If you've filled out a cyber insurance application recently, or tried to, you've probably noticed the questionnaire has gotten a lot longer and a lot more specific than it used to be. Insurers aren't just asking "do you have antivirus" anymore. They want to know about multi-factor authentication, backup testing, admin privilege restrictions and patching timeframes, and increasingly, they're mapping those questions directly to the Essential Eight, the Australian Signals Directorate's baseline cyber security framework.
The same shift is happening in government tenders, professional services panels and larger clients' vendor security questionnaires. Whether or not Essential 8 alignment is legally required for your business, it's fast becoming the language everyone else uses to decide whether you're insurable, or workable with.
Why Insurers Care About This Specifically
Cyber insurers pay claims when businesses get breached, and certain gaps predict breaches with remarkable consistency: no multi-factor authentication, unpatched software, staff with more admin access than they need, and backups that were never actually tested. These are, not coincidentally, exactly what the Essential Eight addresses. Rather than build their own bespoke checklist, most insurers now simply ask where you sit against an established framework they already trust.
๐ก A growing number of insurers now offer more favourable premiums or excess terms for businesses that can demonstrate a specific Essential 8 Maturity Level, and some are starting to decline cover or add exclusions for businesses that can't show basic alignment at all.
What "Alignment" Actually Means
The Essential Eight isn't pass/fail, it's a four-level maturity model from Level 0 (not aligned) through to Level 3 (protection against sophisticated, well-resourced adversaries). Most small and medium Melbourne businesses realistically target Maturity Level 1 as a baseline, moving to Level 2 if they handle sensitive client data, work with government, or face specific tender or insurance requirements. Very few SMBs need Level 3, that's aimed at organisations facing nation-state-level threats.
| Strategy | What It Covers |
|---|---|
| Application control | Only approved software can run on business devices |
| Patch applications | Known vulnerabilities in software are fixed within set timeframes |
| Configure Microsoft Office macros | Malicious macros, a common ransomware entry point, are blocked |
| User application hardening | Browsers and apps are locked down against common exploit techniques |
| Restrict admin privileges | Staff and accounts only have the access they actually need |
| Patch operating systems | Known OS vulnerabilities are fixed within set timeframes |
| Multi-factor authentication | MFA is enforced on email, remote access and privileged accounts |
| Regular backups | Backups are taken, tested, and restorable when it actually matters |
An insurer or auditor doesn't take your word for where you sit. A genuine assessment tests actual configuration, not self-reported answers on a form, which is exactly where most businesses get caught out: they believe they're compliant based on what was set up years ago, without knowing whether it's still configured correctly today.
The Gaps That Trip Businesses Up Most Often
- MFA that's "available" but not enforced, turned on for some accounts and quietly skipped for others, especially older or executive accounts
- Backups that have never been test-restored, so nobody actually knows if they'd work in a real incident
- Admin rights handed out generously years ago and never reviewed since
- Patching that happens "eventually" rather than within a defined, tracked timeframe
- No written record of any of the above, meaning even when the technical control exists, there's nothing to show an insurer or auditor
That last point matters more than most business owners expect. Insurers and auditors want evidence, not assurances. A control that exists but was never documented is, from an application's point of view, indistinguishable from a control that doesn't exist at all.
What to Do Before Your Next Application or Renewal
-
1
Get an actual maturity assessment, not a guess Have someone test your real configuration against each of the eight strategies rather than relying on memory of what was set up at some point in the past.
-
2
Fix the cheap, high-impact gaps first Enforcing MFA everywhere and tightening admin privileges are usually fast to fix and carry a lot of weight with insurers, before you tackle longer projects like macro hardening.
-
3
Actually test-restore a backup Not just check that a backup job "completed successfully." Restore a real file or system and confirm it works, then document that you did.
-
4
Keep a written record as you go A simple report showing your current maturity level per strategy, with dates, is what turns "we think we're fine" into something you can actually hand an insurer or tender panel.
-
5
Consider a recognised certification for SMBs Frameworks like SMB1001 are specifically scaled for small and medium businesses and give you a portable, third-party-verified answer to hand to insurers and clients instead of re-explaining your setup every time.
The Bigger Picture
None of this is really about satisfying a form. The controls insurers ask about are the same ones that meaningfully reduce your odds of a serious incident in the first place, insurance readiness and actual security posture point in the same direction. Treating an Essential 8 assessment as a one-off box-tick misses the point; it needs to be maintained as your systems, staff and the threat landscape change, which is exactly why it shows up as an annual renewal question rather than a one-time form.
Not sure where your business actually sits against the Essential Eight, or want a written assessment ready before your next insurance renewal or tender? BITS tests your real configuration against each strategy and gives you a clear roadmap. Book a free consultation and we'll tell you exactly where you stand.