What your cyber insurer is really asking in the renewal questionnaire
The questionnaire reads like a checklist and gets answered like one — quickly, and sometimes optimistically. It is actually testing something more specific: whether you actually know what is true about your own environment.
The real test is not the questions
Whoever fills in a cyber insurance renewal questionnaire is usually the person with the least time to do it properly — an office manager, a finance lead, occasionally whoever answered the email first. The questions themselves have converged heavily across the Australian market over the last two renewal cycles, and most of them now map closely, whether the insurer names it or not, to the ASD Essential Eight: MFA, patching, backup, application control, administrative privilege.
The actual risk is not answering "no" to a question. Insurers price for organisations that say no and are telling the truth. The risk is answering "yes" inaccurately, because that is the answer that gets tested — during a claim, not during the renewal — and an inaccurate "yes" is the difference between a paid claim and a declined one.
MFA is no longer a question, it is a gate
Multi-factor authentication moved from "do you have it" to "is it enforced everywhere, including admin accounts and legacy protocols" across most Australian cyber policies some time ago, and it remains the single most common reason an application gets referred for further underwriting rather than approved outright. The specific trap: MFA enabled but not enforced tenant-wide, or enforced for standard users while a handful of legacy or service accounts are quietly excluded because something broke when it was turned on for them.
Answer this question from a configuration export, not from memory. "We use MFA" and "MFA is enforced for 100% of accounts including admins, with zero exclusions" are different claims, and only one of them is what the questionnaire is actually asking.
Why "do you back up" became "prove it restores"
Backup questions have gotten more specific for a specific reason: insurers have paid claims where an organisation genuinely believed their backups worked, discovered otherwise during a ransomware recovery, and the recovery cost — not the ransom — became the largest line item in the claim. Current questionnaires increasingly ask about immutability, offline or air-gapped copies, and restore testing frequency specifically, not just "do backups run."
If your honest answer to "when did you last test a full restore" is "we are not sure," that is worth fixing before the renewal, not during a claim.
Endpoint detection, and why "antivirus" is the wrong answer
Questionnaires increasingly distinguish between traditional antivirus and endpoint detection and response, and treat them as materially different controls — because they are. Signature-based antivirus catches known threats. EDR watches behaviour and can contain a compromised endpoint before it spreads, which is the capability insurers actually care about after several years of ransomware claims data.
If your questionnaire answer names a product rather than a capability, check what that product actually does before assuming it satisfies the question being asked.
The line that turns an inaccurate answer into a declined claim
Most cyber policies include a warranty clause: the answers in the application are treated as a condition of cover, not just background information. An inaccurate answer discovered during a claim — MFA that was not actually enforced everywhere, backups that had not actually been tested — can be treated as a breach of that warranty, which is a different and worse outcome than simply having weaker controls than a competitor with a cheaper premium.
This is general information about how these clauses commonly operate, not advice on your specific policy — read your own warranty and disclosure wording, or ask your broker to walk through it, before you sign the renewal.
How to actually prepare for the renewal
- Pull configuration evidence before you start answering — MFA coverage, backup test logs, patch compliance — rather than answering from what you believe is true.
- Assign the questionnaire to whoever actually knows the environment, with IT or your provider reviewing the technical sections before submission.
- Treat any "not sure" answer as a finding, not a blank to fill in with the more comfortable guess.
- Run an Essential Eight assessment on a cycle that lines up with your renewal, so the evidence is current when the questionnaire arrives rather than a year stale.
Questions
Does the Essential Eight guarantee my cyber insurance application is approved?
No single framework guarantees approval — underwriting considers your industry, claims history and specific answers too. It does give you a structured, evidenced way to answer the technical sections accurately, which is the part actually within your control.
Who should actually complete the technical sections of the questionnaire?
Whoever can produce evidence for each answer, not just an opinion. For most organisations that means IT or a managed provider completing or reviewing the technical sections, with the business owner or CFO handling the commercial ones.
What happens if we answer a question inaccurately by mistake, not deliberately?
Intent generally matters less than accuracy under a warranty clause — an honest mistake can still affect a claim outcome. That is precisely why pulling evidence before answering matters more than answering quickly.
This is general information about how cyber insurance questionnaires and warranty clauses commonly work, not advice on any specific policy. Read your own policy wording and speak to your broker or insurer about your obligations before renewing.
We complete the technical sections and stand behind the answers
An Essential Eight assessment gives you evidenced answers before the renewal arrives, not a scramble the week it is due.