Add Think Technology as a trusted source Why Cyber Insurance Claims Get Denied | TTA

Why your cyber insurance claim could be denied before it’s even assessed

Australian SME business owner reviewing a cyber insurance claim denied letter with IT advisor in Brisbane office

Cyber insurance is meant to be the financial backstop when things go wrong. But a large share of Australian businesses that file a claim after an attack discover the policy they have been paying for won’t pay out. The reason is almost never fine print or ambiguous wording. It is a failure to maintain the security controls the business declared on its application, particularly multi-factor authentication (MFA). Understanding why a cyber insurance claim gets denied is now one of the most practical risk management steps any business owner can take.

The financial exposure is real. The Australian Signals Directorate’s Annual Cyber Threat Report 2024-25 recorded more than 84,700 cybercrime reports, roughly one every six minutes, and the average self-reported cost of a cyber incident for a small business reached $56,600. For businesses without a valid claim, that cost falls entirely on the business. Directors, CFOs, and operations managers in any organisation that holds customer data or relies on digital systems need to understand how denial happens and how to stop it.

This article covers the leading causes of a cyber insurance claim deniedthe new regulatory conditions that affect Australian businesses as of 2025, and the practical controls that keep a policy enforceable when you need it most.

Why so many cyber insurance claims get denied

Approximately 40% of cyber insurance claims were denied in 2024, based on data from multiple industry sources. The leading cause is not exclusion clauses or policy ambiguity. It is misrepresentation of security controls on the application form, specifically, controls that were declared as active but were not fully in place at the time of the incident. Failure to maintain MFA accounts for roughly 37% of denied claims across the market.

Insurers have changed how they verify your controls. The self-attestation model, where a business ticked boxes on an application and insurers took those answers on trust, is being replaced. Underwriters now use third-party telemetry and external scanning to check whether the controls you declared are actually in place. If your application says MFA is enforced everywhere and an external scan shows it is not, your policy may be invalid before any incident occurs.

The Travelers v International Control Services case established a pattern the industry has followed since. The insurer denied a ransomware claim after a post-breach investigation showed MFA was not fully deployed, despite being declared on the application. The court agreed the policy could be rescinded. The denial was not because MFA caused the breach, it was because the company had stated it was in place when it was not.

The MFA gap – the single most common denial trigger

MFA is now a universal requirement for Australian cyber insurers. Most will not issue a policy to an SME without MFA enforced on Microsoft 365 or Google Workspace, on remote access (VPN, RDP), and on privileged accounts. Some insurers now also require MFA on customer-facing portals and finance system logins. The requirement is not just to have MFA enabled, it must be enforced, meaning users cannot bypass it.

The practical gap most businesses miss is partial deployment. MFA might be active for most staff but not for a service account, a legacy system, or a recently onboarded contractor. One unprotected login path is enough. If an attacker uses that path, and a post-breach investigation identifies it, the insurer can deny the entire claim, not just the portion related to that account. Coalition’s 2024 data shows 82% of denied claims involved organisations where MFA was not fully deployed.

The fix is an MFA audit before the next application or renewal. Map every system, every access path, and every account type. If MFA is not enforced on privileged accounts, remote access, email, and cloud services, address it before applying. Document that you have done it. Evidence of enforcement, not just configuration, is what underwriters want to see.

Notification delays and other policy conditions that void cover

A cyber insurance claim denied because of late notification is one of the most avoidable failures. Most Australian cyber insurance policies require the insurer to be notified within 48 to 72 hours of discovery, not 48 hours after the business has finished assessing the damage, but 48 hours after it first suspected something was wrong. The instinct to investigate internally before calling the insurer is understandable and almost always costly.

Other policy conditions that frequently result in denial include:

  • Incomplete or outdated patching logs, insurers want documented evidence that critical patches were applied within a defined timeframe, typically 30 days for critical vulnerabilities.
  • No tested incident response plan, a written plan that has never been exercised does not satisfy most insurer requirements.
  • Endpoint detection and response (EDR) gaps, traditional signature-based antivirus no longer meets underwriting requirements. Insurers expect behavioural detection on every endpoint, including servers and remote devices.
  • Backup testing gaps, immutable or offline backups are required, and evidence that restores have been tested is increasingly part of the renewal questionnaire.
  • No security awareness training records, evidence of phishing simulations and staff training is expected, not just policy documents.

Each of these gaps gives an insurer grounds to deny a claim independently. Missing more than one shifts the risk significantly toward a full denial.

How Brisbane SMEs are caught out – what we see at TTA

The pattern we see most often across Brisbane and South-East Queensland SMEs is not negligence, it is drift. A business sets up MFA correctly when it onboards Microsoft 365. Twelve months later, a new staff member is added under a legacy licence, a shared inbox is created without MFA, and a contractor gets RDP access with a workaround “just for now.” None of these decisions feel significant at the time. Together, they create the gap an insurer finds after a breach.

Professional services firms, accounting, legal, financial advice, are particularly exposed. They hold sensitive client data, they are named in cyber insurance policies as higher-risk sectors, and their staff often include part-time or contract workers whose access is harder to manage consistently. We have seen businesses in this group pay premiums for years and then face a denied claim because their controls had drifted from what was declared at application.

The second pattern is the annual renewal problem. A business answers the renewal questionnaire based on memory rather than a current audit. Controls that were true twelve months ago may no longer be. Underwriters are comparing the renewal attestation against their external scans. Where the two don’t match, the insurer has grounds to deny, or to rescind the policy retroactively. Our IT security assessments treat the renewal questionnaire as a live audit, not a form-filling exercise.

How to reduce the risk of a cyber insurance claim being denied

The controls Australian cyber insurers assess map closely to the ACSC Essential Eight. Businesses that can evidence maturity across patching, MFA, backups, application control, and privileged access management report premium reductions of 20 to 40% compared to organisations with no documented programme. The compliance work and the insurance work are largely the same work, they just need to be presented correctly.

A practical starting point for most SMEs:

  • Audit MFA coverage honestly across every system and access path before the next application or renewal.
  • Document your patch schedule and keep logs, evidence of adherence matters as much as the schedule itself.
  • Test at least one backup restore before renewal and document it with a date and result.
  • Write a simple incident response plan and run one tabletop exercise so it has been tested, not just filed.
  • Notify your insurer as soon as you suspect an incident, not after you have assessed it.
  • Use the renewal questionnaire as a trigger for a current-state review, not a memory exercise.

For businesses that want independent verification, a formal IT audit against the insurer’s requirements before renewal is a worthwhile investment. The cost of the audit is small relative to a denied claim.

New Australian regulations change the insurance equation

Australia’s Cyber Security Act 2024 introduced mandatory ransomware payment reporting from 30 May 2025. Organisations with annual turnover exceeding $3 million must report any ransomware payment to the Department of Home Affairs within 72 hours. Failure to report carries penalties of up to $19,000. More significantly for insurance, many policies now include compliance with this reporting obligation as a policy condition, meaning failure to report can itself be grounds for a cyber insurance claim denied.

Privacy Act reforms that commenced in June 2025 introduced a statutory tort for serious invasions of privacy, with expanded OAIC investigation powers and new civil and criminal penalties. A data breach that triggers regulatory action under the Privacy Act now carries financial exposure beyond the incident response costs, exposure that cyber insurance is designed to cover, but only if the policy is enforceable. The Notifiable Data Breaches scheme continues to apply, and notification obligations under it feed directly into your insurer’s post-breach review.

The practical implication: your incident response plan must now explicitly address the 72-hour ransomware reporting window and the NDB notification process. Your insurer needs to be part of that process from the start, not after you have made decisions independently.

Frequently asked questions

What is the most common reason a cyber insurance claim gets denied in Australia?

The most common reason a cyber insurance claim is denied is failure to maintain the security controls declared on the insurance application, particularly multi-factor authentication (MFA). Approximately 37% of denied claims across 2024 involved MFA gaps. Insurers now verify controls using external scanning, not just self-attestation. If your application states MFA is fully enforced and it is not, the insurer can deny the claim or rescind the policy entirely.

Does having cyber insurance mean I’m covered for any cyberattack?

Not automatically. Cyber insurance policies include conditions, security controls you must maintain throughout the policy period. If those controls were not in place at the time of an attack, the insurer may deny the claim regardless of the type of attack. Exclusions for state-sponsored attacks, pre-existing breaches, and intentional acts also apply. Coverage also varies between first-party costs (your own losses) and third-party liability (claims by others).

How long do I have to notify my insurer after a cyber incident?

Most Australian cyber insurance policies require notification within 48 to 72 hours of discovering, or suspecting, an incident. The clock starts when you first suspect something is wrong, not after you have assessed the damage. Delaying notification to investigate internally is one of the most common reasons claims are rejected. Contact your insurer and their incident response panel as soon as the incident is identified.

Will the Cyber Security Act 2024 affect my cyber insurance?

Yes, for businesses with annual turnover above $3 million. From 30 May 2025, mandatory ransomware payment reporting to the Department of Home Affairs within 72 hours became law. Many policies now include compliance with this obligation as a policy condition. Failing to report can give your insurer grounds to deny a claim. Your incident response plan should explicitly address the 72-hour reporting window and involve your insurer from the outset of any ransomware incident.

Does Essential Eight compliance help with cyber insurance?

Yes. The controls Australian cyber insurers assess map closely to the ACSC Essential Eight, patching, MFA, backups, application control, and privileged access management. Businesses that can document Essential Eight maturity typically pay 20 to 40% less in premiums than comparable organisations with no formal programme. More importantly, the documented evidence of controls is what protects a claim from being denied on the basis of misrepresentation.

Can a small business in Brisbane afford the controls cyber insurers require?

Most of the baseline controls, MFA, patching schedules, tested backups, an incident response plan, are not expensive to put in place for a 10 to 50 user business. MFA on Microsoft 365 is included in existing licences. Documented patch management can be part of a standard managed IT service. The incremental cost of getting these controls in order is far less than the average $56,600 cost of an uninsured cyber incident for a small business.

Where do we get started?

If you are approaching renewal, or if you have not reviewed your security controls against your current policy, we can help. TTA works with Brisbane and South-East Queensland businesses to audit their controls, close the gaps that lead to a cyber insurance claim denied, and document evidence that holds up at renewal. Get in touch to start the conversation.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.