Cyber Insurance Subjectivity Tracker
Australia

Cyber insurance conditions in Australia, on a 90-day clock

In Australia the core list is the ACSC Essential Eight, at the target maturity level the underwriter picks: Maturity Level One by default, or Maturity Level Two. A requirement ASD sets above the target reads "above your target level" and is never a gap. When the Privacy Act 1988 applies to the business (for example annual turnover over AUD 3 million, or a health service provider), the Australian Privacy Principles and the Notifiable Data Breaches lines appear too; "not sure" turns them into questions. PCI DSS is an add-on when the business takes card payments.

Your insurer or broker sets day 0; each gap gets a checkpoint at day 30, 60 or 90 by the default rule, and the applicant reports each fix closed through a private link. Start from the Australia template, or mark the controls in the control list.

The controls with a rule in the core list here (28)

Rule sets