Is Your IT Provider Putting Your Cyber Insurance at Risk?
Australian cyber insurers no longer take your application at face value. What decides a claim is whether the controls you declared were genuinely implemented, and still working, on the day of the incident - MFA, EDR, tested backups, a documented incident response plan, DMARC/SPF/DKIM, patching under 30 days, security awareness training. Claims come unstuck when those were ticked on a form but never maintained by the IT provider. If you have never been asked to prove they are in place, that is worth checking before you need to make a claim, not after.
The controls insurers actually check
Multi-factor authentication (MFA) enforced across email, remote access and admin accounts
Endpoint Detection and Response (EDR), not just legacy antivirus
Regularly tested backups — not just backups that run, but ones proven to restore
A documented, rehearsed incident response plan
DMARC, SPF and DKIM enforced on your email domain to stop spoofing
Patch management with critical patches applied inside 30 days
Regular staff security awareness training
How SSDL Helps
Most businesses don’t find out their controls are inadequate until a claim gets denied. SSDL offers a free cyber insurance readiness review: we check your current setup against what insurers actually verify, tell you plainly where the gaps are, and give you a clear, prioritised plan to close them. If you already work with SSDL, this is folded into our existing Cybersecurity service. If you don’t, it’s a no-obligation way to see exactly where you stand before your next renewal or claim.
Call 1300 364 722 or book a free cyber insurance readiness review before your next renewal.
Cyber Insurance FAQs
-
Because insurers now verify the controls declared on the application rather than taking them on trust. The most common reason for denial is that a control the business said was in place, most often multi-factor authentication, was not fully enforced across every account at the time of the incident. Other claims fall outside the policy’s conditions because backups were never tested or patching had slipped.
-
MFA enforced across email, remote access and admin accounts; EDR rather than legacy antivirus; regularly tested (not just running) backups; a documented and rehearsed incident response plan; DMARC, SPF and DKIM enforced on your email domain; patching within 30 days for critical vulnerabilities; and regular staff security awareness training.
-
Many businesses assume so, but few have ever asked for proof. If you’ve never been shown documented evidence of MFA enforcement, backup restore testing, or a rehearsed incident response plan, that’s worth checking now, not at claim time. SSDL’s free readiness review gives you a plain-language answer either way.
-
Yes, no obligation. We review your current controls against what insurers actually check, explain any gaps in plain language, and give you a prioritised plan. If you decide to act on it with SSDL, great; if not, you still walk away knowing exactly where you stand.
-
Yes. The readiness review works whether or not you switch providers afterwards. Many businesses use it simply to understand where they stand before a renewal, and decide what to do about it from there.
-
The readiness review is part of SSDL’s broader Cybersecurity service. Once we know where your gaps are, we can implement the missing controls, whether that’s MFA rollout, EDR deployment, backup testing, or building your incident response plan, so you’re actually covered, not just compliant on paper.