Aussie Pentest
Book Now

Cyber Insurance and Penetration Testing: What Do Australian Insurers Actually Require?

Australian cyber insurers typically want enforced MFA, tested backups, patching evidence, and often third-party assessment artefacts—not a vague “secure” promise. Match the ask to the right evidence.

Caleb Brooke

Caleb Brooke

Australian cyber insurance requirements rarely boil down to “buy a penetration test and you’re done.” Underwriters and brokers typically want evidence that core controls — especially MFA, backups, patching, privileged access, and endpoint protection — actually exist and work. A security assessment, a human-led penetration test, or an Essential Eight maturity assessment can each support that conversation; they answer different questions. This guide explains what insurers often ask for, how testing and E8 evidence fit, and how to choose the right rung without over-declaring controls on the application.

Important: Requirements vary by insurer, policy schedule, sector, and limit. Nothing here is a promise that any particular report will be accepted. Ask your broker what artefact they mean — then buy that.

What do Australian cyber insurers typically require?

Most Australian cyber underwriting conversations in recent years have tightened around implemented controls plus evidence, not a tick-box that says you “have security.” Exact wording differs by policy, but the themes recur.

Controls and artefacts insurers often look for:

  • Multi-factor authentication (MFA): Enforced (not optional) on email, remote access/VPN/RDP, privileged/admin accounts, and often cloud admin consoles — Evidence that usually helps: MFA policy + coverage/export reports showing enforcement; legacy auth disabled where relevant
  • Backups: Regular backups that ransomware on production cannot easily wipe; ideally offline, segregated, or immutable; tested restores — Evidence that usually helps: Backup job success reports; config showing isolation/immutability; dated restore-test records
  • Patching: Defined cadence for critical / internet-facing systems; visibility across the estate — Evidence that usually helps: Patch compliance reports; vulnerability scan history; documented SLAs and exceptions
  • Privileged access: Admin rights restricted; separate admin accounts; fewer standing privileges — Evidence that usually helps: Privileged account inventories; access reviews; AD/IdP config evidence
  • Endpoint detection: EDR (or equivalent) broadly deployed — increasingly treated as baseline alongside MFA — Evidence that usually helps: Coverage reports; agent health dashboards
  • Email / phishing hygiene: Gateway filtering, DMARC/SPF/DKIM, sometimes awareness training — Evidence that usually helps: DNS auth records; gateway config; training attendance logs
  • Incident response: A documented plan with an owner and a recent review date — Evidence that usually helps: IR plan PDF; tabletop notes; escalation contacts
  • Third-party assessment: Independent verification — wording ranges from “vulnerability assessment” to “penetration test” to Essential Eight-style maturity evidence — Evidence that usually helps: Analyst-reviewed assessment, human-led pentest, and/or independent E8 report — match the ask

ASD’s Essential Eight is not itself an insurance product — but MFA, patching, privileged access, and regular backups sit squarely inside that model. That is why brokers increasingly use E8 language even when the policy never says “Essential Eight.”

What this is not: a universal legal checklist for every Australian SMB, and not a substitute for reading your policy schedule and proposal form. Conditions precedent, sub-limits, and representation clauses matter; misrepresenting controls can put claims at risk even if you paid the premium.

Do Australian insurers require a penetration test?

Sometimes — but not always, and not always under that name.

In practice we see three patterns:

  1. Control questionnaire only. The form asks about MFA, backups, patching, EDR, IR plans. No named technical test. Your job is accurate answers plus artefacts that back them.
  2. Assessment / scan / “recent security testing” language. Brokers want a recent third-party report on internet-facing exposure. An analyst-reviewed Automated Security Assessment is often the right fit — structured severity ratings and remediation language, not a raw scanner dump. It is not a penetration test.
  3. Named penetration test. Higher limits, certain sectors, enterprise customers riding on the same renewal, or an underwriter who wants exploit-backed assurance. Then a human-led pentest with written scope, methodology, and proof-of-concept on criticals is what the ask usually means.

A fourth pattern is growing fast: Essential Eight / ML2-style evidence. That is a maturity assessment against ASD’s model — control package scoring — not a pentest of your web app. See our guide on Essential Eight compliance for Australian SMBs for the mandatory-vs-practical distinction.

Rule of thumb: If the broker says “penetration test,” buy a pentest (or clarify in writing that they will accept an assessment). If they say “vulnerability assessment,” “security assessment,” or “show us your external exposure,” start with an assessment. If they say “Essential Eight,” “ML1/ML2,” or map questions to the eight mitigations, budget for an independent E8 assessment. Guessing wrong wastes money and still leaves the renewal hanging.

MFA, backups, and patching: what “good evidence” usually looks like

Underwriters care less about marketing slogans and more about whether the control would still hold on the day of a claim.

MFA

Typically expected: MFA enforced on Microsoft 365 / Google Workspace email, remote access, and privileged accounts — not “available if users opt in.” Gaps we often see called out: legacy protocols still enabled; MFA on email but not on Azure/admin portals, payroll, or RMM tools; SMS-only factors treated as enough when the questionnaire implies stronger assurance.

Evidence that travels: IdP MFA registration/coverage reports, Conditional Access (or equivalent) screenshots with enforcement clear, and a short note on which systems are still exempt and why.

Backups

“We have backups” is rarely enough. Questions increasingly dig into whether a copy is offline or immutable, whether backup consoles themselves use MFA and separate credentials, and whether you have a dated successful restore test.

Evidence that travels: backup job success exports, immutability/retention settings, and a restore-test record (date, system, result, time to restore). Quarterly restore testing is a common broker expectation in market commentary — confirm what *your* form asks.

Patching

Expect questions about critical patch windows on internet-facing systems and whether you have visibility across the estate. Essential Eight maturity language often references rapid treatment of critical / actively exploited issues (including 48-hour themes in ASD guidance) — insurers may use similar pressure even when they never cite ASD.

Evidence that travels: patch compliance dashboards, vulnerability scan history, a documented cadence, and exceptions with owners.

None of this replaces reading the proposal form. It does explain why a scramble the week before renewal feels so expensive.

How does Essential Eight map to cyber insurance questionnaires?

Essential Eight is ASD’s prioritised set of eight technical mitigations, scored as a maturity model (ML0–ML3). It is not a vendor badge, and there is no official “E8 certified” stamp for your business or your assessor.

  • Multi-factor authentication: Enforced MFA on email, remote access, privileged accounts
  • Patch applications / OS: Critical patch SLAs; vulnerability management
  • Restrict administrative privileges: Least privilege; admin account hygiene
  • Regular backups: Isolated/tested backups; restore evidence
  • Application control, macros, hardening: Hardening / allow-listing questions (more common as forms deepen)

An independent Essential Eight assessment produces maturity scores, a technical evidence file, gap analysis, and a remediation roadmap — the kind of artefact brokers increasingly recognise when they ask for ML2-aligned proof. Published fixed fee for environments up to 50 seats: $4,950 + GST, report within 10 business days of assessment.

Limits of the product (say these out loud): An E8 assessment does not guarantee insurance issuance, premium reduction, or claims payment. It does not prove every exploit path on a custom app. It measures the control package against ASD’s model so you can answer maturity questions honestly and prioritise uplift with your MSP or IT team.

For deeper framing (mandatory vs practical drivers, ML1 vs ML2, assessment vs uplift), use the Essential Eight SMB guide.

Soft next step: If your broker is asking for Essential Eight / ML2-style evidence — not just a vuln PDF — book an Essential Eight assessment. Independent of your MSP; technical validation, not interview theatre.

Assessment vs penetration test vs Essential Eight: which evidence for insurance?

Match the artefact to the question. Do not buy theatre.

  • If the ask is… Recent vulnerability / security assessment on public assets; first baseline; questionnaire needs a readable third-party report — Prefer: Analyst-reviewed Automated Security Assessment. Published Aussie Pentest rung: $80 / $200 / $500 / $2,000. What you get: Severity-ranked findings, evidence, plain-English remediation — not a pentest
  • If the ask is… Named penetration test, exploit proof, internal/cloud/AD depth, tender-grade human assurance — Prefer: Human-led penetration test. Published Aussie Pentest rung: From $5,000 / $12,000 / $20,000 (+ GST where applicable). What you get: Written scope, fixed fee, PoC on criticals, retest path, compliance-mapping language as *support*
  • If the ask is… Essential Eight / ML1–ML2 / control maturity for insurer, tender, or DISP-oriented packs — Prefer: Essential Eight maturity assessment. Published Aussie Pentest rung: $4,950 + GST (≤50 seats). What you get: Maturity scores + evidence file + roadmap + debrief

We do not pretend an $80 assessment and a $5,000 pentest produce identical outcomes. For a full comparison of depth, turnaround, and decision logic, see Automated vs Manual Penetration Testing. For what drives manual pricing, see Penetration Testing Costs for SMBs in Australia.

Acceptance disclaimer (again, on purpose): Reports are designed to *support* underwriting and due-diligence conversations. Whether an insurer, auditor, or scheme accepts a given report is always their decision.

Why independence from your MSP matters for insurance evidence

Your MSP built and runs the environment. Asking them alone to score how secure it is creates an obvious conflict of interest — especially when an underwriter or claims adjuster later asks who verified the controls.

Independence does not mean “fire your MSP.” The clean pattern is:

  1. An independent assessor or tester produces the evidence pack.
  2. Your MSP / IT team remediates against a clear roadmap.
  3. Assessment stays separate from implementation so the artefact stays defensible.

Aussie Pentest assesses and tests; we do not replace your managed IT provider. That separation is often exactly what brokers and auditors prefer. “Validate what your MSP built” beats another reassuring internal chat.

What should you ask your broker before you buy any testing?

Clarify the artefact in writing before you spend. Useful questions:

  1. What exact wording is on the proposal form or policy schedule — “penetration test,” “vulnerability assessment,” “independent security assessment,” or Essential Eight / maturity language?
  2. How recent must the report be (e.g. within 12 months)?
  3. What scope do they expect — external only, named apps, internal network, cloud admin?
  4. Will they accept an analyst-reviewed assessment, or do they insist on a human-led pentest with methodology and PoC?
  5. Do they want Essential Eight maturity evidence (ML1/ML2) in addition to, or instead of, a vuln/pentest report?
  6. What control artefacts should sit alongside any test report (MFA coverage, backup restore tests, patch reports, IR plan)?
  7. Are there conditions precedent or warranty language that makes accurate representation critical for claims?

Bring those answers to scoping. Buying the wrong rung because the sales deck said “insurance ready” is how renewals still stall.

For vendor hygiene once you know the ask, use How to Choose a Penetration Testing Provider in Australia — sample report, fixed fee, who is on the keyboard, retest, and whether they mislabel scans as pentests.

Decision guidance: which rung should you book this quarter?

Use the broker’s words first, then your attack surface, then budget.

  1. Broker says Essential Eight / ML2 / control maturity → Independent Essential Eight assessment ($4,950 + GST ≤50 seats). Remediations with your MSP after.
  2. Broker says vulnerability assessment / recent security report / external exposureAutomated Security Assessment from $80–$2,000 depending on target count and depth.
  3. Broker or customer says penetration test by name / needs PoC / internal or complex estateHuman-led pentest from $5,000.
  4. Form is control-heavy but silent on testing → Fix MFA, backups, patching, EDR evidence first; add a third-party assessment where it strengthens the application — and still ask the broker whether a test is expected.
  5. You are tired of annual scramble → After the immediate artefact, consider whether a vCISO retainer (advisory/oversight only — not IR, not implementation) stops the next renewal panic. It does not replace a scoped test.

Practical sequence many AU SMBs use: honest control evidence → independent E8 baseline if maturity is on the form → assessment or pentest where the form asks for testing → MSP remediates → keep artefacts dated for the next renewal.

Common mistakes that create insurance pain

  • Over-declaring controls. Saying MFA is “everywhere” when finance systems or remote tools are exempt. Align the application with reality; use assessments to find gaps before the underwriter does.
  • Calling a scan a pentest. If the form asked for a penetration test and you submit a raw scanner PDF, you may still fail the ask. See automated vs manual.
  • MSP-only self-attestation when the broker wanted third-party evidence.
  • No restore-test record for backups — “we back up daily” without a dated restore.
  • Buying E8 when they asked for a pentest (or the reverse). Different questions.
  • Leaving it until the week before renewal. Assessment and E8 report SLAs are days to a couple of weeks — but remediation often takes longer than the PDF.

FAQ: cyber insurance evidence for Australian SMBs

Do I need a penetration test to get cyber insurance in Australia?

Not always. Many policies focus on MFA, backups, patching, EDR, and related controls. Some underwriters or higher-limit deals ask for a named penetration test or another independent assessment. Ask your broker what the form and schedule require before you buy.

Will my insurer accept an Aussie Pentest report?

Reports are structured to support common insurance, Essential Eight, ISO 27001, and SOC 2 *evidence* conversations. Acceptance is always the insurer’s (or auditor’s) decision. We do not guarantee cover, premiums, or claims outcomes.

Is an Automated Security Assessment enough for insurance?

Often yes when the ask is a vulnerability / security assessment on internet-facing assets and you need a readable third-party PDF quickly ($80–$2,000 tiers). It is not a penetration test. If the broker requires a named pentest or Essential Eight maturity scoring, choose those products instead.

How does Essential Eight help with cyber insurance?

E8’s MFA, patching, privileged access, and backup strategies map closely to typical underwriting questions. An independent maturity assessment produces scores and evidence that support ML-style discussions. It does not certify you “E8 compliant” as a badge and does not replace accurate control declarations.

What if my MSP already “assessed” us?

Useful for uplift planning — often weaker as sole insurance evidence. Independence (assessor ≠ remediator) is frequently what brokers and auditors want. Keep your MSP for fixes; use an independent firm for the score or test.

How much should we budget?

Published Aussie Pentest ladder (AUD): Automated Security Assessment $80–$2,000; human-led pentest from $5,000; Essential Eight assessment $4,950 + GST (≤50 seats). Scope and the broker’s exact ask drive which rung — not a single “insurance package” price.

Bottom line

Australian cyber insurance is increasingly about provable controls and matching artefacts — MFA and backups done properly, patching you can show, and third-party reports that answer the question the form actually asked. Buy an Automated Security Assessment for fast, analyst-reviewed exposure evidence; a human-led penetration test when exploit proof or a named pentest is required; an Essential Eight assessment when maturity scoring is the ask. Confirm with your broker first. Then book the right engagement — get in touch if you want help mapping the wording on your form to a fixed-fee scope.

Sources

General guidance for Australian SMBs renewing or buying cyber insurance — not a substitute for broker advice, policy wording, legal advice, or a scoped assessment. Insurer requirements vary; pricing and product claims match published Aussie Pentest service pages as of September 2026.