The 12 questions insurers actually ask, your readiness score, and the gap list to fix first. Nothing is sent or stored.
Answer honestly; nothing is sent or stored. These are the questions cyber insurance proposal forms actually ask.
MFA on email is the first question on nearly every cyber insurance proposal form.
Remote access without MFA is a common reason for declined claims.
Insurers ask specifically about offline or immutable copies.
An untested backup is a hope, not a control, and assessors know it.
Running end-of-life systems like Windows 10 raises premiums or refusals.
Baseline expectation on every proposal form.
Human error drives most claims; insurers price for it.
Restricting admin privileges is an Essential Eight control insurers recognise.
Reused passwords turn one breach into many; assessors ask how passwords are managed.
An incident response plan, even one page, is increasingly required.
Social engineering / invoice fraud cover often depends on a call-back procedure.
You cannot protect or truthfully declare what you have not mapped.
Cyber insurance has changed: insurers now ask detailed questions about MFA, backups, patching and training before quoting, and weak answers mean higher premiums, excluded cover, or refusal. Worse, answers that turn out to be wrong can void a claim when you need it most. Working through the real questions before you apply, and fixing the gaps, gets you cheaper cover that will actually pay out.
The controls insurers ask about are largely the Essential Eight in different clothing, so closing insurance gaps and improving security are the same project. We implement these controls as part of managed IT. For the policy itself, talk to a specialist broker; cyber policies differ enormously in what social engineering and business interruption cover they include.
For most businesses holding customer data or invoicing electronically, yes, provided the controls insurers assume are actually in place. The premium is usually modest against the cost of an incident; Australians reported $2.18 billion in scam losses in 2025 alone.
At claim time, yes. If a proposal form said MFA was enabled everywhere and the breach walked through an account without it, the insurer can reduce or deny the claim. Answer accurately, and fix the gaps before you sign, not after.
MFA on email and remote access, working backups with an offline or immutable copy, supported and patched operating systems, endpoint protection, and some evidence of staff awareness. Beyond that, call-back procedures for payment changes are increasingly required for social engineering cover.
Through a broker rather than direct, for a policy this nuanced. A specialist broker can match cover to how your business actually operates, and we are happy to introduce you to the partner we recommend; what this tool gives you is honest answers for the proposal form and fewer surprises at claim time.
No tool can promise that; policies differ and insurers assess each business. A good score means you can answer the standard questions honestly and well, which is what drives both premium and claim reliability.