Cyber insurance has quietly changed. A few years ago you filled in a form and got a certificate. Today insurers ask detailed questions about your security controls — and when a claim lands, they check whether your answers were true. The uncomfortable industry reality: policies respond to the security you actually had on the day, not the security you intended to have.
Why insurers got strict
The losses are real and rising. New Zealand’s National Cyber Security Centre recorded $26.9 million in direct financial losses reported in the 2024/25 year across nearly 6,000 incidents — and one quarter of 2025 alone saw $12.4 million, driven largely by business email compromise: attackers getting into email, sending fake invoices, and redirecting payments. Insurers responded the way insurers do — by pricing risk properly and scrutinising claims.
The questions that decide your claim
Most proposal forms now ask some version of: Is multi-factor authentication enforced for all users, including remote access? Are backups separated from your network, and have you tested restoring them? Are systems patched within a defined window? Do you run modern endpoint protection? Is there security awareness training? Answer “yes” to get the premium down, and that yes becomes part of the contract. If an incident reveals the control was not actually in place — MFA “mostly” enforced, backups never test-restored — you have given the insurer grounds to reduce or decline the claim precisely when you need it most.
The fix is unglamorous
Make the answers true. The controls insurers demand are the same ones that stop most incidents in the first place — the NCSC notes that many breaches still succeed through basics: unpatched systems, reused passwords, exposed remote access. Close those and you win twice: fewer incidents, and a policy that pays if one gets through anyway.
Where to start
Take our free 12-question Security Health Check — it maps closely to what insurers ask, and gives instant feedback on where you stand. Or read how we build insurance-ready security with evidence your broker can actually use. If you would rather just talk to a human first, we are easy to reach.
Want this handled properly? Talk to us about Cybersecurity.


