Cyber insurance in New Zealand has changed significantly in the last two years. What was once a relatively straightforward application — answer a few yes/no questions about firewalls and backups — has become a detailed security assessment. And increasingly, the question that decides your premium — or your eligibility — is about staff training.
Insurers are paying claims. They're seeing the data on what causes breaches. And the data is consistent: most incidents involve a human action — a clicked link, a transferred payment, a reused password. So they're asking harder questions about what you're doing to reduce that risk.
What insurers are actually asking
The application questions have evolved from "do you provide security awareness training?" to a much more specific set:
- How often is training completed? (Annual vs. quarterly vs. ongoing)
- Is training role-based, or the same content for all staff?
- Do you run phishing simulations? How often?
- What percentage of staff have completed training in the last 12 months?
- Do you have completion records?
- What happens when staff fail a phishing simulation?
These aren't rhetorical. Insurers use the answers to calculate risk. A business that runs quarterly simulations with documented completion rates is statistically less likely to suffer a successful BEC or ransomware attack than one that sends a PDF once a year.
What "approved" training means in practice
There's no formal NZ certification scheme that designates a training programme as "approved." When insurers use that language, they mean training that meets certain minimum criteria — and those criteria vary by insurer. Generally, they're looking for:
Regularity — Training delivered at least annually, with evidence of ongoing reinforcement (simulations, newsletters, reminders). A once-every-two-years all-staff session typically won't satisfy the question.
Coverage — All staff, not just technical roles. Finance staff, receptionists, and site managers are as likely to be targeted as IT teams. Some insurers specifically ask about training coverage by department.
Content relevance — Training that covers the current threat landscape: BEC, invoice fraud, credential phishing, smishing. Generic "don't click bad links" content from 2019 won't satisfy an underwriter who's seen the claims data.
Simulation — Many insurers now treat phishing simulation as a separate, mandatory question. Running simulations at least quarterly is the threshold that most put between standard and preferred risk.
Documentation — Completion certificates, training records, and simulation results that you can produce on request. If you can't show it happened, the underwriter treats it as if it didn't.
What happens when you can't demonstrate training
The consequences range from a higher premium to an outright exclusion — or a denied claim. The specific risk is in the policy wording around "reasonable precautions" and "failure to maintain controls." If your policy requires you to maintain a security awareness training programme, and a breach occurs because an employee fell for a phishing attack, and you can't show the employee received relevant training — that's a basis for declining the claim.
This isn't hypothetical. CERT NZ documents multiple NZ businesses that suffered significant BEC losses in circumstances where basic awareness training would likely have prevented the incident.
How to build a training record that satisfies insurers
The documentation requirement is specific. When you renew your policy or file a claim, you need to be able to show:
- A training programme with named modules — Not "we do cybersecurity training" but "we deliver X modules covering phishing, BEC, password security, and incident reporting"
- Completion records by staff member — Name, role, module, date, pass/fail
- Phishing simulation results — Frequency, template types used, click rates over time
- Follow-up training records — Evidence that staff who failed simulations received remediation
- Policy acknowledgement sign-offs — Staff confirming they've read and understood your security policies
See our post on cyber insurance requirements for NZ businesses for a detailed breakdown of the full insurance application process and what other controls are now standard requirements.
What cyber insurance actually covers when training is in place
When you can demonstrate a documented training programme, you're not just satisfying an underwriter — you're positioning the organisation as a lower risk. Tangible outcomes include:
- Reduced premiums — Documented training with simulation results is a direct input to risk scoring
- Fewer exclusions — Policies for organisations with documented controls tend to have fewer carve-outs for "preventable" incidents
- Coverage confidence — If an incident occurs despite documented training, you're in a much stronger position to demonstrate you took reasonable precautions
SecureAZ is designed specifically for this purpose — awareness training built for NZ businesses, with phishing simulation, role-based modules, and automatic completion records you can export for your insurer. Start a free trial and have your first training programme live within a day.