Cyber insurance used to be a backstop for almost anything. Submit a claim, get paid, move on. That era is over.
The NZ cyber insurance market has hardened significantly since 2020. Premiums have tripled on average. Underwriters have added technical questionnaires that rival a security audit. And insurers are investigating claims more thoroughly — often finding exclusions to deny coverage that policyholders didn't know were there.
If you have a cyber policy — or are considering one — here's what the market now requires.
What underwriters are asking before they quote
Two years ago, a cyber insurance application asked for your revenue, your industry, and whether you had antivirus. Today, the technical questionnaire typically covers:
Multi-factor authentication — Is MFA enabled on email (especially Microsoft 365 and Google Workspace)? On remote access (VPN, RDP)? On privileged accounts? Insurers are now declining to quote — or applying significant exclusions — for businesses without MFA on email.
Backup status — Do you have backups? Are they offline or isolated from your network? Have you tested restoration in the past 12 months? An insurer that discovers your backups were connected to the same network that was encrypted will contest a ransomware claim.
Endpoint detection — Do you run EDR (endpoint detection and response) rather than basic antivirus? This is increasingly a requirement for businesses above a certain premium threshold.
Patch management — Is your operating system and critical software patched and up to date? Breaches via known, unpatched vulnerabilities are increasingly being classified as preventable and excluded.
Security awareness training — Do your staff receive regular security awareness training? Increasingly yes, and with documentation. A phishing attack that succeeded because no training had occurred is an uncomfortable exclusion conversation to have post-breach.
Why claims are being denied
Marsh's 2023 Cyber Claims Report identified the most common grounds for claim denial or reduction:
- Material misrepresentation — The application said MFA was in place. The forensic investigation showed it wasn't on the specific accounts accessed.
- Prior known vulnerabilities — The breach exploited a vulnerability that had been publicly disclosed and patched months earlier. The insurer argued the business failed to take reasonable steps.
- War exclusions — Attacks attributed to state-sponsored actors have been increasingly contested under war exclusion clauses. The Lloyd's of London market updated its war exclusion language in 2023 specifically to address this.
- Failure to notify in time — Most policies require notification within 24–72 hours of discovering an incident. Businesses that waited — often hoping to handle it internally — found their claims complicated or voided.
What a solid cyber insurance posture looks like
The businesses that get paid when they claim share a common profile:
- MFA on all email, remote access, and privileged accounts
- Offline backups, tested in the past 12 months
- EDR on endpoints
- Current patches on operating systems and key applications
- Documented security awareness training for staff, with completion records
- An incident response plan — even a basic one — with CERT NZ's contact on it
That last point matters more than people expect. Insurers increasingly want to see that you had a plan before the incident, not that you figured it out afterwards.
The ACSC's information on cyber insurance is a useful primer on what to look for in a policy and how to compare coverage.
The staff training piece
Security awareness training now appears explicitly in underwriting questionnaires. But more importantly, staff training is what prevents the phishing attack that triggers the claim in the first place.
An insurer that investigates a breach and finds no training records has grounds to argue the loss was preventable. That's a much harder conversation than showing documented quarterly training with completion records.
For a practical breakdown of what that training should cover, see our guide on what a security awareness program is and whether you need one. SecureAZ gives you the training, the completion records, and the documentation your insurer — and your board — will want to see. Start free.