers how the business keeps operating while that happens, which is a management document rather than a technical one and covers things like where people work and how customers are told. The incident response plan covers the first hours: who decides, who is called, what gets isolated, and what the notification obligations are. All three need named roles rather than job titles that may be vacant, and current contact details including personal mobile numbers, because a compromise may take out the phone system and the email.

The evidence is the three documents plus dated test records. A tabletop exercise counts as a test and takes about two hours: sit the relevant people in a room, present a ransomware scenario, and work through the plan out loud. Write down what did not work. That written record is the artefact the underwriter wants, and it is worth more than a polished plan nobody has read.

Does your incident response plan specifically address ransomware scenarios?

Insurers ask this as its own question because generic incident response plans almost never have it, and ransomware is the scenario that generates the largest claims. A plan written around a data breach does not tell anyone what to do when systems are encrypting in front of them.

What the ransomware section needs to cover: how to isolate quickly and who has authority to do it without waiting for a meeting, the position on paying a ransom and who decides, who gets called first, the notification obligations under the Notifiable Data Breaches scheme, and the recovery sequence from the immutable backup copy including how long it is expected to take.

The first call is the detail most often wrong, and it matters commercially. Most cyber policies require the insurer to be notified before the insured engages forensic responders or legal counsel, because the insurer has panel providers and pre-agreed rates. A plan that says to call your IT provider and then a preferred forensics firm can leave the business paying for work the policy would otherwise have covered. Put the insurer’s incident hotline in the plan, above everything else, and check the number every year when you review it.

Have you had any unforeseen downtime to your website or IT network of more than 8 hours?

This is a factual disclosure rather than a control, and it is answered no incorrectly more often than any other question in this section, because people read it as asking about cyber incidents. It does not say that.

Any unforeseen outage over eight hours counts. A failed server, a corrupted database, an internet or carrier outage, a power event, a migration that went wrong over a weekend, a hosting provider’s problem taking your website down for a day. If it was unplanned and it lasted more than eight hours, it belongs in the answer, and the form usually asks for the duration, how it was resolved and what it cost.

The evidence is your monitoring history and ticket records. Answer this one from the records rather than from memory, because an eight hour outage eighteen months ago is easy to forget and it is exactly the kind of thing that surfaces during a claim investigation. Disclosing it costs very little. Failing to disclose it is a different category of problem.

Are critical components, services and supplies available from multiple sources?

Proposal forms ask this in support of contingent business interruption cover, with banded answers: readily available from multiple sources, substitutes available within ten days, longer than ten days, substitution not possible, or don’t know.

What you need is a named list of critical suppliers and platforms with the substitution position recorded against each. For most Australian businesses the honest answer is uncomfortable: the critical dependency is a single platform that runs the business, whether that is a practice management system, a job management platform or an industry-specific application, and there is no substitute available inside ten days at any price.

Answer honestly and state the fallback, because “substitution not possible, and here is how we would operate manually for two weeks” is a better answer than a vague claim of availability. The evidence is the supplier list with alternates identified, and building it is useful well outside the insurance process, since it is the same list your business continuity plan needs.

Who is the person responsible for cyber security in your business?

Australian proposal forms ask for a name, a title, an email address and a mobile number, and they usually note that this person will receive critical security notifications. It looks administrative. It is not.

The answer should be a director or a senior manager inside the business, with the IT provider recorded alongside as the party delivering the controls. Naming only the IT provider is the wrong answer, and it is the answer IT providers often supply on a client’s behalf out of helpfulness. Accountability for cyber security is a governance function that cannot be outsourced, and an underwriter reading an external provider in that field learns that nobody inside the business owns the topic. It also means urgent notifications from the insurer go to a third party rather than to someone who can authorise a decision.

The evidence is the name. The useful part is the conversation it forces, because deciding who holds this internally is usually the first governance step a business takes on the topic.

The evidence to assemble before the form arrives

  • Three plan documents with named roles and current contact details, including personal mobile numbers.
  • Dated tabletop exercise notes for each plan, recording what did not work.
  • A ransomware section in the incident response plan, with the insurer’s notification hotline as the first call.
  • Monitoring and ticket history covering any outage over eight hours in the disclosure period.
  • A critical supplier list with the substitution position recorded for each.
  • A named internal owner for cyber security, with contact details.

Notification obligations under the Notifiable Data Breaches scheme are set out by the Office of the Australian Information Commissioner at oaic.gov.au, and the ransomware guidance published by the Australian Cyber Security Centre at cyber.gov.au is a reasonable starting point for the plan section. The recovery sequence in the plan depends on the backup controls asked about elsewhere on the form, so write the two together.

One thing not to do

Do not write the ransomware section with your IT provider as the first call and leave the insurer out of it. It feels like the natural order and it can cost the business the response costs the policy was bought to cover. The correct sequence is to notify the insurer, then act on their instructions, with your IT provider isolating and containing in parallel. Get the hotline number into the document and verify it at every annual review, because it is the one piece of the plan that has a direct dollar consequence if it is wrong.

If a questionnaire has landed and the plans either do not exist or have never been tested, 4iT writes the three documents, runs the tabletop exercise, and produces the dated evidence the underwriter will ask for. Request a callback and we will work out what you need.

Ready to Talk to a Sydney IT Specialist?

4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details

Book a meeting