Home | Cyber insurance questionnaire | payment fraud
Cyber insurance payment fraud questions: how to answer them
Australian cyber insurance proposal forms ask two questions about payment fraud, and they are the questions most likely to be sent to an IT provider who cannot answer them. Both are finance process controls: whether payee bank details are verified directly with the payee, and whether transfers require two people to authorise them. Neither is a product you buy. Both are the difference between a recoverable mistake and a payment that is simply gone.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner

Key facts
- Proposal forms ask two payment fraud questions, usually under an optional cover section for criminal financial loss or socially engineered theft.
- The thresholds differ between insurers. One form triggers dual authorisation on transfers above $10,000, another applies it to any transfer of funds at all, plus cheques above $10,000 and instructions to disburse assets or investments.
- Verification has to be out of band. One form’s wording requires the details be independently verified with a known contact by phone or in person.
- Replying to the email to confirm is not verification, because in a mailbox compromise the attacker controls the mailbox and answers your confirmation.
- These are the cheapest controls on the entire proposal form to implement, because they are procedures rather than purchases.
- The technical controls that prevent the mailbox compromise behind these attacks are asked about elsewhere on the same form, under identity and email security.
Why your IT provider gets asked a finance question
These two questions arrive in the same document as the technical ones, so the whole section tends to get forwarded to whoever handles IT. That is understandable and it is also the wrong destination for the controls themselves. Dual authorisation is a setting inside your banking platform, configured by whoever administers the business’s accounts. Payee verification is a written procedure followed by whoever processes payments.
The reason it is worth an IT provider engaging rather than sending it back is that the attack these questions defend against is delivered by email, and everything upstream of the fraudulent request is technical. An attacker gets into a mailbox, creates an inbox rule to hide their activity, reads invoice threads until a real payment is in play, and sends a request that is contextually perfect because it is based on a real conversation. Multi-factor authentication, email filtering, impersonation protection and inbox rule alerting all sit underneath these two answers.
So the honest division is this: 4iT supplies and monitors the controls that stop the mailbox being taken over in the first place, and the business configures the two controls that stop a fraudulent instruction being acted on. Both halves are needed, and the form asks about both.
The questions below come from Australian cyber insurance proposal forms current as at September 2026. No insurer is named, and the stricter wording is used where forms differ. The full set of 45 technical questions is on the cyber insurance questionnaire guide.
The payment fraud questions insurers ask
Are new payees and changes to existing payee bank details verified with the payee directly?
Australian cyber insurance proposal forms ask this in two ways. One asks whether all new payees, and changes to existing payees’ banking details, are double authenticated with the payee. Another asks whether, when creating or amending supplier and customer payment details, the business independently verifies the details with a known contact by phone or in person. Answer to the second, because a control built for it satisfies both.
What needs to be in place is a written procedure requiring out-of-band verification for every new payee and every change to existing details, using a phone number already held on file rather than one supplied in the request. That last clause is the part that gets missed. An attacker asking you to confirm a bank detail change will helpfully include a phone number, and calling it reaches the attacker. The number has to come from your own records.
The evidence is the written procedure plus a verification record kept against changes, which is usually a note against the supplier record naming who called, who they spoke to, and when. The single most common inaccurate answer to this question is a yes based on replying to the email to confirm. In a mailbox compromise that confirmation is read and answered by the attacker, which makes it worse than no check at all, because it produces false confidence.
Do transfers require dual authorisation?
One Australian form asks whether transfers above $10,000 require a dual signature or supervisor and manager sign off. Another asks whether at least two members of staff authorise any transfer of funds, the signing of cheques above $10,000, and the issuance of instructions for the disbursement of assets, funds or investments. The second is materially stricter: no lower threshold on transfers, and investment instructions brought into scope.
Build the control to the stricter version. That means two-person authorisation configured in the banking platform, applying to all transfers rather than only large ones, plus cheques above $10,000 and any instruction to move assets or investments. Configuring it in the platform matters more than writing it in a policy, because a policy is a request and a platform setting is a constraint.
The evidence is the banking platform’s authorisation settings and the written finance procedure. There is a real practical problem here for smaller businesses: dual authorisation needs two people, and plenty of Australian businesses run payments with one bookkeeper and one director who is often unreachable. The workable answer is usually the director as second authoriser with a mobile approval method, and a named alternate for leave periods. Saying it cannot be done is understandable and it is also the answer that leaves the exposure open, since the attacker is counting on exactly that arrangement.
What does 4iT do about this?
The two controls above belong to the business. What we supply is everything that prevents the compromise that makes the fraudulent request possible: multi-factor authentication on every mailbox with legacy authentication protocols disabled, email filtering across all accounts, impersonation and lookalike domain protection, sender authentication so nobody can send mail as your domain, and alerting on inbox rule creation.
That last control is the one worth asking us about specifically. An intruder in a mailbox almost always creates a rule to hide their sent items and replies from the real owner, and that rule typically appears days before any fraudulent payment request. It is the earliest available warning for the most expensive thing that happens to Australian small businesses by email, and it is a monitoring configuration rather than a purchase.
The evidence to assemble before the form arrives
- The written payee verification procedure, stating that the phone number must come from your own records.
- A verification record against recent payee changes, showing who called and who they spoke to.
- Banking platform authorisation settings showing two-person approval and the threshold it applies from.
- The written finance procedure covering cheques and instructions to disburse assets or investments.
- A named alternate second authoriser, for leave and absence.
One thing not to do
Do not treat these as the soft questions on the form. They sit under an optional cover section, which makes them look like a formality next to the technical questions, and they are the questions attached to the loss type most likely to happen. A business with excellent endpoint protection and no payee verification procedure has covered the dramatic scenario and left the common one open.
If a questionnaire has landed and the criminal financial loss section is the part nobody can answer, 4iT works through the whole form, sets up the technical controls that sit underneath these two answers, and produces the evidence pack the underwriter will ask for. Request a callback and we will work out what applies to you.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.







