Home | Cyber insurance questionnaire | policy
Cyber insurance policy questions: how to answer them
Australian cyber insurance proposal forms ask two questions about policies. One is a tick list covering a privacy policy, a cookies policy, and a data retention and destruction policy. The other asks specifically whether you have a bring your own device policy that ensures data on portable devices is encrypted. All four documents have to exist for both answers to be yes, and we have written all four as free templates you can download from this page.
Sydney MSP
Greater Sydney, NSW
- Microsoft Partner
- Sophos Partner
- Ubiquiti Partner

Key facts
- Insurers ask for four policy documents across two questions: privacy, cookies, data retention and destruction, and bring your own device.
- The bring your own device question is worded around encryption of data on portable devices, so a general device policy that does not mention encryption does not answer it.
- The data retention and destruction policy is the one most Australian small businesses lack, and it is the one that lowers your record count at the next renewal.
- A policy with no technical enforcement behind it is not an accurate yes, because the same forms ask separately for evidence of the controls the policy describes.
- Whether the Privacy Act 1988 legally requires a privacy policy depends on your business. As at September 2026 the small business exemption for turnover of $3 million or less has not been repealed, despite widespread commentary saying it has.
- Insurers ask for the policy regardless of whether the law requires it of you.
Download the four templates
These are Word documents so you can edit them. Each one opens with a short page explaining how to adapt it, a list of every placeholder to replace, and a note on why an insurer asks for it. Delete that first page when you are done and the document reads as your own. They are free, there is no form to fill in, and you do not need to give us your email address.
- Privacy Policy template
- Cookies Policy template
- Data Retention and Destruction Policy template
- Bring Your Own Device Policy template
All four also sit on our downloads page alongside our other free resources.
Why insurers ask for policies at all
A policy is not a control. It does not stop an intrusion and it does not encrypt anything. Insurers ask for these four because a policy is evidence that somebody in the business has thought about the topic and written down a position, and because a claim assessment will compare what the policy says against what the environment does.
That comparison is the part worth understanding. If your privacy policy says you encrypt personal information and your laptops are not encrypted, the policy has documented the gap rather than covered it. Policies are only an asset when they describe what is true, which is why the templates below are written to be cut down rather than padded out.
The questions below come from Australian cyber insurance proposal forms current as at September 2026. No insurer is named. The full set of 45 technical questions is on the cyber insurance questionnaire guide.
The policy questions insurers ask
Do you have a privacy policy, cookies policy, and data retention and destruction policy?
Australian proposal forms ask this as a single tick list with each policy as its own item, so a partial answer is visible. Most businesses tick privacy and cookies and stop, because the third one is the one nobody has.
What each document needs to do is different. The privacy policy states what personal information you collect, why, who you disclose it to, how you secure it, and how someone can access it or complain. The cookies policy describes the cookies your website sets, what they do and how long they last, which means it has to reflect your site rather than a generic list. The data retention and destruction policy sets how long you keep each type of record and how you destroy it, which requires you to make decisions rather than copy text.
The evidence is the documents themselves with a review date on each. Keep the security section of the privacy policy consistent with what you claim elsewhere on the form, since an underwriter reading both will notice if the policy promises encryption that the encryption question does not support. On the legal question, the position as at September 2026 is that the small business exemption for turnover of $3 million or less still applies, so many Australian SMEs are not legally required to have a privacy policy at all. That does not help with this form. Insurers ask for it either way, and so do tender processes and larger customers.
Do you have a bring your own device policy that ensures data on portable devices is encrypted?
The wording of this question is the whole question. Insurers are not asking whether you have a device policy. They are asking whether you have one that ensures encryption of data on portable devices, and a policy covering acceptable use, personal calls and data allowances without addressing encryption does not answer it.
What needs to be in place is a written policy requiring encryption on any personal device that holds business data, covering phones, tablets, laptops, USB drives and portable hard drives, plus the technical enforcement to make it true. Enforcement usually means device compliance or app protection policies that check encryption before granting access to business data. The policy should also say what the business can and cannot do to a personal device, because the point at which you need to remove business data from someone’s phone is a bad time to be having that conversation for the first time.
The evidence is the policy document, the signed staff acknowledgements, and the device compliance state showing encryption enforced. This answer needs to be consistent with two others on the same form: the encryption question, which asks separately whether data on portable devices is encrypted, and the endpoint protection question, which asks what proportion of your devices are covered. If personal devices are in scope for one and invisible to the others, an underwriter will ask why.
Does a policy count if nothing enforces it?
On the form, a written policy is enough to tick the box. In a claim, it is not, and that gap is where businesses get caught.
Consider the encryption requirement in a bring your own device policy. If the policy requires it and nothing checks it, then at any given moment you do not know whether it is true, and neither does your insurer. When a phone goes missing, the question is not what the policy said. It is whether that specific device was encrypted, and the answer comes from a compliance report rather than from a document. A lost encrypted phone is a lost asset. A lost unencrypted phone holding customer records is potentially a notifiable data breach.
So the useful test for each of these four policies is whether something other than memory makes it true. Retention periods configured in the platform rather than in a spreadsheet. Encryption checked before a device gets access rather than assumed. A cookies policy regenerated when a marketing tool is added rather than left describing last year’s website. Policies that the systems enforce survive staff turnover. Policies that rely on someone remembering do not, and turnover is exactly when the gap opens.
The evidence to assemble before the form arrives
- Four policy documents, each with an approval date and a review date.
- Signed staff acknowledgements for the bring your own device policy.
- A device compliance report showing encryption enforced across managed and personal devices.
- Retention settings configured in your systems, matching the retention schedule in the policy.
- A dated record of the last annual review of each policy.
Obligations under the Notifiable Data Breaches scheme, and guidance on what a privacy policy should contain, are published by the Office of the Australian Information Commissioner at oaic.gov.au. The retention policy interacts directly with the record count question elsewhere on the form, because records you have destroyed are records you no longer report.
One thing not to do
Do not download a policy, fill in your business name, and file it without reading it. These four documents make claims about how your business operates, and a proposal form is a disclosure document. A privacy policy promising encryption you do not have, or a retention schedule you do not follow, is worse than not having one, because it converts a control gap into a written statement that was not true when you signed the form. Read them, cut anything that does not describe your business, and make the rest true.
The templates above are free and yours to use. If you would rather have the policies match what your systems can prove, 4iT works through the whole questionnaire against your environment, configures the enforcement behind each policy, and produces the evidence pack the underwriter will ask for. Request a callback and we will work out what applies to you.
Ready to Talk to a Sydney IT Specialist?
4iT Support covers SMEs across Greater Sydney including the Hills District, North Shore, Parramatta, and the CBD. No lock-in contracts. Straight answers.







