Your next cyber insurance renewal will ask for evidence, not assurances.

Cyber insurance pricing has softened across most of the Australian market, but the evidence bar has risen sharply. Questionnaires that used to accept "yes, we have backups" now request architecture diagrams, backup-admin MFA proofs, dated restore-test reports and documented RTO and RPO targets — and insurers verify them.

See what underwriters actually verify
Short answer

Insurance-auditable recovery is recovery capability backed by documented, dated evidence — not backup existence, and not verbal assurance. It is a real recovery architecture (immutable copies, tested restores, MFA-protected backup administration, documented RTO and RPO, dependency maps) plus the artefacts that prove the architecture operates as described. Insurers increasingly treat the renewal questionnaire as an audit and verify claims through scanning tools, requested evidence, or post-incident review.

Quick answers

What it is, what changed and what evidence needs to exist.

Question

What does insurance-auditable recovery mean?

Recovery capability backed by documented, dated evidence — a real recovery architecture plus artefacts that prove it operates as described. Insurers increasingly treat the questionnaire as an audit and verify claims through scanning tools, requested evidence or post-incident review.

Question

What changed in the underwriting posture?

The audit bar. Pricing has softened, but the evidence bar has risen sharply. Questionnaires that used to accept "yes, we have backups" now request architecture diagrams, backup-admin MFA proofs, dated restore-test reports and documented RTO and RPO. Insurers now audit the attestation, not just the incident.

Question

What should we be able to produce?

A structured evidence pack covering backup architecture, retention policies, backup logs, dated restore-test reports, MFA coverage proofs, dependency maps, incident response runbook, tabletop records, recovery assumptions register and break-glass documentation. Each claim maps to a specific artefact — or the gap is flagged before the questionnaire is signed.

What has changed

Cyber insurance renewals are now evidence audits in everything but name.

The Australian cyber insurance market is softening in price and hardening in proof. Brokers describe it as buyer-leaning, with premium increases moderating compared to the 2021–2023 hard-market years. At the same time, obtaining meaningful coverage increasingly requires demonstrating specific controls, not simply attesting that security exists. Three dynamics sit behind the shift.

Questionnaires have been rewritten as audits. Insurers now ask for evidence that used to be assumed — backup architecture diagrams, MFA enrolment proofs for backup administrators and privileged accounts, dated restore-test reports, and RTO and RPO tied to a documented business impact analysis. The questions are more specific because the answers are now verified.

Verification has moved beyond the form. Underwriters increasingly use external scanning tools, request evidence during the quote process, and conduct structured assessments before binding coverage. After a loss event, the pre-incident attestation is tested against what is found; gaps between what was claimed and what existed are a common basis for denial or coverage reduction.

The gap between attested controls and verified reality is now visible at the governance layer. Recent Australian enforcement has linked cyber control adequacy to statutory duties. In ASIC v FIIG Securities Limited (2026), the Federal Court made declarations relating to failures to maintain adequate cybersecurity measures under AFSL obligations, contributing to a substantial penalty plus costs; the 2022 ASIC v RI Advice Group decision established the precedent. For directors and executives, the practical expectation is increasingly clear: cyber control claims need credible oversight, evidence and follow-through. Cyber insurance renewal, claim integrity and governance oversight are connected problems — and much of the same evidence supports all three conversations.

Eight audit categories

Across Australian renewal questionnaires and insurer-driven assessments, the same eight categories recur.

A credible recovery posture must produce defensible evidence in each category below. Each maps to a specific question on the questionnaire, and each maps to a specific artefact in the evidence pack. "Backups exist" is no longer an answer.

01
Backup architecture

A 3-2-1 design at minimum: three copies, two media types, one offsite, with at least one copy offline or immutable to survive a cyber attack that reaches the production network. Evidence: architecture diagram, storage configuration, retention settings.

02
Separation from production

Backup infrastructure isolated from production identity and credentials. Backup admin accounts not shared with daily operational accounts; backup servers not domain-joined to production Active Directory. Evidence: network diagrams, identity platform reports.

03
Restore testing

Dated, documented restore tests on a defined cadence. The question asked is "when did you last successfully restore from backup, and what did that restore cover?" A test without a written report is not evidence. Evidence: dated restore-test reports, ticket records.

04
Recovery Time and Recovery Point objectives

Documented RTO and RPO per critical service, tied to a business impact analysis rather than a round number. The question behind the question is whether the targets are achievable against the actual architecture. Evidence: BIA summary, per-service targets.

05
Privileged access controls

MFA enforced on backup administrator accounts, privileged administrator accounts and remote access, with a documented break-glass procedure for emergency access without violating MFA controls. Evidence: MFA enrolment reports, privileged access review.

06
Immutability and versioning

Write-Once-Read-Many storage for the backup copy that must survive a destructive cyber event; versioning enabled on cloud data stores where relevant. Evidence: WORM configuration exports, retention policy settings, version-history configuration.

07
Operational documentation

Incident response plan with named roles, business continuity plan covering recovery sequence, and tabletop exercise evidence. Documentation must be current — not filed during a compliance push three years ago and never updated. Evidence: IR plan, BCP, exercise reports.

08
Governance and ownership

A named owner for the recovery program, a documented review cadence for the plan and the evidence, and change management records showing updates after environment changes. Evidence: role assignment, review logs, change management records.

Artefacts that map to insurer questions

Each insurer question maps to a specific document.

The evidence pack is the structured artefact set that makes recovery posture auditable. Each item exists for a specific reason and answers a specific underwriter question. A useful discipline: each item carries a last-reviewed date — if it is older than six months, it is flagged for refresh before renewal.

Artefact
Answers the underwriter question
Backup architecture diagram
How are backups structured and what survives a cyber attack? Shows onsite and offsite copies, snapshot frequency, and which copy is immutable or offline.
Retention policy exports
How long can we recover from? Current retention configuration for each workload — mailbox retention, OneDrive versioning, server backup retention.
Backup logs and success reports
Do the backups actually run, and who notices when they do not? Recent job outcomes, storage consumption and failure investigations.
Dated restore-test reports
Have you actually recovered from a backup, or just backed up? Last test scope, procedure, timing, outcome and issues — signed by the engineer who performed it.
Incident response runbook
Who does what, in what order, when it happens? Step-by-step procedure with named roles, contacts and escalation paths.
Tabletop exercise notes
Has anyone practised this, or is it only theoretical? Participants, scenarios tested, gaps identified and actions taken.
System dependency map
What has to come back online first, and what blocks what? Critical services and their upstream dependencies.
Recovery assumptions register
Under what conditions does the plan hold? Documented assumptions behind every recovery-time estimate.
Break-glass credential documentation
What happens if the attacker locks the primary administrator out? Emergency account inventory, credential storage location and use conditions.
MFA coverage report
Are the accounts that matter protected? MFA enrolment across privileged and administrative accounts, with specific attention to backup administrators.
Change management log
Is the evidence current, or produced once and never updated? Recent environmental changes and their impact on recovery documentation.
Business impact analysis summary
Why are the targets what they are? Critical processes, recovery priority order, and RTO and RPO per process.
Who signs off, and whether it matters

Insurers care about who is attesting as much as what is attested.

A statement that the organisation meets a given standard carries different weight depending on who signs it, what records support it, and whether those records are independently verifiable. The central principle: attestation language must match the evidence. The most common failure is not dishonesty — it is aspirational answers to specific questions under renewal-deadline pressure.

01
Independent third-party assessmentStrongest weight

An external assessor performs a structured review, documents findings and produces a signed, dated report. Strongest weight, especially for high-value renewals, post-incident assurance, or client and governance attestation requirements.

02
MSP attestation backed by operational recordsCredible

The managed provider attests to systems they operate, supported by MFA reports, backup logs, restore-test records and ticket history. Credible because the attestation is backed by the evidence the provider produces in the course of operations.

03
Internal IT attestation with documented recordsConditional

The internal IT lead signs off, with records maintained internally. Credible where the records exist and are current; exposed where they do not.

04
Executive sign-off without technical backingSymbolic

Important for compliance reasons, but it does not constitute evidence. Insurers do not accept CFO or CEO attestation in isolation as sufficient for technical claims.

The fix is procedural. Each claim on the questionnaire is tied to a named artefact; if the artefact does not support the claim, the claim is reworded or the gap is flagged for remediation before the questionnaire is signed.

Where evidence packs commonly fail

Seven failure patterns that surface under scrutiny.

Every pattern below is documented in Australian renewal reviews and post-incident investigations. Most are fixable before the next renewal if identified in time.

01
Untested backups

Backups exist but have not been restored in practice — treated by insurers as an assumption rather than a plan. The first restore under real pressure is the first time it has been tried, which is the wrong time to discover that a configuration assumption was wrong.

02
Outdated documentation

Recovery plans written two years ago and never updated. New systems added, old systems decommissioned, staff turnover — the document is still on file but no longer reflects the environment. An underwriter reading it can usually tell.

03
Microsoft 365 misconception

The assumption that because data sits in Microsoft's cloud, Microsoft backs it up. Microsoft's Service Agreement explicitly advises customers to back up their own content. Native retention is short (14 to 30 days for mail, up to 93 days for OneDrive and SharePoint recycle bins), and a cyber attack that encrypts inside Microsoft 365 is replicated, not reverted.

04
Unprotected backup administrators

Backups well-designed, but the backup administrator account is not MFA-enforced, or shares credentials with daily operations. A single account compromise reaches the backups. One of the most specific questions on current questionnaires, and one of the most common denial reasons when found absent after a claim.

05
Partial coverage gaps

Production servers backed up, SaaS data and endpoints ignored. Microsoft 365, endpoint-stored data and cloud-native services like Teams chat history fall out of scope and are discovered missing at recovery time.

06
No offline or immutable copy

All backups are online, reachable from the production network. A cyber attack that encrypts the production environment reaches the backup repository. An offline or immutable copy is the control that breaks this pattern.

07
Attestation that overstates the evidence

The questionnaire is signed off above what the records support. The gap is invisible until an insurer verifies or an incident triggers a claim review. This is the pattern most likely to convert a covered loss into a declined claim.

Each failure pattern maps to a specific artefact. Untested backups map to the restore-test report; the Microsoft 365 misconception maps to the backup configuration and coverage report. The patterns persist because, without a structured review, nobody notices which artefacts are missing until the questionnaire arrives.
Where most organisations land

Insurance-auditable readiness, in three zones.

A quick way to position current state before a formal review. Most Australian mid-sized organisations land in the yellow zone before a structured engagement; red and green are less common on first assessment.

Red — backups exist, evidence does not

Backup software is running and jobs appear to complete. No documented restore tests, no dated MFA coverage report, no dependency map. RTO and RPO are informal targets rather than documented commitments. A questionnaire requesting specific evidence will trigger a scramble.

Yellow — controls in place, documentation patchy

Backup architecture is sound (3-2-1, offline or immutable copy exists). A restore test was performed, possibly more than a year ago, without a formal report. MFA is enforced across most accounts but not systematically verified. The questionnaire can be answered, but some claims rest on recollection rather than documentation.

Green — evidence pack current and defensible

Each insurer question maps to a dated artefact. Restore tests are performed on cadence with written reports. MFA coverage is verified against a named backup-administrator list. RTO and RPO tied to a current business impact analysis. A named owner reviews the pack quarterly. The questionnaire is answered from records, not from memory.

Most organisations land in the yellow zone. A Recovery Readiness Assessment turns that into a defensible, dated evidence pack — mapped to your insurer's exact questions before you sign.

Assess your evidence pack
How this fits

The evidence pack is one output of broader recovery readiness work.

Insurance-auditable recovery is the evidence layer of broader recovery readiness. It connects to backup architecture (what the evidence describes), to immutability (what the storage configuration evidences), to identity recovery sequencing (what the dependency map captures), to cyber recovery time modelling (what the recovery numbers attest to) and to operational documentation (what the runbook and exercise records evidence). Where the broader question is "could we recover from a destructive cyber event with evidence that holds up at renewal," the evidence pack is produced inside a Recovery Readiness Assessment alongside the architecture review and remediation sequencing, rather than assembled as a standalone deliverable under deadline pressure.

Inlight IT view

The Inlight IT view on insurance-auditable recovery.

A backup that has never been restored in anger is an assertion — and an assertion is not a recovery capability. Current renewal questionnaires are built to find that out. The gap between "we have 3-2-1 backups" and "we have a dated report from February showing a 4-hour restore of a representative workload to an isolated environment, verified by the named engineer who signed the report" is the entire space this page is trying to close. Both organisations have backups; only one has recovery evidence, and underwriters are asking questions specifically designed to surface which of the two they are insuring.

Where organisations usually have work to do is in three places: MFA on backup administrator accounts, consistently enforced and documented; dated, written restore-test reports produced on a defined cadence; and attestation language that matches what the evidence supports rather than the ambition. None of these is expensive to fix, and all three are commonly absent until a structured review surfaces them. Audit-ready recovery posture is the benefit; the ongoing engineering discipline to produce, refresh and keep the evidence current is the trade-off.

A backup that exists is not the same as a recovery path that works. The difference matters most on the day it is tested by an attacker.

Before renewal

Answering the questionnaire from evidence is a very different fortnight to answering it from memory — and the evidence pack is buildable now.

Build the evidence →
Posture characteristics

Four characteristics that turn an evidence pack from a document collection into an audit-ready artefact.

Each artefact has a date and a named engineer

A restore test from February signed by a named engineer is evidence. An undated document titled "Backup Test" from an unknown year is not. Underwriters trust a recent, dated artefact.

The pack is structured to the questionnaire

Organised so each insurer question maps to a specific artefact, so the renewal conversation becomes a structured walk-through rather than a back-and-forth.

Gaps are flagged, not concealed

Where the evidence does not support a desired claim, the claim is reworded. Overstating what the evidence supports converts a covered loss into a declined claim. Integrity on the questionnaire is protective, not restrictive.

Refresh is scheduled, not reactive

A defined review cadence (quarterly or biannual) ensures the pack is current when the renewal arrives. Reactive refresh under deadline pressure is what produces the gaps in the first place.

Frequently asked

Questions Australian organisations ask about insurance-auditable recovery.

What does insurance-auditable recovery mean?
Recovery capability backed by documented, dated evidence — not backup existence, and not verbal assurance. It combines a real recovery architecture (immutable copies, tested restores, MFA-protected backup administration, documented RTO and RPO, dependency maps) with artefacts that prove the architecture operates as described. Underwriters increasingly treat the renewal questionnaire as an audit and verify claims through scanning tools, requested evidence, or post-incident review.
Why is the current renewal questionnaire harder than before?
The underwriting posture has changed. Pricing has softened, but the evidence bar has risen sharply. Questionnaires that used to accept yes-or-no answers now ask for architecture diagrams, backup-administrator MFA proofs, dated restore-test reports and documented RTO and RPO. Insurers have seen too many claims where attested controls did not match verified reality, and they have adjusted the process to audit the attestation rather than only the incident.
What is the difference between backup and insurable recovery?
Backup is the existence of data copies. Recovery is the process of returning systems to operation from those copies. Insurable recovery requires both, plus documented evidence that the recovery process has been tested, is repeatable and will meet defined RTO and RPO under real conditions. A backup that has never been restored in anger is an assertion, not a recovery capability — and the questionnaire is built to find that out.
How often should we test restores?
A defensible cadence is quarterly partial restores and an annual full-scope restore test covering a representative workload, with dated reports on each. Insurers vary, but an annual test at minimum with written results is the common floor. The test should be scoped to a workload that matches something critical, not a trivial file, and the report should capture scope, procedure, timing, outcome and issues. Untested backups are treated as an assumption rather than a recovery plan.
Do insurers audit backup administrator accounts?
Increasingly, yes. Backup administrator account configuration is one of the most specific question categories. Underwriters ask whether the backup admin account is separate from production administrator accounts, whether MFA is enforced, where credentials are stored, and whether the account has been reviewed recently. Absence of MFA on the backup admin account is one of the most common claim-denial triggers when found after a loss event.
We use Microsoft 365. Do we still need a separate backup?
Usually, yes — particularly where cyber insurance, client data, financial records or recovery evidence are in scope. Microsoft operates the platform but does not back up customer data in the way most organisations assume. Native retention for deleted mail is short (typically 14 to 30 days); OneDrive and SharePoint recycle-bin windows expire after up to 93 days; and a cyber attack that encrypts files inside Microsoft 365 is replicated, not reverted. Microsoft's Service Agreement advises customers to back up their content. Independent Microsoft 365 backup is now expected on most renewal questionnaires.
Who should sign the attestation statement?
Attestation is strongest when signed by a named technical lead whose records support the claims, co-signed by a responsible executive, and where relevant supported by an independent assessment report. Executive sign-off without technical backing is symbolic; internal sign-off without documented evidence is exposed if an insurer verifies. Attestation language must match the evidence — if the evidence supports a weaker claim, the attestation needs to reflect that rather than overstate.
How long does it take to build an evidence pack from nothing?
Three to four weeks is reasonable for a mid-sized organisation where the underlying controls are mostly in place but the evidence has not been collected. Timeframe extends where remediation is needed first — for example where MFA on backup administrator accounts is absent, where there is no offline or immutable copy, or where no restore test has ever been performed. The pack is assembled during a structured assessment that maps each insurer question to a specific artefact and flags gaps for remediation.
What if our attestation does not match our actual controls?
After a loss event, the pre-incident attestation is verified against what is found. Where the controls attested to did not exist, the claim is exposed to denial or coverage reduction on the basis of misrepresentation. The risk is asymmetric: the controls are cheaper to verify and remediate before the claim than the claim is to defend after the loss. Most underwriters will work with an organisation that flags a gap proactively; most will not work with one that misrepresented the position and then filed a claim.
How does this differ from general backup and disaster recovery?
General backup and disaster recovery focuses on the capability to restore operations after a disruption. Insurance-auditable recovery adds the evidentiary layer: the capability plus documented, dated proof that it has been tested and operates as described. The technical architecture is often identical; the difference is in the documentation, testing cadence and the structured mapping of artefacts to insurer questions. A competent backup and disaster recovery posture that is not documented is not insurance-auditable.
From the work

Insurance-auditable recovery as the driving question.

As an illustration of the approach rather than a headline: in one multi-clinic healthcare environment, recovery readiness work produced the evidence pack alongside the architecture review and recovery-time modelling — backup architecture diagram, MFA coverage verification, dated restore-test reports, dependency map and recovery assumptions register. The pack arrived at the renewal questionnaire ready, not as a deadline scramble. The point of the example is the sequencing: evidence produced alongside the engineering work, not reconstructed after the fact.

Practical next step

Arrive at the renewal with evidence, not a scramble.

A Recovery Readiness Assessment maps each questionnaire claim to a dated artefact, flags the gaps before the form is signed, and sequences remediation while there is still time to close them.

Book a Recovery Readiness Assessment