Cyber insurance in Australia has changed in the past three years in ways that catch many SMBs off-guard at renewal time. The underwriting questionnaire that used to be a formality is now a detailed cyber controls audit, and the difference between an accepted quote and a declined one increasingly turns on the answers. Understanding what underwriters are actually looking for is the difference between a smooth renewal and an unpleasant surprise.

What changed

Between 2020 and 2023, cyber insurance underwriters in Australia and globally paid out significantly more than they collected, driven mostly by ransomware. The market corrected. Premiums rose sharply, coverage terms tightened, and underwriting standards became rigorous. In 2026 the market has largely stabilised, but the underwriting bar is higher than it was and appears unlikely to drop.

The practical implication for SMBs: the cyber controls the business actually has in place, at renewal time, materially determine whether the insurer offers cover, at what price, and with what exclusions.

The controls that show up on every questionnaire

Australian cyber insurance questionnaires in 2026 consistently probe the same set of controls. If your business has these documented and evidenced, most renewals go smoothly.

Multi-factor authentication. On email, on remote access, on privileged accounts, on cloud administrative consoles. Not we are working on it; MFA in place, evidence available.

Endpoint detection and response. Not just antivirus; a modern EDR product with either an internal SOC or a managed service watching alerts. Underwriters increasingly ask for the product name.

Immutable, tested backups. Backups that ransomware cannot delete or encrypt, and that have been demonstrably restored recently. A backup policy on paper is not sufficient; recent restore evidence is.

Patch management with defined SLAs. Critical patches applied within a specified window, tracked and evidenced.

Email security. Anti-phishing, DMARC alignment, sandboxing for attachments. This is the single most common attack vector and underwriters ask about it in detail.

Incident response plan. Documented, current, tested. The underwriter will often ask when it was last exercised.

User awareness training. Regular, tracked, with completion rates. Underwriters accept various vendors; they do not accept we send an email now and then.

The Essential Eight overlap

Underwriter questions map closely to the Essential Eight, and many now explicitly ask about Essential Eight maturity level. Businesses at ML1 or above on most of the Eight tend to sail through underwriting; businesses below ML1 face harder conversations, exclusions, or declines. The framework was not designed for insurance purposes, but it has effectively become the shared vocabulary.

Preparing for the questionnaire

The single most useful preparation for a renewal is to score your own posture in advance and address the obvious gaps. A free self-assessment like CyberSafeCheck maps to the Essential Eight and produces an evidenced score that closely mirrors the underwriter’s questionnaire structure. Running it four to six weeks before renewal gives you time to remediate the gaps that would otherwise cost you money or coverage.

Common declines and how to avoid them

The most common reasons for a 2026 cyber insurance decline: no MFA on privileged accounts; no EDR (still using traditional antivirus only); backups not tested in the past 90 days; no incident response plan; no awareness training program. Each of these is affordable to fix; the difficulty is discovering the gap before the underwriter does.

The bottom line

Cyber insurance is now a controls-driven product, not a checkbox one. Underwriters ask specific questions, expect specific evidence, and price the outcome accordingly. Preparation before renewal (self-assessment, gap remediation, evidence gathering) is the difference between a routine transaction and an expensive scramble. In 2026 Australia, businesses that treat their cyber controls as an insurance conversation as well as a security one see meaningfully better renewal outcomes.