Home | Cyber insurance questionnaire | security training
Cyber insurance security training questions: how to answer them
Australian cyber insurance proposal forms ask three questions about security awareness training: how often you train staff, how often you test them with simulated phishing, and whether you maintain written materials on social engineering and fraud with a review cycle. The frequency answers are banded and monthly scores best, but completion rate matters more than cadence, and an underwriter who asks for evidence will see the difference immediately.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner

Key facts
- Insurers ask three questions here: training frequency, simulated phishing frequency, and whether written materials exist with regular review.
- Both frequency questions use the same bands: annually, quarterly, monthly, or not provided.
- A platform subscription alone does not answer the written materials question, which asks about documented content and a review cycle.
- Quarterly training at 95% completion is a stronger position than monthly training at 40% completion, because the evidence is a completion report.
- The phishing click rate trend over several quarters is the most persuasive evidence available in this area, and no policy document can substitute for it.
- These questions sit alongside the payment fraud questions on the same forms, because they defend against the same attack.
Why insurers ask about this at all
Every technical control on a cyber insurance proposal form can be defeated by one person entering credentials into a convincing page or approving a request that looked routine. Insurers ask about training because the loss types that dominate Australian small business claims, invoice redirection and mailbox compromise, both depend on a person taking an action rather than on software being broken.
The reason there are three questions rather than one is that the three measure different things. Training frequency measures whether the programme exists. Simulation frequency measures whether it is tested against reality. The written materials question measures whether it is documented well enough to survive staff turnover and to be reviewed, which is the difference between a programme and a subscription somebody bought.
The questions below come from Australian cyber insurance proposal forms current as at September 2026. No insurer is named. The full set of 45 technical questions is on the cyber insurance questionnaire guide.
The awareness training questions insurers ask
How frequently do you provide security awareness training to your employees?
Australian proposal forms offer annually, quarterly, monthly, or not provided. Monthly is the best-scoring answer, and for most small businesses quarterly is the realistic one that still reads well.
What needs to be in place is a platform delivering short modules on a set cadence, with completion tracked per person, and new starters enrolled as part of onboarding rather than at the next cycle. New starters are the gap that matters: someone who joined in March and receives their first training the following January has been the least prepared person in the business for ten months, and they are also the person least likely to notice that a supplier’s bank details have never changed before.
The evidence is a completion report by employee covering the stated period. Be aware of the trap in answering monthly. If the platform sends monthly content and half the staff have not opened it, the completion report shows that, and it is a worse position than an honest quarterly answer with high completion. Pick the cadence you can complete.
How frequently do you test employees’ security awareness through simulated phishing campaigns?
Proposal forms use the same four bands for simulation as for training. Quarterly is the minimum that produces anything useful, because a single annual campaign is a measurement rather than a programme.
What satisfies the question is simulation running on a schedule, with results recorded per person, and follow-up training assigned to anyone who clicks. That last part is what turns testing into training. Simulation with no consequence for a click measures the problem without addressing it, and the businesses that see real improvement are the ones where a click leads to a short piece of targeted content rather than to a conversation with a manager. Punitive handling reliably makes people hide their mistakes, which is the opposite of what you want, because the single most valuable thing an employee can do after clicking something is tell somebody immediately.
The evidence is campaign results over time showing the click rate trend. A falling rate across four quarters is the strongest single piece of evidence in this whole area, because it demonstrates the programme changes behaviour. Keep the history rather than only the latest campaign.
Do you maintain written training materials on social engineering, phishing and cyber fraud, with regular review?
One Australian form asks this separately, worded around whether procedures exist for providing written training materials to all employees on the dangers of social engineering fraud, phishing and cyber fraud, incorporating regular review. It is a different question from the two above and it catches businesses out, because a training platform subscription does not answer it.
What is required is documented content issued to all employees, covering those specific topics, with a review cycle and a review date. In practice that means a short written procedure or handbook section that says what the threats look like in your business, what an employee should do when they see one, and who to tell. It should name the finance process controls explicitly, because the material has to connect to the payee verification and dual authorisation controls that the same form asks about elsewhere.
The evidence is the materials themselves, the distribution record showing they went to all employees, and the review date. Reviewing annually and recording that you did is sufficient. The review is the part most often missing, and it is a calendar entry rather than a project.
The evidence to assemble before the form arrives
- A completion report by employee for the last full training period.
- New starter enrolment evidence, showing training assigned at onboarding.
- Phishing simulation results across at least four campaigns, showing the click rate trend.
- The follow-up training assignment record for people who clicked.
- Written materials on social engineering, phishing and fraud, with a distribution record and a review date.
These questions connect directly to the payment fraud questions on the same forms, since awareness training is what makes the payee verification procedure work in practice rather than only on paper. The Australian Cyber Security Centre publishes free material on recognising scams and business email compromise at cyber.gov.au that can be used inside your own written materials.
One thing not to do
Do not answer monthly because the platform is set to monthly. The evidence for this question is a completion report, and an underwriter or a claims assessor asking for it will see the gap between what was sent and what was done. An accurate quarterly answer with 95% completion, a phishing click rate that has fallen over a year, and a written procedure reviewed last month is a considerably stronger submission than a monthly claim that the reporting contradicts.
If a questionnaire has landed and you need the training answers to be backed by reporting rather than intent, 4iT runs the programme, keeps the completion and simulation evidence, and writes the material so it points at your own finance controls. Request a callback and we will set it up.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.







