SecureLoop
Cloud Security7 min read

Why Your Cyber Insurer Now Cares About the Essential Eight

Australian cyber insurers have quietly rewritten the rules. What they check before they'll cover you β€” and what they check before they'll pay a claim β€” now maps almost exactly to the Essential Eight. Here's what that means at your next renewal.

A few years ago, getting cyber insurance was easy. You filled in a short form, ticked some boxes about your security, and the policy turned up. Nobody checked. Then ransomware losses exploded, insurers paid out far more than they expected, and the whole market tightened almost overnight. The result is a very different environment in 2026 β€” and if you run a small business, it's worth understanding before your next renewal rather than after a declined claim.

Underwriting now maps to the Essential Eight

Here's the key thing: the security controls Australian cyber insurers assess line up closely with the Essential Eight. Most of the eight strategies β€” multi-factor authentication, patching applications and operating systems, tested backups, restricting admin privileges, application control β€” appear directly in underwriting questionnaires. For a small business, reaching Essential Eight Maturity Level One is generally enough to satisfy most insurers' baseline requirements.

One control is effectively non-negotiable: multi-factor authentication. Across the market, insurers now expect MFA on email and Microsoft 365 or Google Workspace, on remote access, and on privileged accounts. If you don't have it, cover becomes expensive or simply unavailable. (Exact requirements vary by insurer and cover level β€” this is the common pattern, not a universal rulebook.)

They no longer take your word for it

The biggest shift is that self-attestation β€” you ticking a box that says β€œyes, we have MFA” β€” is no longer enough for many underwriters. Major carriers increasingly verify what you declare, using external scans of your public-facing systems and third-party security data. Some run checks mid-policy, not just at application. The practical upshot: overstating your controls on the form doesn't just risk a higher-scrutiny application, it risks a declined claim later.

The honest advice every broker will give you: write down what's actually true. If MFA is on 80% of accounts, put 80%, not 100%. A slightly higher premium is cheaper than voided cover when a claim gets declined for misrepresentation.

Claims are being denied on control failures

This is the part that should focus the mind. A significant share of cyber claims are now denied β€” and the pattern is consistent: they're denied not because the incident was unforeseeable, but because it was preventable with controls the business said it had. A ransomware claim knocked back because the backups were never tested. A breach claim declined because MFA wasn't actually enforced. Insurance you can't claim on is an expensive false sense of security.

The Essential Eight controls are, in effect, the same controls that keep a claim payable. Getting them genuinely in place β€” not just declared β€” is what protects both your business and your cover.

The upside: it's cheaper, not just safer

There's a genuine silver lining. Because insurers price on evidence, a business that can document solid Essential Eight controls typically pays meaningfully less β€” reported differences of around 20–40% versus an equivalent business with nothing documented. That turns security spending into something partly self-funding: the money you put into getting MFA, backups and patching right comes back, in part, as lower premiums. A documented, independently-checked baseline carries far more weight with an underwriter than your own internal say-so.

What to do before your renewal

Start by finding out where you actually stand against the Essential Eight β€” honestly, the way an insurer would. Our free Essential Eight self-check gives you a plain-English maturity read in five minutes and flags your weakest control, which is usually the one an underwriter will pick up on too. For the Microsoft 365 side β€” where MFA and admin controls actually get configured β€” the free M365 security check goes deeper.

If the gaps need closing before renewal, that's our cloud security work β€” fixed price, and documented in a way you can hand to a broker. And if you're weighing up whether any of this applies at your size, we wrote a straight answer to β€œdo I need the Essential Eight if I only have six staff?”

General information for Australian small business as at July 2026, drawn from publicly reported 2026 cyber insurance market commentary. Insurer requirements, premiums and claim outcomes vary by carrier, cover level, industry and business size. This is not insurance, legal, or security advice β€” talk to a licensed broker about your specific cover.

Know what an underwriter would see

Check your Essential Eight maturity in five minutes β€” free, no signup β€” before your next renewal does it for you.

Brisbane QLD Β· Serving all of Australia Β· Fixed prices