The person who signs is not the person who knows.

A cyber insurance proposal form arrives about six weeks before renewal, forwarded by the broker with a note asking for it back when convenient. The first page is easy, ABN, trading name, business activities, revenue by state, employee count. Someone in accounts fills that in over a coffee.

Then it turns technical, and it does it abruptly. Is multi-factor authentication required for all users across remote network access, web-based email, administrative accounts and cloud resources including backups. How are critical security patches handled, automatically or manually, and within what window. Is a copy of the backups held offline and segregated from the network. Nobody in accounts can answer those, so the form goes to whoever handles the IT, the answers come back, and the owner signs it.

That handoff is so ordinary it doesn't look like anything. It's the most consequential moment in the renewal.

The forms are honest about the difficulty. They say on the front page that completing them requires technical knowledge of the business's IT, and they tell the applicant to consult their IT manager or head of cyber security. That instruction is written for a business that has one of those people, and most Australian small businesses have neither.

At the other end sits the declaration, where the policyholder certifies the information is true and correct. There's a clause covering answers that weren't written by the policyholder, asking the signatory to confirm they've checked them and certify them anyway. That clause exists because everybody forwards the technical section to somebody else. The insurer knows the answers are coming from a third party, and the declaration is what puts responsibility for them back on the business.

Above that sits the duty of disclosure under section 21 of the Insurance Contracts Act 1984, which applies to commercial insureds and covers every matter the insured knows, or could reasonably be expected to know, is relevant to the insurer's decision. The remedies sit in section 28. Innocent non-disclosure can reduce what gets paid, and where the insurer wouldn't have written the risk at all it can decline the claim outright. Fraudulent non-disclosure lets the insurer avoid the contract entirely.

A fire policy asks about the building, and the owner has seen the building. A cyber policy asks whether administrative accounts are covered by multi-factor authentication, and the owner has never seen the tenant. The signature is still theirs and so is the duty, and if the answer turns out to have been optimistic, the conversation at claim time is between the insurer and the insured. The provider who supplied that answer isn't a party to it. Their exposure is an awkward phone call, the client's is the claim.

None of this means insurers are hunting for reasons to decline, or that IT providers are careless. Cyber has been consistently profitable in Australia, premiums softened through 2025, and claims get paid every day. Most providers answer these questions in good faith and get most of them right.

The problem is narrower than that, and more mechanical. The questions are binary and environments are not. A form asks whether MFA is required for all users, yes or no, with no third option, and the provider knows it's enforced on everyone except two service accounts excluded years ago for an integration that still needs them. There's nowhere on the page to say that, so they tick yes, because yes is closer to the truth than no. Then the owner signs for it.

The standard advice for this is the same everywhere, and it's where the trap sits. Have your IT provider complete the technical section. It's sensible, it's what the form itself suggests, and it puts the assessment in the hands of the party who configured the thing being assessed. That's a conflict even when everybody involved is competent and well meaning, because a provider answering these questions is grading their own work, in writing, in a document their client will sign. The incentive isn't to lie, it's to round up.

The pattern generalises past insurance. Signing for something you can't verify is the same shape as a green dashboard nobody has audited, a backup nobody has restored from, and a policy document describing a control that was switched off in 2023 for a project that finished. The proposal form is just the version that comes with a signature block and a statutory duty attached.

I read these forms because the questions on them are a fair summary of what actually matters in a small environment. I don't advise on cover, that's the broker's work and properly theirs. Whether the answers are true is a different question, and it's the one I can answer.

Back to Writing