If you’re preparing for your cyber insurance renewal, you’ll notice the application asks far more questions than it did a few years ago.
Insurers now ask far more detailed questions because ransomware, software supply chain attacks and AI-powered scams have become more frequent and more expensive. Before they provide cover, they want evidence that your business has the right cybersecurity controls in place.
For many Australian businesses, it’s no longer enough to simply tick “yes” to having antivirus software or backups. Your insurer wants to know how your business is protected, whether those protections are tested, and if they would still work during a real cyberattack.
This increased scrutiny reflects the growing financial impact of cyber incidents. According to IBM’s Cost of a Data Breach Report, the global cost of responding to a data breach remains significant for organisations worldwide.
At the same time, the Australian Cyber Security Centre (ACSC) continues to receive thousands of cybercrime reports each year, highlighting the ongoing threat facing Australian businesses. As cyber threats continue to evolve, insurers are placing greater emphasis on businesses demonstrating strong cybersecurity controls before providing cover.
Here at Microsavvy, we regularly help businesses across the Sunshine Coast and Brisbane improve their cybersecurity before renewing their cyber insurance through our Cybersecurity Services. Understanding what insurers are looking for can help you avoid higher premiums, exclusions or even having a future claim denied.
Why Your Cyber Insurance Renewal Is More Detailed Than Ever
Cyber insurance applications have evolved because attackers have changed the way they operate.
Over the past few years, several high-profile cyber incidents highlighted weaknesses in backup systems, identity security, software supply chains and payment processes. These incidents prompted insurers to review the questions they ask businesses before offering cover.
Cyber insurance renewals have changed significantly over the past few years. The table below highlights how insurers’ expectations have evolved.
| A Few Years Ago | Today |
|---|---|
| Antivirus software | Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) |
| Basic backups | Immutable or air-gapped backups |
| Passwords | Multi-factor authentication (MFA) |
| Simple yes/no review | Evidence that security controls are in place |
| Annual security review | Continuous cybersecurity management and monitoring |
Many of these controls align with the Australian Cyber Security Centre’s (ACSC) Essential Eight, which outlines practical strategies to help organisations reduce cyber risk.
Instead of asking broad questions, insurers now focus on specific security controls, including:
- Multi-factor authentication (MFA)
- Backup protection
- Endpoint Detection and Response (EDR)
- Managed Detection and Response (MRD)
- Vendor security
- Incident response planning
- Wire transfer approval processes
The better you can demonstrate these controls, The easier your renewal process is likely to be.
1. Cyber Insurance Renewal Questions About Backups
One of the biggest cyber insurance renewal changes involves backups.
Many businesses believe Microsoft 365 or nightly backups protect them. Unfortunately, that’s no longer enough.
Many businesses also assume Microsoft 365 automatically backs up all their data. While Microsoft provides built-in resilience and retention features, but organisations remain responsible for protecting and recovering their own data and ensuring it can be recovered if it’s accidentally deleted, encrypted by ransomware or affected by a cyber incident.
Cybercriminals now commonly target backup systems before deploying ransomware. If attackers can delete or encrypt your backups, recovery becomes far more difficult.
That’s why insurers now look beyond whether you have backups. They’re increasingly asking questions such as:
- Are your backups immutable or air-gapped?
- Have you tested restoring data within the past 12 months?
- Can administrator accounts delete your backups?
Immutable backups prevent anyone from changing or deleting data during a defined retention period, even if an attacker gains administrator access.
This add another layer of protection during a ransomware attack.
Regular restoration testing is equally important. A backup is only valuable if you know it can be restored when you need it most.
You can’t rely on an untested backup during an emergency.
Testing and monitoring your backups should be part of your regular cybersecurity routine, not something you only think about when it’s time to renew your insurance.
A proactive Managed IT Services provider can regularly test your backups, monitor your systems and help ensure you can recover quickly if a cyber incident occurs. Businesses that use secure Business Cloud Solutions, including immutable backups, are often better placed to recover from ransomware and other cyber incidents.
2. Cyber Insurance Renewal Questions About Multi-Factor Authentication
When reviewing your application, insurers want evidence that multi-factor authentication protects every critical account.
They want to know whether MFA protects:
- Microsoft 365
- Email accounts
- Remote desktop access
- VPN connections
- Administrator accounts
- Privileged accounts
If administrator accounts remain unprotected, cybercriminals may still gain complete control of your environment.
Many insurers also prefer authenticator apps or hardware security keys over SMS verification because text messages are more vulnerable to interception and SIM swapping.
Reviewing your MFA settings before renewing your policy can significantly strengthen your application.
3. Cyber Insurance Renewal Questions About EDR and MDR
Another common cyber insurance renewal question focuses on endpoint protection.
Modern attacks often behave differently to avoid detection.
That’s why insurers increasingly ask whether your business uses Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) solutions.
EDR continuously monitors devices for suspicious behaviour and helps detect attacks much earlier than traditional antivirus.
MDR goes a step further by providing a security team that monitors alerts around the clock and responds when suspicious activity occurs.
For many insurers, having EDR or MDR in place demonstrates a much stronger security posture than relying on antivirus alone.
4. Cyber Insurance Renewal Questions About AI Fraud
Artificial intelligence has made social engineering attacks more convincing than ever.
Cybercriminals can now create realistic emails, voice recordings and even video calls that appear to come from senior executives or trusted suppliers.
As a result, insurers are asking more questions about payment approvals.
They may ask whether your business:
- Uses callback verification for bank transfers
- Requires dual approval for large payments
- Has documented payment approval procedures
- Trains employees to recognise AI-generated scams
A simple phone call to a verified contact before transferring funds can prevent significant financial losses.
Even with strong technical security, staff awareness remains one of the most effective defences against business email compromise, payment fraud and deepfake scams.
5. Cyber Insurance Renewal Questions About Vendor Security
Your cyber insurance renewal may also ask about your software vendors and third-party suppliers.
Some of the most damaging cyber incidents now originate through trusted software providers or third-party vendors.
Because of this, insurers increasingly ask businesses about vendor risk management.
They may want to know:
- Which suppliers store your sensitive information?
- Do your software vendors have recognised security certifications?
- Have you assessed their cybersecurity practices?
Understanding who has access to your data is becoming an essential part of maintaining cyber insurance cover.
Answer Your Cyber Insurance Renewal Honestly
One of the biggest mistakes businesses make is overstating their cybersecurity.
For example, if your application states that every administrator account is protected by multi-factor authentication, but an investigation after a cyber incident finds that several privileged accounts were left unprotected, your insurer may question whether the information you provided was accurate. Depending on the terms of your policy and the circumstances of the claim, this may affect your level of cover or the outcome of your claim.
This may lead to what’s known as rescission. In some circumstances, an insurer may treat the policy as though it never existed because the information provided during the application was inaccurate.
While every policy differs, inaccurate answers can lead to denied claims, reduced payouts or higher premiums.
If you’re still improving a security control, it’s generally better to explain what is currently in place and outline your planned improvements than to claim the work has already been completed.
A Simple Cyber Insurance Renewal Checklist
Before you submit your cyber insurance renewal, take a few minutes to review your cybersecurity controls. Identifying any gaps now is much easier than discovering them after a cyber incident.
Before you renew, check that you can answer “yes” to the following questions:
- Is MFA enabled on every critical account?
- Are backups immutable or securely isolated?
- Have backups been successfully restored during testing?
- Is EDR or MDR protecting every device?
- Does your business have an incident response plan?
- Are staff trained to identify phishing and AI scams?
- Do payment approvals require independent verification?
- Have you reviewed the security of your key suppliers?
Completing this checklist before renewal can strengthen your security while improving your chances of obtaining the right level of cover.
Final Thoughts
Cyber insurance is no longer just about completing a form each year. Insurers want evidence that your business actively manages cyber risk.
Reviewing your Microsoft 365 security, backups, identity protection and endpoint security before renewal can identify gaps early and help you complete your application with greater confidence.
At Microsavvy, we help businesses across the Sunshine Coast, Brisbane and throughout Australia strengthen their cybersecurity before renewal.
If you’d like an independent review before your next cyber insurance renewal, contact Microsavvy to discuss how we can help.
If you’d like an independent review before your next renewal, contact Microsavvy to discuss how we can help strengthen your cybersecurity and prepare your business with confidence.
Frequently Asked Questions
Why are cyber insurance renewal applications becoming longer?
During your cyber insurance renewal, insurers now require more detailed information because cyberattacks have become more frequent and more costly. They want to understand how well your business is protected before providing cover.
What is an immutable backup?
An immutable backup cannot be modified or deleted for a specified period, even if an attacker gains administrator access. This makes it far more resilient against ransomware.
Is antivirus enough for cyber insurance?
In many cases, no. Many insurers now expect businesses to use Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) alongside traditional antivirus.
Does cyber insurance cover ransomware?
Many policies include ransomware cover, but the level of protection varies between insurers. Most insurers now expect businesses to have controls such as MFA, immutable or isolated backups, and Endpoint Detection and Response (EDR) or Managed Detection and Response (MDR) before offering cover.
Can inaccurate answers affect my insurance claim?
Yes. Providing incorrect information about your cybersecurity controls could result in reduced cover or a denied claim if those controls are found to be missing after an incident.
How can Microsavvy help?
Microsavvy can review your Microsoft 365 environment, backup strategy, endpoint security, multi-factor authentication and cybersecurity controls to help your business prepare for cyber insurance renewal with greater confidence.


