Cybersecurity

Cyber Insurance Requirements in Australia: MFA, EDR, Backups

Mark Holden·Technical Operations Lead
7 September 20267 min read

Cyber insurance renewals in Australia have quietly turned into a controls audit. The questionnaire is no longer four boxes about antivirus and passwords — it asks which multi-factor method you enforce, whether your endpoint tooling is monitored around the clock, whether your backups are immutable, and when you last restored from one. Answer those with exports and test logs rather than assertions and the renewal conversation gets short. The useful part is that the same evidence pack is what tells you the controls are actually running, which is a better reason to build it than the policy.

What insurers are now asking for

A Melbourne cyber-insurance readiness service publishes the checklist most Australian underwriters now work from, last updated on 20 August 2026. Three requirements do the heavy lifting.

MFA, everywhere that matters. Enforced on all remote access, email, cloud apps and privileged accounts. The guidance is blunt that partial implementation does not count, and that SMS-only codes are marked "not acceptable". Acceptable methods are app-based authenticators such as Microsoft Authenticator or Duo, FIDO2 hardware tokens, and conditional access policies that enforce them.

EDR with 24/7 monitoring on all endpoints, including servers. Traditional signature-based antivirus no longer qualifies. The word "all" is the one that catches people — servers, and particularly outsourced or legacy on-premises workloads, are where coverage gaps sit.

Tested backups with immutable or air-gapped copies. A 3-2-1 strategy, documented RTO and RPO, and evidence of restore testing. Online-only and untested backups are explicitly not acceptable.

None of that is exotic. All of it is verifiable, which is the change. An underwriter can ask for the artefact.

Costing the licensing layer

For most Australian businesses under 300 staff, the identity and endpoint half of the list starts with Microsoft 365 Business Premium. Microsoft's Australian pricing lists it at AU$32.90 per user per month, paid yearly, ex GST, with month-to-month subscriptions roughly 20% higher at around AU$39.48. That SKU is what brings Intune device management, Microsoft Defender for Business and Entra ID P1 conditional access into the tenant — a step up of about A$14 per user per month from Business Standard that covers a large share of the Essential Eight.

Buying through a reseller changes the number and the tax treatment. Telstra's Apps Marketplace lists Business Premium at $38.01 per user per month on a 12-month term and $43.43 on a one-month contract, including GST. Comparing that to Microsoft's $32.90 is comparing GST-inclusive to GST-exclusive; Microsoft's advertised prices exclude GST and the billing page shows the inclusive figure — Business Premium with Copilot, for instance, is $47.90 ex GST and $52.69 inc GST. Copilot sits on top of Business Premium and does not replace or alter Intune, Defender or Entra ID P1, so it is an AI line item, not a security one.

Line itemPrice (AUD, per user per month)
M365 Business Premium, Microsoft direct, annual$32.90 ex GST
M365 Business Premium, Microsoft direct, monthly~$39.48 ex GST
M365 Business Premium, Telstra, 12-month term$38.01 inc GST
M365 Business Premium, Telstra, 1-month term$43.43 inc GST
M365 Business Premium with Copilot, Microsoft direct$47.90 ex GST ($52.69 inc GST)

Two things are not in that table, and they are the two that decide whether you pass the underwriter's check: 24/7 monitoring of the endpoint telemetry, and backup with immutable storage plus restore testing. Both are services rather than SKUs, both are priced per endpoint or per workload rather than per user, and both are where the real spend lands for a business that already holds Business Premium licences. Budget for them as separate lines from day one rather than discovering them at renewal.

On timing: the 2026 Microsoft 365 pricing announcement was quoted in US dollars, with Business Standard rising 12% while Business Premium holds flat at around US$22. Australian list price changes took effect 1 July 2026, and existing customers stay on their current pricing until renewal. Telstra separately confirmed no change to the Business Premium monthly charge as of 1 July 2026. The practical read for anyone still on Business Standard is that the gap to Premium narrowed rather than widened.

The five places SME implementations fail the check

Partial MFA

The most common pattern is MFA on administrators and on anything that prompted for it during a Microsoft security default rollout, with a long tail of exclusions: service accounts, a legacy line-of-business application using basic authentication, the finance user whose exemption was meant to last a fortnight, contractors on guest accounts. Each one is defensible on its own. Collectively they mean the honest answer to "is MFA enforced on all email and remote access" is no, and that is the answer the claims assessor will reconstruct from your sign-in logs after an incident.

SMS as the second factor

SMS codes still feel like MFA to users and still show as MFA in a lot of dashboards. SIM-swap and interception have moved insurers off them, and the readiness guidance now lists SMS-only as unacceptable outright. Migrating a workforce from SMS to Authenticator with number matching is a registration campaign, not a switch — it needs comms, a support window, a fallback path for people without work phones, and hardware tokens for the roles that genuinely cannot use an app.

Licences bought, monitoring absent

Defender for Business ships in Business Premium. Owning the licence is not the same as having a human or a monitored service watching the alerts at 2am on a Sunday, which is what "24/7 monitored EDR" means. A console nobody reads is an audit finding, not a control. This is the gap where a licence-plus-service model matters — the alert has to reach someone whose job is to act on it, and the alert-to-action trail has to be reportable. Combining monitored detection and response with the compliance reporting that produces that trail is exactly what our managed security and compliance service exists to do.

Servers missed

Endpoint agents get deployed by device management to laptops enrolled in Intune. Servers are frequently outside that path — a hypervisor at head office, a couple of VMs at a hosting provider, a file server nobody has touched since it was migrated. Insurers ask about all endpoints including servers because that is where ransomware operators go. The fix starts with an asset inventory that is authoritative, then agent coverage measured against it as a percentage rather than a feeling.

Backups that have never been restored

Almost every business has backups. Far fewer have immutable copies that a compromised administrator account cannot delete, and fewer again have a dated record of a restore that worked, with the elapsed time written down next to the RTO the business agreed to. A second copy in the same tenant, under the same credentials, is a copy — not an air gap. This is the requirement that most often turns a claim into a dispute, because the failure only becomes visible at the exact moment it costs the most.

The evidence pack is the point

Everything an underwriter wants is something you should be able to produce anyway, and producing it is what proves the control is live:

  • Identity. An export of conditional access policies showing which users, apps and locations are in scope, plus an authentication methods report showing registered method by user. Exclusions listed explicitly, with a reason and an owner.
  • Endpoint. Agent coverage as a count against the asset register, split by device type, with servers called out. Plus the monitoring arrangement in writing: who watches, what hours, what the escalation path is.
  • Backup and recovery. Job success reporting, immutability or air-gap configuration, documented RTO and RPO per workload, and the date and result of the last test restore including how long it took.
  • Governance. An incident response plan naming who declares an incident, who talks to the insurer and the OAIC, and where the plan lives when the network is down.

That pack answers the questionnaire, gives your broker something to negotiate with, and gives you a maintenance rhythm. Refresh the exclusions list quarterly. Test a restore on a schedule you actually keep. Re-run the coverage report after every device refresh.

Start with one export: pull the authentication methods report from your Microsoft 365 admin centre and count how many active users are registered for SMS only or for nothing at all. Then compare the number of devices reporting into your endpoint console with the number of machines on your asset list. Those two numbers, side by side, tell you within minutes whether you would pass the check today.

If you want that assessed properly rather than sampled, our Essential Eight assessment scores your current maturity control by control, maps each finding to what insurers are asking for, and comes back with a costed remediation plan in AUD — including a straight answer on which gaps are worth closing before your next renewal and which can wait.

cyber insurancemfaedrbackupsessential eightmicrosoft 365

Ready to Transform Your IT?

Our team of cloud and security experts is ready to help your business thrive. Get a free consultation today.

Get in Touch

Ready to simplify your IT?

Talk to our team about managed IT, cloud and cybersecurity for your business.