Home | Cyber insurance questionnaire | patching
Cyber insurance patching questions: how to answer them
Australian cyber insurance proposal forms ask one question about how you patch and four about what independent testing you have had done in the last 12 months. The patching question has banded answers that openly reward automation. The four assessment questions are all yes or no, and for a small business the right answer to at least one of them is no, which is worth understanding before you spend money trying to turn it into a yes.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner

Key facts
- Insurers ask five questions in this area: one on patch process, then whether a vulnerability scan, penetration test, external IT audit or Payment Card Industry assessment has been done in the last 12 months.
- The patching answers are banded: manual within 30 days, manual within 90 days, manual with no time frame, or devices set to update automatically where available.
- Automatic updates is the strongest answer for workstations, and it says nothing about servers, network equipment or line-of-business applications, which is where most patching risk sits.
- A vulnerability scan with no remediation trail is a weaker position than no scan, because it evidences known findings that were left open.
- Penetration testing is usually not warranted at small business scale, and a vulnerability scan plus an external attack surface review addresses the same underwriting concern for far less.
- For most Australian businesses, the external IT audit question means an Essential Eight maturity assessment.
Why insurers ask about this in so much detail
Unpatched software is the second most common way attackers get in, behind stolen credentials, and unlike credentials it is entirely within a business’s control. Insurers separate the process question from the testing questions because they measure different things. The process question asks whether patching happens systematically. The testing questions ask whether anyone independent has checked, which is a proxy for whether the business would know if the process had quietly stopped working.
The four testing questions also help an underwriter place the business on a maturity scale without needing to inspect anything. A business that has had a scan and an external assessment inside 12 months is telling the insurer that someone is looking, and that matters more than the specific findings.
The questions below come from Australian cyber insurance proposal forms current as at September 2026. No insurer is named. The full set of 45 technical questions is on the cyber insurance questionnaire guide.
The patching and assessment questions insurers ask
Do you have a critical security patch management process, and how are patches applied?
Australian cyber insurance proposal forms ask this as a yes or no followed by four options describing how patches are handled: manual updates implemented within 30 days, manual updates within 90 days, manual updates with no time frame, or devices set to update software automatically where available.
What needs to be in place is a documented cadence with a defined window for critical and high-risk vulnerabilities, applied across operating systems, third-party applications and device firmware. The third of those is the one most often absent. Firewalls, network switches, wireless access points, printers and network video recorders all run firmware, they are all reachable from inside the network, and almost nobody has a schedule for them. A patching answer that covers only Windows updates is describing part of the estate.
The evidence is a patch compliance report broken down by device, an exception register for anything deliberately held back, and the documented cadence itself. Note that the strongest available answer, automatic updates, only speaks to endpoints. If you tick it, be ready for the follow-up about servers and applications, because that is where an underwriter’s interest sits.
Have you had a vulnerability scan conducted in the last 12 months?
This is a yes or no on Australian proposal forms, sitting in a list alongside the other three assessment types. It is the one on this list that every business should be able to answer yes to, because it is inexpensive, repeatable and it produces the evidence the other questions cannot.
What satisfies it is an authenticated internal scan plus an external scan of your internet-facing footprint, run inside the last 12 months, with the findings tracked through to closure. Quarterly is better than annually, because a scan is a snapshot and the estate changes underneath it.
The evidence is the scan report with a date inside the period, together with the remediation record showing what was fixed and what was accepted as a risk. That second part matters more than people expect. A scan report with 40 open critical findings and no remediation trail puts you in a worse position than never having scanned, because it demonstrates the business knew and did nothing. If you are going to scan, plan the remediation at the same time.
Have you had a penetration test conducted in the last 12 months?
Insurers ask this on the same list, and for most small and medium Australian businesses the honest answer is no. That is usually the correct answer rather than a gap, and it is worth saying so plainly rather than treating it as something to fix.
A penetration test is a scoped, manual attempt by a skilled tester to break in. It is valuable when a business has custom applications, holds unusually sensitive data, or has a specific question it needs answered. It costs several thousand dollars at minimum and it produces findings that only help if there is capacity to act on them. For a 20-person business running standard platforms, a vulnerability scan plus a review of what is exposed to the internet addresses the same underwriting concern at a fraction of the price.
If you have had one, hold the report or its executive summary along with the remediation plan. If you have not, answer no and answer yes to the vulnerability scan question. An underwriter reading no to penetration test and yes to scanning and external assessment sees a business making sensible decisions about proportionate spend.
Have you had an external IT audit conducted in the last 12 months?
Proposal forms leave this deliberately broad, and in the Australian market it means an independent review of your controls by someone who is not the party that built them. For most businesses that is an Essential Eight maturity assessment, because the Essential Eight is the framework Australian underwriting questions are largely derived from.
What satisfies it is a documented assessment against a recognised framework, dated, performed by a party independent of day-to-day operations, with a maturity rating or a findings list attached. An internal checklist filled in by the person who administers the systems is not what the question is asking about.
The evidence is the assessment report. The useful side effect is that a maturity assessment answers a large share of the rest of the proposal form as a by-product, since it examines patching, application control, administrative privileges, multi-factor authentication and backups. Doing one before the form arrives turns the questionnaire from a research exercise into a transcription exercise.
Have you had a Payment Card Industry (PCI) assessment conducted in the last 12 months?
This one only applies if your business stores, processes or transmits payment card data. Australian proposal forms ask it alongside the other assessments without qualifying it, which leads businesses that take card payments through a hosted gateway to answer yes when they should not, or to worry about an obligation they do not have.
What determines the answer is where the card data goes. If payments are handled entirely by a compliant hosted gateway or terminal, and card numbers never touch your systems, your obligation is usually a self-assessment questionnaire rather than a full assessment, and the gateway provider’s attestation of compliance covers the processing itself. If you store card numbers anywhere, including in a customer record or an email, you have a genuine obligation and a genuine exposure.
The evidence is either the completed self-assessment questionnaire or the provider’s attestation of compliance. Keep this answer consistent with the record types question elsewhere on the form: claiming no payment card information is held and then a PCI assessment, or the reverse, gets queried by an underwriter.
The evidence to assemble before the form arrives
- The documented patching cadence, with the window for critical vulnerabilities stated.
- A patch compliance report by device, covering operating systems, applications and firmware.
- An exception register for anything held back, with the reason.
- A dated vulnerability scan report, internal and external, plus the remediation record.
- A dated Essential Eight maturity assessment or equivalent independent review.
- Where card data applies, the self-assessment questionnaire or the gateway’s attestation of compliance.
Patching applications and patching operating systems are two of the eight strategies in the Australian Signals Directorate Essential Eight, and the framework sets specific windows for critical vulnerabilities. The Essential Eight guide for Australian SMEs covers those windows, and the framework is published by the Australian Cyber Security Centre at cyber.gov.au.
One thing not to do
Do not commission a penetration test because a proposal form mentions one. It is the most expensive item on this page and the least likely to change an underwriting outcome for a small business. The money goes further on a quarterly vulnerability scan with the remediation carried through, and on an independent maturity assessment that answers half the rest of the form at the same time. Spending proportionately and being able to explain why is a better position than an expensive report with unaddressed findings in it.
If a cyber insurance questionnaire has landed and you are unsure which of these four assessments are worth doing, 4iT works through the whole form against your environment, tells you where spending is proportionate and where it is not, and produces the evidence pack the underwriter will ask for. Request a callback and we will work out what applies to you.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.







