Cyber Insurance Requirements for Australian Small Businesses — MFA, EDR & Backups Checklist
Cyber insurers in Australia commonly ask small businesses, in their application and renewal questionnaires, to show a baseline of security controls — typically multi-factor authentication (MFA), endpoint detection and response (EDR) on every device, and tested offline or offsite backups. The exact requirements differ between insurers and policies, so confirm them with your broker or insurer. CyberOM Australia helps small businesses put these controls in place and document them through its managed security service.
Last updated:
Why do insurers ask about security controls?
Insurers use the questionnaire to understand how likely and how costly an incident would be, and they may review the answers again at renewal. Answering accurately matters, so it helps to know which controls you actually have.
Which controls appear on the checklist?
The controls below are the ones commonly raised in cyber insurance questionnaires. Several of them — multi-factor authentication, patching and regular backups — are also Essential Eight strategies.
| Control | What questionnaires commonly ask | How CyberOM can help |
|---|---|---|
| Multi-factor authentication (MFA) | Is MFA enforced on email, cloud, remote access and admin accounts? | vCISO advisory to review MFA coverage; MFA itself is set in your identity provider |
| Endpoint detection and response (EDR) | Is EDR installed on every endpoint, and are alerts monitored 24/7? | Managed EDR/XDR monitored 24/7 through the group's central SOC & MDR hub (Tier-3), DIAMATIX |
| Backups | Are backups kept offsite or offline, and are restores tested? | Microsoft 365 security and backup with Acronis |
| Email security | Are SPF, DKIM and DMARC in place, with phishing filtering? | Email security with Perception Point and Sendmarc |
| Patching | Are operating systems and applications patched promptly? | vCISO advisory; see the Essential Eight page |
| Incident response plan | Is there a documented escalation and response process? | 24/7 SOC & MDR response and vCISO advisory |
| Essential Eight alignment | Can you show which Essential Eight strategies are implemented? | See /warranty-auessentialeight |
Requirements differ by insurer and policy. Confirm the exact questions with your broker or insurer.
MFA — what are insurers checking?
- MFA on email, cloud services such as Microsoft 365, remote access and administrator accounts
- Authenticator apps or security keys are generally regarded as stronger than SMS codes
- MFA is configured in your identity provider, for example Microsoft Entra ID for Microsoft 365
- CyberOM's vCISO advisory can help you review where MFA is and is not enforced
See CyberOM's Microsoft 365 email security service.
EDR — what does "endpoint detection and response" mean on the form?
- An EDR agent on laptops, desktops and servers, rather than signature-only antivirus
- Questionnaires often ask whether EDR alerts are monitored around the clock
- CyberOM's managed EDR/XDR is monitored 24/7 through the group's central SOC & MDR hub (Tier-3), DIAMATIX
Read about managed EDR and CyberOM's SOC services.
Backups — what counts as a good answer?
The 3-2-1 approach means keeping three copies of data on two types of media, with one copy offsite. It also means keeping a copy that cannot be altered by an attacker and testing restores regularly. CyberOM provides Microsoft 365 security and backup with Acronis.
What other controls are often asked about?
- Email authentication and filtering using SPF, DKIM and DMARC
- Patching of operating systems and applications
- An incident response plan or documented escalation process
- Essential Eight alignment
CyberOM's Essential Eight page describes support through gap analysis, practical recommendations, implementation planning, monitoring and ongoing improvement. This helps organisations work towards alignment; it is not a certification or a guarantee of compliance.
How does CyberOM help you prepare?
- 24/7 SOC and MDR
- EDR and XDR
- Email security with Perception Point and Sendmarc (SPF/DKIM/DMARC)
- Microsoft 365 security and backup with Acronis
- vCISO advisory
CyberOM is not an insurer or broker and cannot guarantee that a policy will be issued or a claim paid. It helps you implement and evidence controls. Published package prices are at cyberom.shop/packages, and the MDR pricing guide explains the published pricing model.
Start with the free domain exposure check, or contact CyberOM Australia at office@cyberom.tech or +61 341 505 317.
FAQs
Frequently asked questions
Ready to secure your business?
Talk to our Australian team about managed security, 24/7 SOC coverage and a financial-backed warranty for your organisation.
A short, no-obligation conversation. You will leave with a clear view of your next steps.
Contact
Talk to our Australian team
Tell us what you are trying to protect and we will come back with clear, practical next steps.
Send us a message
A short form — fields marked with an asterisk are required.
