What Australian Cyber Insurers Will Require in 2027
The Australian cyber insurance market has hardened every year for the last four. Premiums have risen, underwriting has tightened, and the questions on the application form have moved from broad to specific. By 2027, the pattern visible today will be the new baseline.
If your business holds cyber insurance and renews in the next twelve to eighteen months, the form you fill in will not be the form you filled in last time. Some of the changes are predictable. Others are emerging now and will be standard at your next renewal. Better to know in advance.
This is what we expect to see in 2027 renewals, based on the trajectory of underwriting questionnaires we have helped clients complete over the last two years, and on signals from the major Australian carriers and their reinsurers.
Phishing-resistant MFA on privileged accounts
For several years, the headline question has been "do you have MFA". By the 2027 renewal, that question will be split into two.
The first half asks whether MFA is in place for all users, with explicit coverage of email, VPN, cloud apps, remote desktop, and administrative consoles. This part is already standard.
The second half asks specifically about phishing-resistant MFA on privileged accounts. The expected answer is yes, with documented evidence. FIDO2 security keys, passkeys, or certificate-based authentication for IT administrators, finance leaders, and any role that can authorise payments or change critical configuration. App-based MFA on these accounts will increasingly be considered insufficient.
The reason underwriters care is that real-time phishing kits have been beating app-based MFA for two years now. The claims data is showing this clearly enough that underwriters are going to require the harder credential type for the highest-risk accounts.
What to do this year: roll out FIDO2 keys or passkeys to every administrator, every finance staff member with payment authority, and every executive. Document the rollout. Be ready to attest with evidence.
EDR with managed monitoring, not just installed
Endpoint Detection and Response has been on insurance forms for several years. The 2027 question goes deeper. It is no longer "do you have EDR". It is "do you have EDR that is centrally monitored, with alerts being reviewed and acted on, by a defined party with documented procedures".
Underwriters have learned that having EDR installed and having EDR doing useful work are different things. The claims investigations have repeatedly found EDR present, alerts firing, and nobody reading them. That gap is now in the questionnaire.
The expected form of the answer is a managed detection and response service, an internal security operations capability, or a documented commitment from an MSP that includes alert review with response time targets. Self-managed EDR with no defined review process will increasingly produce a higher premium or a coverage exclusion.
What to do this year: confirm that someone, named, is responsible for reviewing your EDR alerts. Document the response time target. If the answer is "we have it, nobody really watches it", fix that before your renewal.
Backup integrity and tested restore evidence
The 2027 question on backups will not just ask whether you have them. It will ask:
- Are backups stored in a way that cannot be encrypted or deleted by an attacker who has compromised your network? In practice this means immutable cloud backups or properly air-gapped media.
- Is there a defined recovery time objective and recovery point objective, by system?
- When was the last full restore test performed? Of which system, by whom, with what result?
- Is the test result documented and signed off?
The "tested restore" question is the new one. Underwriters know that around a quarter of untested backups fail when needed. Saying you have backups is different from saying you have proven that they work. The 2027 questionnaire will reward the difference.
What to do this year: run a real restore test on a meaningful system. Document the result, including how long it took. Repeat at least annually. Build the evidence trail before you need it.
Patching and vulnerability evidence
The patching question is moving from descriptive to evidentiary. The earlier form asked whether you had a patching process. The 2027 form will ask:
- What is your target time to patch internet-facing systems for critical vulnerabilities? What is your actual time, on average, over the last year?
- What vulnerability scanning is in place? How often does it run?
- What is the process for tracking and remediating findings?
- Can you produce a recent scan report?
The shift here is from policy to practice. Insurers have stopped accepting that a written policy means the work is being done. They want to see the evidence stream, with timestamps.
What to do this year: implement vulnerability scanning if you do not have it. Track time-to-patch on critical findings. Keep the scan reports for the last twelve months. Be ready to share a sanitised summary at renewal.
Email security configuration
Email is the most common attack vector and the most measurable. The 2027 questionnaire will ask:
- Is SPF, DKIM, and DMARC fully configured, with DMARC enforcing (not just monitoring)?
- Is anti-impersonation, anti-phishing, and safe links enabled at the email gateway?
- Are external email banners enforced?
- Is mailbox auditing on, with at least one year of retention?
The DMARC enforcement question is the one most likely to surprise SMBs. Many tenants we audit have DMARC at "p=none", which monitors but does not block. Underwriters are increasingly treating that as a partial implementation, not a complete one.
What to do this year: take your DMARC posture from monitoring to enforcement. Verify SPF and DKIM are correct first. Ensure your tenant has anti-phishing policies enabled and tuned, and that mailbox auditing has at least a year of retention.
Privileged access management evidence
The questionnaire will move beyond "do you restrict admin privileges" to:
- How many global administrators do you have? Why each one?
- How are administrative tasks performed? Permanent privileges or just-in-time elevation?
- How are administrative passwords stored?
- When was the last review of administrative roles?
Just-in-time elevation, where users are granted privileges only for the duration of a specific task, has been an enterprise practice for years. It is now arriving in SMB-targeted insurance forms. Tenants without it, but with permanent privileged accounts, will be assessed as higher risk.
What to do this year: document your administrative roles. Review them quarterly. For Microsoft 365 tenants on Premium licensing, evaluate Privileged Identity Management. For tenants without that licensing, at minimum reduce the count of permanent global admins to two, with a documented review.
Incident response readiness
The 2027 form will look for evidence of practised, not just documented, incident response. Expect questions like:
- Do you have a written incident response plan? When was it last reviewed?
- Has it been tested in the last twelve months, in a tabletop or live exercise?
- Are out-of-band communication channels established for use during an incident, when normal email may be compromised?
- Is there a relationship with a forensic responder, on retainer or pre-agreed?
The practised-versus-documented distinction is the new one. A plan written three years ago and never rehearsed is no longer credible evidence of readiness. Tabletop exercises, even short ones, are becoming the expected demonstration.
What to do this year: schedule a two-hour tabletop exercise. Walk through one realistic scenario, with the people who would actually be involved. Document the gaps surfaced and the actions taken.
Awareness training with measurement
Training questions will move from "do you do training" to:
- How often, with what content, with what completion tracking?
- Do you run simulated phishing campaigns? What is your most recent click rate, by department?
- How are repeat clickers managed?
The measurement piece is the new layer. Underwriters are wary of "we did training" as an unverified claim. They want the metrics that show the training is working.
What to do this year: run quarterly simulated phishing campaigns. Track results. Have a defined process for repeat clickers, even if it is just additional training rather than punitive action.
What this all adds up to
The 2027 cyber insurance application is, in effect, a small audit. The questionnaire moves from claims about controls to evidence of controls. The work that produces good answers is the same work that reduces real risk.
The two failure modes worth avoiding.
Overstating to get the policy. The single most common reason claims are denied is a gap between what the application said and what was in place at the time of the incident. As questionnaires get more specific, the consequences of inaccurate answers get more severe.
Treating renewal as a once-a-year scramble. The work needed to answer next year's form well is twelve months long, not one week. Build the evidence trail through the year.
If you are renewing in the next twelve months and would like an outside view of where you stand, our free IT health check includes a cyber insurance readiness review. We map your current controls against what 2027 underwriters are likely to ask, identify the gaps, and produce a remediation plan you can work through before your renewal date. No obligation, no sales pitch.
Need help with cybersecurity?
Our free IT health check will show you exactly where your business stands and what to prioritise. No obligation.
Book your free health checkGet IT insights in your inbox
Practical tips for Australian businesses. No spam. Unsubscribe anytime.
More from the blog
Passkeys Are Replacing Passwords. Is Your Business Ready?
Passkeys are the most significant change to authentication in twenty years. They are faster, more secure, and now supported by every major platform. Here is what they actually are, why they matter for your business, and how to roll them out without breaking anything.
StrategyWhen to Fire Your IT Provider: 5 Signs It's Time to Switch
Switching IT providers feels disruptive, so most businesses delay it longer than they should. By the time the relationship is clearly broken, the business is paying for the delay. Here are the five signs that say it is time to look elsewhere, and how to switch without breaking everything.