Your Cyber Insurance Application Is a Compliance Audit in Disguise
You’re renewing your cyber insurance. The broker sends over the proposal form. You open it expecting a few basic questions about revenue and employee count.
Instead, you get four pages asking about multi-factor authentication, endpoint detection, email filtering, backup procedures, incident response plans, access controls, and security awareness training.
That’s not an insurance form. That’s a compliance audit. And how you answer it determines three things: whether you get coverage, how much you pay, and whether a claim gets paid when you actually need it.
Why underwriters care about your M365 configuration
Cyber insurance used to be simple. Pay the premium, get the policy. Underwriters treated it like fire insurance: measure the risk broadly, price accordingly, hope for the best.
Then they started paying claims. Lots of them.
Business email compromise alone cost Australian businesses over $152 million in 2024. Ransomware incidents jumped from 49 to 60 reported cases in the second half of 2024 alone. Underwriters realised that most breaches weren’t sophisticated nation-state attacks. They were preventable incidents caused by basic security gaps.
So the proposal forms got specific. Very specific.
What they’re actually asking
Here’s a breakdown of what a typical Australian cyber insurance proposal covers, and what underwriters are really looking for:
Multi-factor authentication
The question: “Is MFA enabled for all remote access, email access, and privileged accounts?”
What they want to hear: Yes, for all users, using phishing-resistant methods (authenticator apps or hardware keys, not SMS).
What happens if you say no: Some underwriters will decline coverage outright. Others will offer coverage with exclusions, meaning the exact scenario you’re most likely to face (credential compromise) won’t be covered.
The reality: Microsoft’s data shows 99.9% of compromised accounts had MFA disabled. Underwriters know this. If you don’t have MFA and you get breached, they’ll argue the claim was preventable. And they’ll be right.
Backup and recovery
The question: “Do you maintain offline or immutable backups? What is your recovery time objective?”
What they want to hear: Yes, with tested recovery procedures, immutable storage, and backups covering all critical systems, not just email.
Why it matters: Ransomware attackers increasingly target backup systems first. If your backups are online, connected to the same network, and accessible with the same credentials as your production environment, they’ll be encrypted along with everything else. An immutable backup is one that can’t be modified or deleted, even by someone with admin access.
The gap most firms have: Microsoft 365’s built-in retention is not backup. The 93-day recycle bin is not backup. If your answer to “what’s your backup strategy?” is “Microsoft handles it,” your claim will be contested.
Endpoint detection and response (EDR)
The question: “Do you use EDR software on all endpoints? Is it centrally managed?”
What they want to hear: Yes, deployed to all devices (including servers), centrally monitored, with automated response capabilities.
What traditional antivirus misses: Legacy antivirus looks for known malware signatures. Modern attacks use legitimate tools (PowerShell, remote management software) that signature-based detection ignores entirely. EDR monitors behaviour: what programs are doing, not just what they look like.
Email security
The question: “Are SPF, DKIM, and DMARC configured? Do you use advanced threat protection?”
What they want to hear: All three email authentication protocols configured and enforced, with an advanced filtering solution that catches phishing, impersonation, and malicious attachments.
Why this matters: Email remains a common route for impersonation and credential attacks against professional firms. If your domain does not have an effective DMARC policy, attackers may be able to send convincing messages that appear to come from your firm, including fraudulent invoice instructions.
Incident response
The question: “Do you have a documented and tested incident response plan?”
What they want to hear: A written plan that’s been tested within the last 12 months, with defined roles, communication procedures, and contact details for your IT provider, legal counsel, and insurance broker.
The FIIG lesson: The Federal Court noted that FIIG had no tested incident response plan. When the breach occurred, they didn’t start investigating for six days after being notified. A $2.5 million penalty followed. Your insurer will ask about this because they know that slow response means bigger claims.
Security awareness training
The question: “Do all staff complete regular cyber security training?”
What they want to hear: Mandatory training for all staff, at least annually, with phishing simulations.
The hidden question: They’re really asking whether your staff will click a phishing link and hand over credentials. Because if they will, and nobody’s taught them not to, the underwriter is pricing in a near-certain claim.
The warranty problem
Here’s what most firms don’t realise: your answers on the proposal form become warranties in the policy. If you say “yes” to MFA and you don’t actually have it enforced for all users, your insurer can void the claim.
This isn’t theoretical. Australian insurers have denied claims on the basis of material misrepresentation in proposal forms. If you tick “yes” to questions you’re not sure about, you’re not getting insurance. You’re getting a false sense of security that evaporates the moment you make a claim.
Your M365 Secure Score is your compliance score
Every question on a cyber insurance proposal maps to a Microsoft 365 security control. Your Secure Score, a free dashboard in every M365 tenant, measures exactly the controls insurers are asking about:
| Insurance question | M365 control | Secure Score action |
|---|---|---|
| MFA enabled? | Conditional Access + Authenticator | Enable MFA for all users |
| Legacy auth blocked? | Conditional Access policy | Block legacy authentication |
| Admin accounts limited? | Role-Based Access Control | Reduce Global Admins to 2-4 |
| Email auth configured? | Exchange Online DNS records | Configure SPF, DKIM, DMARC |
| External sharing controlled? | SharePoint admin settings | Restrict “Anyone” links |
| DLP policies active? | Microsoft Purview | Enable DLP across all workloads |
| Audit logs retained? | Compliance centre | Set retention to 18+ months |
Secure Score can help identify configuration gaps, but it is not a compliance certificate and there is no universal percentage that satisfies insurers. Treat the score as one input; answer the insurer’s actual control questions and retain evidence for each answer.
How to prepare for your renewal
- Check your Secure Score today. Log into security.microsoft.com and look at your score. If it’s below 60%, you have material gaps that will affect your premium or your coverage.
- Answer the proposal form honestly. If you’re not sure whether MFA is enforced for all users, check before you tick yes. A claim denied for misrepresentation costs infinitely more than a higher premium.
- Fix the quick wins first. MFA, legacy auth blocking, admin account reduction, and email authentication can all be configured in a day. These are the controls that move your score and your insurability the most.
- Document everything. When you make changes, record the date, what was changed, and who approved it. If you need to prove to an insurer that controls were in place at the time of an incident, “we think we turned that on” isn’t evidence.
- Get an independent assessment. Your broker can tell you what the underwriter wants. Your IT provider should be able to tell you whether you actually have it.
Our cyber compliance work helps firms prepare for cyber-insurance renewals by checking the technical controls in the application and assembling supporting evidence. Better controls may affect an insurer’s decision, but pricing and coverage remain decisions for the insurer and licensed broker.
If your renewal is coming up and you’re not confident in your answers, book a conversation. We’ll review your Secure Score, map it against a standard proposal form, and tell you exactly where the gaps are. Straight answer, no surprises.
Your cyber insurance application isn’t a formality. It’s the most honest security assessment your firm will face all year. Make sure your answers hold up.
Need to prove where you stand?
Compare Essential Eight, SMB1001 and DISP side by side, and see the evidence each one expects you to produce.
More on this: Compliance articles · Cyber Compliance