Cyber Insurance Requirements for Australian Small Businesses — MFA, EDR & Backups Checklist

    Cyber insurers in Australia commonly ask small businesses, in their application and renewal questionnaires, to show a baseline of security controls — typically multi-factor authentication (MFA), endpoint detection and response (EDR) on every device, and tested offline or offsite backups. The exact requirements differ between insurers and policies, so confirm them with your broker or insurer. CyberOM Australia helps small businesses put these controls in place and document them through its managed security service.

    Last updated:

    Why do insurers ask about security controls?

    Insurers use the questionnaire to understand how likely and how costly an incident would be, and they may review the answers again at renewal. Answering accurately matters, so it helps to know which controls you actually have.

    Which controls appear on the checklist?

    The controls below are the ones commonly raised in cyber insurance questionnaires. Several of them — multi-factor authentication, patching and regular backups — are also Essential Eight strategies.

    Cyber insurance controls checklist
    ControlWhat questionnaires commonly askHow CyberOM can help
    Multi-factor authentication (MFA)Is MFA enforced on email, cloud, remote access and admin accounts?vCISO advisory to review MFA coverage; MFA itself is set in your identity provider
    Endpoint detection and response (EDR)Is EDR installed on every endpoint, and are alerts monitored 24/7?Managed EDR/XDR monitored 24/7 through the group's central SOC & MDR hub (Tier-3), DIAMATIX
    BackupsAre backups kept offsite or offline, and are restores tested?Microsoft 365 security and backup with Acronis
    Email securityAre SPF, DKIM and DMARC in place, with phishing filtering?Email security with Perception Point and Sendmarc
    PatchingAre operating systems and applications patched promptly?vCISO advisory; see the Essential Eight page
    Incident response planIs there a documented escalation and response process?24/7 SOC & MDR response and vCISO advisory
    Essential Eight alignmentCan you show which Essential Eight strategies are implemented?See /warranty-auessentialeight

    Requirements differ by insurer and policy. Confirm the exact questions with your broker or insurer.

    MFA — what are insurers checking?

    • MFA on email, cloud services such as Microsoft 365, remote access and administrator accounts
    • Authenticator apps or security keys are generally regarded as stronger than SMS codes
    • MFA is configured in your identity provider, for example Microsoft Entra ID for Microsoft 365
    • CyberOM's vCISO advisory can help you review where MFA is and is not enforced

    See CyberOM's Microsoft 365 email security service.

    EDR — what does "endpoint detection and response" mean on the form?

    • An EDR agent on laptops, desktops and servers, rather than signature-only antivirus
    • Questionnaires often ask whether EDR alerts are monitored around the clock
    • CyberOM's managed EDR/XDR is monitored 24/7 through the group's central SOC & MDR hub (Tier-3), DIAMATIX

    Read about managed EDR and CyberOM's SOC services.

    Backups — what counts as a good answer?

    The 3-2-1 approach means keeping three copies of data on two types of media, with one copy offsite. It also means keeping a copy that cannot be altered by an attacker and testing restores regularly. CyberOM provides Microsoft 365 security and backup with Acronis.

    What other controls are often asked about?

    CyberOM's Essential Eight page describes support through gap analysis, practical recommendations, implementation planning, monitoring and ongoing improvement. This helps organisations work towards alignment; it is not a certification or a guarantee of compliance.

    How does CyberOM help you prepare?

    • 24/7 SOC and MDR
    • EDR and XDR
    • Email security with Perception Point and Sendmarc (SPF/DKIM/DMARC)
    • Microsoft 365 security and backup with Acronis
    • vCISO advisory

    CyberOM is not an insurer or broker and cannot guarantee that a policy will be issued or a claim paid. It helps you implement and evidence controls. Published package prices are at cyberom.shop/packages, and the MDR pricing guide explains the published pricing model.

    Start with the free domain exposure check, or contact CyberOM Australia at office@cyberom.tech or +61 341 505 317.

    FAQs

    Frequently asked questions

    Ready to secure your business?

    Talk to our Australian team about managed security, 24/7 SOC coverage and a financial-backed warranty for your organisation.

    A short, no-obligation conversation. You will leave with a clear view of your next steps.

    Contact

    Talk to our Australian team

    Tell us what you are trying to protect and we will come back with clear, practical next steps.

    Send us a message

    A short form — fields marked with an asterisk are required.

    Your details are used to respond to your enquiry only and are never sold to third parties.