June 2026

Cyber Insurance: Why SMBs Get Knocked Back (and How to Fix It)

Five years ago, cyber insurance was a checkbox purchase. Today, insurers have paid out enough ransomware claims that the questionnaire has teeth: answer "no" to the wrong question and you'll face an exclusion, a premium loading, or a flat refusal. Here's what they're really asking — and how to get to "yes".

The five questions that decide your application

  • "Is MFA enforced on all email, remote access and admin accounts?" — The single biggest factor. "Mostly" counts as no.
  • "Do you run EDR / managed detection on your endpoints?" — Traditional antivirus no longer satisfies most underwriters.
  • "Are backups offline/immutable and restore-tested?" — They're asking: if ransomware hits, will you actually recover without paying?
  • "Do staff receive security awareness training and phishing simulation?" — Because most claims start with a click.
  • "How quickly do you patch critical vulnerabilities?" — "Within 48 hours for internet-facing systems" is the answer they want.

Why this matters beyond the premium

Misstating these answers is worse than answering "no". If you claim MFA is universal and the forensics after an incident show it wasn't, the insurer can deny the claim outright — exactly when you need it most. Your questionnaire answers need to be true, evidenced and kept current.

The readiness checklist

  • Enforce MFA everywhere — including the "temporary" admin account everyone forgot about.
  • Deploy EDR on every device, ideally with 24/7 monitoring behind it.
  • Move to immutable or offline backups, and do a timed restore test twice a year.
  • Run quarterly phishing simulations and keep the completion reports.
  • Automate patching and document your SLA for critical fixes.
  • Keep an evidence folder: screenshots, policies, reports. Renewal becomes an afternoon, not a month.

The good news

Everything on that list is also just... good security. Insurers didn't invent new requirements; they operationalised the Essential Eight. Do the uplift once and you satisfy the insurer, the tender panel and the enterprise customer's due-diligence team with the same evidence pack — while actually being harder to breach.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check