Cyber Insurance Subjectivity Tracker
Rules

The rule sets behind the schedule

The core list for each jurisdiction, the add-ons the applicant ticks, the privacy lines and the optional lens, each with when it applies and the edition held.

Rule setRoleWhereWhen it applies
ACSC Essential EightcoreAustraliaThe core list for Australia. ASD publishes the Essential Eight and its maturity levels; for a private business it is a baseline, not a law, and the target maturity level is the underwriter's choice.
Australian Privacy Principles (APPs)privacyAustraliaOnly when the Privacy Act 1988 applies to the business: for example annual turnover over AUD 3 million, a health service provider, or another case the Act lists.
Notifiable Data Breaches Scheme (Australia)privacyAustraliaOnly when the Privacy Act 1988 applies to the business (the entities APP 11 binds).
CIS Controls v8coreUnited StatesPart of the core list for the United States. A consensus control set, not a law, cited by safeguard number.
ISO 27001:2022lensAustralia, United States, United KingdomAn optional lens in any jurisdiction: shown as "also cited" beside a gap, never a gap on its own.
NIST Cybersecurity Framework 2.0coreUnited StatesPart of the core list for the United States. A voluntary framework of outcomes, cited at subcategory level.
FTC GLBA Safeguards Rule (16 CFR Part 314)addonUnited StatesFinancial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.
HIPAA Security RuleaddonUnited StatesHIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.
NY DFS 23 NYCRR 500addonUnited StatesEntities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.
PCI DSS 4.0addonUnited States, Australia, United KingdomAny business that stores, processes or transmits payment card data, in any of the three jurisdictions.
UK Cyber EssentialscoreUnited KingdomThe core list for the United Kingdom: the government-backed baseline scheme. The test steps of Cyber Essentials Plus are not used.

Not in this product: the SEC cyber disclosure rule and SOX 404 (both bind public companies), the test steps of Cyber Essentials Plus, and any rule that binds the insurer rather than the applicant.