Cyber insurance conditions in Australia, on a 90-day clock
In Australia the core list is the ACSC Essential Eight, at the target maturity level the underwriter picks: Maturity Level One by default, or Maturity Level Two. A requirement ASD sets above the target reads "above your target level" and is never a gap. When the Privacy Act 1988 applies to the business (for example annual turnover over AUD 3 million, or a health service provider), the Australian Privacy Principles and the Notifiable Data Breaches lines appear too; "not sure" turns them into questions. PCI DSS is an add-on when the business takes card payments.
Your insurer or broker sets day 0; each gap gets a checkpoint at day 30, 60 or 90 by the default rule, and the applicant reports each fix closed through a private link. Start from the Australia template, or mark the controls in the control list.
The controls with a rule in the core list here (28)
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication
- Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
- The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)
- Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
- Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them
- Administrator accounts (other than the backup administrator) cannot change or delete backups
- Restoring from backup is tested as part of a disaster recovery exercise
- Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement
- Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
- Other business applications are patched within the timeframe in the requirement
- Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements
- Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
- Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
- Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked
- Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
- Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed
- Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
- Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review
- Macros in office files from the internet are blocked, macros are off for staff with no business need, are scanned, and users cannot change the settings
- Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
- Office and PDF software are hardened, blocked from creating child processes and executable content, and users cannot change their security settings
- Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
- There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names
- Personal information held is protected by reasonable steps against misuse, interference, loss and unauthorised access
- A data breach response plan exists, and a suspected data breach is assessed within the 30 days the Notifiable Data Breaches scheme sets
- The business knows when and how to notify the Commissioner and the people affected by a data breach the scheme covers
- A clearly expressed, up-to-date privacy policy is published
Rule sets
- ACSC Essential Eight: The core list for Australia. ASD publishes the Essential Eight and its maturity levels; for a private business it is a baseline, not a law, and the target maturity level is the underwriter's choice.
- Australian Privacy Principles (APPs): Only when the Privacy Act 1988 applies to the business: for example annual turnover over AUD 3 million, a health service provider, or another case the Act lists.
- Notifiable Data Breaches Scheme (Australia): Only when the Privacy Act 1988 applies to the business (the entities APP 11 binds).
- ISO 27001:2022: An optional lens in any jurisdiction: shown as "also cited" beside a gap, never a gap on its own.
- PCI DSS 4.0: Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.