Insights

What Australian Cyber Insurers Are Actually Demanding in 2026

What Australian Cyber Insurers Are Actually Demanding in 2026

Essential 8, endpoint detection, incident response plans — here’s the checklist insurers are using to set premiums (and deny coverage).

Your renewal notice lands. You open it. The number staring back at you is three times what you paid last year.

For a mid-market Australian retailer or logistics operator, this isn’t a hypothetical. It’s 2026 — and cyber insurance premiums for mid-market businesses have risen 60 to 200 per cent year-on-year, according to the Insurance Statistics Industry Group (ISIG).

Retail and logistics are the two highest-risk sectors on the Australian cyber insurance market. Insurers have stopped treating them gently.

The days of a five-page questionnaire and a quick renewal are over. Insurers — Chubb, AIG, QBE, Zurich, Marsh — now run structured Evidence of Minimum Effectiveness (EME) submissions on every mid-market policy.

If you can’t demonstrate specific controls, you’re not facing a higher premium. You’re facing a denial of coverage.

Here’s what they’re actually checking — and what it means for your business.

Australian cyber insurance requirements checklist 2026

Why is Essential 8 the first question on every application?

Two years ago, Essential 8 was a government framework most mid-market operators had never heard of. Today, it’s the first question on every cyber insurance application.

Insurers are asking pointed, specific questions:

  • Multi-factor authentication: “Have you implemented MFA on all internet-facing services?”
  • Patching: “Are you patching critical vulnerabilities within 48 hours of release?”
  • Privilege restriction: “Do you restrict administrative privileges to named individuals?”

For a retailer with 60-plus store locations, answering “yes” to all three requires visibility and control across every POS terminal, every in-store server, every backend system — and someone whose full-time job is knowing the answer.

Most mid-market operators don’t have that person. They have one or two IT generalists stretched across helpdesk, network and vendor management.

Essential 8 gaps surface at renewal — when the insurer finds them first. And across sixty locations, closing those gaps isn’t a weekend project. It’s a structural capability gap.

Related reading: Start with the framework insurers check first. Our ASD Essential 8 Compliance: A Security Checklist walks through every control step by step.

Is antivirus still enough — or do insurers want EDR?

Insurers in 2026 are no longer accepting “we run antivirus” as a security control. They’re asking for Endpoint Detection and Response (EDR): 24/7 endpoint monitoring, real-time threat detection, automated containment.

Why? Because attackers have moved beyond signature-based malware. Ransomware operators now run living-off-the-land attacks using legitimate tools already installed on your systems.

Traditional antivirus doesn’t catch it. EDR does.

For a multi-site retailer, endpoint surface area is the multiplier. Fifty stores, each with multiple POS terminals, back-office workstations and manager laptops. One compromised endpoint is all it takes.

Insurers know this — and they’re pricing accordingly.

Add e-commerce and the surface grows again. Online platforms run on a shared responsibility model: your business owns the endpoints, access controls and data handling; the platform owns the infrastructure. Insurers want EDR coverage across the entire estate — stores, back office, warehouse and head office.

What does an incident response plan need to prove?

Insurers aren’t just asking whether you have an incident response plan. They’re asking when it was last tested.

The 2026 requirement: a written plan with named roles, internal and external communication protocols, data breach notification procedures — and evidence of a tabletop exercise within the last twelve months.

Most mid-market companies have a plan. Few have tested it. Fewer still can produce a test log.

Insurers are now asking for that log. A plan that hasn’t been exercised carries near-zero weight in underwriting decisions.

Add certification pressure — B Corp, ISO or other governance frameworks — and the compliance load compounds. Recertification audits demand data governance evidence; insurers demand Essential 8 evidence. The incident response plan is where both converge — and both demand proof it works.

Where do insurers draw the line on multi-factor authentication?

Insurers are no longer accepting “MFA on email”. They want it on everything internet-facing: M365, remote access VPNs, admin portals, POS backends, cloud infrastructure consoles.

The gaps that trip up mid-market operators are predictable. Retailers skip MFA on in-store POS systems because “it’s too hard for shift staff”. Logistics operators skip it on driver portals because “they’re in a truck with a scanner”.

Insurers in 2026 don’t accept either excuse. If it’s internet-facing and it processes business data, MFA is a condition of coverage.

Consider a logistics operator with hundreds of drivers, each carrying a handheld device or phone that connects to delivery systems. Every one of those devices is an endpoint an insurer wants authenticated, monitored and managed.

Rolling out MFA across a national depot network is genuinely hard. The insurance consequence of not doing it is harder.

What does “prove your backups work” actually mean?

The insurer requirement has moved from “do you have backups?” to “prove they work.”

  • Daily encrypted backups.
  • Offsite or air-gapped storage.
  • Quarterly restore testing.
  • Documented test results.

If your backup lives on the same network as your production systems — and ransomware encrypts both — your backup isn’t a control. Insurers have learned this the hard way. They’re now verifying.

For logistics, the stakes are stark. A freight operator with offices across multiple countries runs warehouse and transport management systems at every site.

Encrypt production and backup together and all freight operations stop — no picking, no packing, no shipping. Downtime is measured in SLA penalties per hour, not inconvenience.

Related reading: Ransomware is why insurers verify backups. See what the new Australian laws require — Australia’s New Ransomware Laws: How to Prepare.

Are insurers looking past your own network?

Insurers are now looking past your network perimeter. They want to know how you manage the security of the vendors, partners and platforms you connect to.

For logistics operators, this is especially pointed. Third-party integrations — client APIs, customs brokers, courier networks, warehouse automation platforms — create a web of interconnected risk. A breach at one partner can flow straight through to your environment.

There’s a chain reaction at play. A breach in a logistics operator’s systems can expose a retailer’s customer data — and the retailer’s insurer will follow the chain back. Insurers are now asking logistics firms to prove they audit their integrations.

What evidence do insurers want for security awareness training?

The final piece: insurers want evidence that every staff member — from the CEO to the casual store attendant — has completed security awareness training within the last twelve months.

Phishing simulation results earn bonus points.

Social engineering remains the number one entry vector for ransomware. Insurers know this. They’re checking that their insureds know it too.

How can a mid-market business meet all seven requirements?

Here’s the structural problem. These seven requirements aren’t a one-off project. They’re not something you fix at renewal time and then forget about.

They’re continuous. Insurers verify them every twelve months — and the bar is rising.

Most mid-market operators see two options. Option one: hire a dedicated security team they can’t afford. Option two: hope the insurer doesn’t look too closely.

We built a third option.

At Planet6, ASD Essential 8 compliance is part of your monthly managed IT service — not a separate audit project. The full set of insurer requirements is included:

  • Endpoint detection and response.
  • Multi-factor authentication.
  • Incident response planning and tabletop testing.
  • Air-gapped backup with restore verification.
  • Third-party risk assessment.
  • Security awareness training with phishing simulation.

All seven requirements. One fixed monthly service.

No separate compliance engagement. No surprise invoice when the renewal form arrives. Just the controls insurers are demanding, built into how your IT runs every day.

We already do this for Australian retailers and logistics operators including 2XU, Australian Venue Co. and MCM Logistics. They run the same Essential 8 framework, the same EDR platform, the same tested backup and IR procedures. When their insurer asks for evidence, they have it.

Your cyber insurance renewal is coming. Make sure you can pass it.

Planet6 helps Australian retailers and logistics operators turn insurer requirements into everyday IT — Essential 8, EDR, tested backups and more, in one fixed monthly service. Talk to us.

Frequently asked questions

What do cyber insurers require in Australia in 2026?

Insurers are checking seven things: Essential 8 compliance, endpoint detection and response, a tested incident response plan, MFA everywhere, verified backups, third-party risk management and documented security awareness training.

Is Essential 8 mandatory for cyber insurance?

Not legislated — but effectively required. Essential 8 is the first question on most mid-market applications, and gaps are discovered at renewal, when the insurer finds them first.

Why have cyber insurance premiums risen so sharply?

ISIG data shows mid-market premiums up 60 to 200 per cent year-on-year. Retail and logistics are the highest-risk sectors, driven by ransomware frequency, multi-site attack surfaces and stricter insurer verification.

How do I prove my backups to an insurer?

Daily encrypted backups, offsite or air-gapped storage, quarterly restore testing and documented test results. A backup on the same network as production isn’t a control.

Source: Insurance Statistics Industry Group (ISIG) data on Australian cyber insurance premiums, 2026.