Your next cyber insurance renewal will ask for evidence, not assurances.
Cyber insurance pricing has softened across most of the Australian market, but the evidence bar has risen sharply. Questionnaires that used to accept "yes, we have backups" now request architecture diagrams, backup-admin MFA proofs, dated restore-test reports and documented RTO and RPO targets — and insurers verify them.
See what underwriters actually verifyInsurance-auditable recovery is recovery capability backed by documented, dated evidence — not backup existence, and not verbal assurance. It is a real recovery architecture (immutable copies, tested restores, MFA-protected backup administration, documented RTO and RPO, dependency maps) plus the artefacts that prove the architecture operates as described. Insurers increasingly treat the renewal questionnaire as an audit and verify claims through scanning tools, requested evidence, or post-incident review.
What it is, what changed and what evidence needs to exist.
What does insurance-auditable recovery mean?
Recovery capability backed by documented, dated evidence — a real recovery architecture plus artefacts that prove it operates as described. Insurers increasingly treat the questionnaire as an audit and verify claims through scanning tools, requested evidence or post-incident review.
What changed in the underwriting posture?
The audit bar. Pricing has softened, but the evidence bar has risen sharply. Questionnaires that used to accept "yes, we have backups" now request architecture diagrams, backup-admin MFA proofs, dated restore-test reports and documented RTO and RPO. Insurers now audit the attestation, not just the incident.
What should we be able to produce?
A structured evidence pack covering backup architecture, retention policies, backup logs, dated restore-test reports, MFA coverage proofs, dependency maps, incident response runbook, tabletop records, recovery assumptions register and break-glass documentation. Each claim maps to a specific artefact — or the gap is flagged before the questionnaire is signed.
Cyber insurance renewals are now evidence audits in everything but name.
The Australian cyber insurance market is softening in price and hardening in proof. Brokers describe it as buyer-leaning, with premium increases moderating compared to the 2021–2023 hard-market years. At the same time, obtaining meaningful coverage increasingly requires demonstrating specific controls, not simply attesting that security exists. Three dynamics sit behind the shift.
Questionnaires have been rewritten as audits. Insurers now ask for evidence that used to be assumed — backup architecture diagrams, MFA enrolment proofs for backup administrators and privileged accounts, dated restore-test reports, and RTO and RPO tied to a documented business impact analysis. The questions are more specific because the answers are now verified.
Verification has moved beyond the form. Underwriters increasingly use external scanning tools, request evidence during the quote process, and conduct structured assessments before binding coverage. After a loss event, the pre-incident attestation is tested against what is found; gaps between what was claimed and what existed are a common basis for denial or coverage reduction.
The gap between attested controls and verified reality is now visible at the governance layer. Recent Australian enforcement has linked cyber control adequacy to statutory duties. In ASIC v FIIG Securities Limited (2026), the Federal Court made declarations relating to failures to maintain adequate cybersecurity measures under AFSL obligations, contributing to a substantial penalty plus costs; the 2022 ASIC v RI Advice Group decision established the precedent. For directors and executives, the practical expectation is increasingly clear: cyber control claims need credible oversight, evidence and follow-through. Cyber insurance renewal, claim integrity and governance oversight are connected problems — and much of the same evidence supports all three conversations.
Across Australian renewal questionnaires and insurer-driven assessments, the same eight categories recur.
A credible recovery posture must produce defensible evidence in each category below. Each maps to a specific question on the questionnaire, and each maps to a specific artefact in the evidence pack. "Backups exist" is no longer an answer.
A 3-2-1 design at minimum: three copies, two media types, one offsite, with at least one copy offline or immutable to survive a cyber attack that reaches the production network. Evidence: architecture diagram, storage configuration, retention settings.
Backup infrastructure isolated from production identity and credentials. Backup admin accounts not shared with daily operational accounts; backup servers not domain-joined to production Active Directory. Evidence: network diagrams, identity platform reports.
Dated, documented restore tests on a defined cadence. The question asked is "when did you last successfully restore from backup, and what did that restore cover?" A test without a written report is not evidence. Evidence: dated restore-test reports, ticket records.
Documented RTO and RPO per critical service, tied to a business impact analysis rather than a round number. The question behind the question is whether the targets are achievable against the actual architecture. Evidence: BIA summary, per-service targets.
MFA enforced on backup administrator accounts, privileged administrator accounts and remote access, with a documented break-glass procedure for emergency access without violating MFA controls. Evidence: MFA enrolment reports, privileged access review.
Write-Once-Read-Many storage for the backup copy that must survive a destructive cyber event; versioning enabled on cloud data stores where relevant. Evidence: WORM configuration exports, retention policy settings, version-history configuration.
Incident response plan with named roles, business continuity plan covering recovery sequence, and tabletop exercise evidence. Documentation must be current — not filed during a compliance push three years ago and never updated. Evidence: IR plan, BCP, exercise reports.
A named owner for the recovery program, a documented review cadence for the plan and the evidence, and change management records showing updates after environment changes. Evidence: role assignment, review logs, change management records.
Each insurer question maps to a specific document.
The evidence pack is the structured artefact set that makes recovery posture auditable. Each item exists for a specific reason and answers a specific underwriter question. A useful discipline: each item carries a last-reviewed date — if it is older than six months, it is flagged for refresh before renewal.
Insurers care about who is attesting as much as what is attested.
A statement that the organisation meets a given standard carries different weight depending on who signs it, what records support it, and whether those records are independently verifiable. The central principle: attestation language must match the evidence. The most common failure is not dishonesty — it is aspirational answers to specific questions under renewal-deadline pressure.
An external assessor performs a structured review, documents findings and produces a signed, dated report. Strongest weight, especially for high-value renewals, post-incident assurance, or client and governance attestation requirements.
The managed provider attests to systems they operate, supported by MFA reports, backup logs, restore-test records and ticket history. Credible because the attestation is backed by the evidence the provider produces in the course of operations.
The internal IT lead signs off, with records maintained internally. Credible where the records exist and are current; exposed where they do not.
Important for compliance reasons, but it does not constitute evidence. Insurers do not accept CFO or CEO attestation in isolation as sufficient for technical claims.
The fix is procedural. Each claim on the questionnaire is tied to a named artefact; if the artefact does not support the claim, the claim is reworded or the gap is flagged for remediation before the questionnaire is signed.
Seven failure patterns that surface under scrutiny.
Every pattern below is documented in Australian renewal reviews and post-incident investigations. Most are fixable before the next renewal if identified in time.
Backups exist but have not been restored in practice — treated by insurers as an assumption rather than a plan. The first restore under real pressure is the first time it has been tried, which is the wrong time to discover that a configuration assumption was wrong.
Recovery plans written two years ago and never updated. New systems added, old systems decommissioned, staff turnover — the document is still on file but no longer reflects the environment. An underwriter reading it can usually tell.
The assumption that because data sits in Microsoft's cloud, Microsoft backs it up. Microsoft's Service Agreement explicitly advises customers to back up their own content. Native retention is short (14 to 30 days for mail, up to 93 days for OneDrive and SharePoint recycle bins), and a cyber attack that encrypts inside Microsoft 365 is replicated, not reverted.
Backups well-designed, but the backup administrator account is not MFA-enforced, or shares credentials with daily operations. A single account compromise reaches the backups. One of the most specific questions on current questionnaires, and one of the most common denial reasons when found absent after a claim.
Production servers backed up, SaaS data and endpoints ignored. Microsoft 365, endpoint-stored data and cloud-native services like Teams chat history fall out of scope and are discovered missing at recovery time.
All backups are online, reachable from the production network. A cyber attack that encrypts the production environment reaches the backup repository. An offline or immutable copy is the control that breaks this pattern.
The questionnaire is signed off above what the records support. The gap is invisible until an insurer verifies or an incident triggers a claim review. This is the pattern most likely to convert a covered loss into a declined claim.
Insurance-auditable readiness, in three zones.
A quick way to position current state before a formal review. Most Australian mid-sized organisations land in the yellow zone before a structured engagement; red and green are less common on first assessment.
Backup software is running and jobs appear to complete. No documented restore tests, no dated MFA coverage report, no dependency map. RTO and RPO are informal targets rather than documented commitments. A questionnaire requesting specific evidence will trigger a scramble.
Backup architecture is sound (3-2-1, offline or immutable copy exists). A restore test was performed, possibly more than a year ago, without a formal report. MFA is enforced across most accounts but not systematically verified. The questionnaire can be answered, but some claims rest on recollection rather than documentation.
Each insurer question maps to a dated artefact. Restore tests are performed on cadence with written reports. MFA coverage is verified against a named backup-administrator list. RTO and RPO tied to a current business impact analysis. A named owner reviews the pack quarterly. The questionnaire is answered from records, not from memory.
Most organisations land in the yellow zone. A Recovery Readiness Assessment turns that into a defensible, dated evidence pack — mapped to your insurer's exact questions before you sign.
Assess your evidence packThe evidence pack is one output of broader recovery readiness work.
Insurance-auditable recovery is the evidence layer of broader recovery readiness. It connects to backup architecture (what the evidence describes), to immutability (what the storage configuration evidences), to identity recovery sequencing (what the dependency map captures), to cyber recovery time modelling (what the recovery numbers attest to) and to operational documentation (what the runbook and exercise records evidence). Where the broader question is "could we recover from a destructive cyber event with evidence that holds up at renewal," the evidence pack is produced inside a Recovery Readiness Assessment alongside the architecture review and remediation sequencing, rather than assembled as a standalone deliverable under deadline pressure.
The Inlight IT view on insurance-auditable recovery.
A backup that has never been restored in anger is an assertion — and an assertion is not a recovery capability. Current renewal questionnaires are built to find that out. The gap between "we have 3-2-1 backups" and "we have a dated report from February showing a 4-hour restore of a representative workload to an isolated environment, verified by the named engineer who signed the report" is the entire space this page is trying to close. Both organisations have backups; only one has recovery evidence, and underwriters are asking questions specifically designed to surface which of the two they are insuring.
Where organisations usually have work to do is in three places: MFA on backup administrator accounts, consistently enforced and documented; dated, written restore-test reports produced on a defined cadence; and attestation language that matches what the evidence supports rather than the ambition. None of these is expensive to fix, and all three are commonly absent until a structured review surfaces them. Audit-ready recovery posture is the benefit; the ongoing engineering discipline to produce, refresh and keep the evidence current is the trade-off.
A backup that exists is not the same as a recovery path that works. The difference matters most on the day it is tested by an attacker.
Answering the questionnaire from evidence is a very different fortnight to answering it from memory — and the evidence pack is buildable now.
Build the evidence →Four characteristics that turn an evidence pack from a document collection into an audit-ready artefact.
A restore test from February signed by a named engineer is evidence. An undated document titled "Backup Test" from an unknown year is not. Underwriters trust a recent, dated artefact.
Organised so each insurer question maps to a specific artefact, so the renewal conversation becomes a structured walk-through rather than a back-and-forth.
Where the evidence does not support a desired claim, the claim is reworded. Overstating what the evidence supports converts a covered loss into a declined claim. Integrity on the questionnaire is protective, not restrictive.
A defined review cadence (quarterly or biannual) ensures the pack is current when the renewal arrives. Reactive refresh under deadline pressure is what produces the gaps in the first place.
Questions Australian organisations ask about insurance-auditable recovery.
What does insurance-auditable recovery mean?
Why is the current renewal questionnaire harder than before?
What is the difference between backup and insurable recovery?
How often should we test restores?
Do insurers audit backup administrator accounts?
We use Microsoft 365. Do we still need a separate backup?
Who should sign the attestation statement?
How long does it take to build an evidence pack from nothing?
What if our attestation does not match our actual controls?
How does this differ from general backup and disaster recovery?
Insurance-auditable recovery as the driving question.
As an illustration of the approach rather than a headline: in one multi-clinic healthcare environment, recovery readiness work produced the evidence pack alongside the architecture review and recovery-time modelling — backup architecture diagram, MFA coverage verification, dated restore-test reports, dependency map and recovery assumptions register. The pack arrived at the renewal questionnaire ready, not as a deadline scramble. The point of the example is the sequencing: evidence produced alongside the engineering work, not reconstructed after the fact.
Arrive at the renewal with evidence, not a scramble.
A Recovery Readiness Assessment maps each questionnaire claim to a dated artefact, flags the gaps before the form is signed, and sequences remediation while there is still time to close them.
Book a Recovery Readiness Assessment